Skip to content

v0.3.0 — --passphrase replaces primary-secret re-assertion

Choose a tag to compare

@shhac shhac released this 24 Apr 07:35
· 91 commits to main since this release
7d0e412

Breaking. Every escalation command now takes --passphrase instead of
re-pasting the primary secret per auth type.

The change

v0.2: profile allow myapi new.host --token $HUGE_BEARER_TOKEN —
re-pasted the full primary secret, overwrote on mismatch, silently
broke the profile on typos.

v0.3: profile allow myapi new.host --passphrase 'my-friendly-phrase'
— constant-time verified, wrong value errors cleanly.

At profile add time, optionally set a short friendly phrase with
--passphrase (min 12 chars). If you don't, the stored passphrase
auto-defaults to your primary secret — so existing profiles still
work, you just keep typing the token into --passphrase until you
run change-secret to pick a friendlier one.

New command: profile change-secret

Rotate the primary secret without losing allowlist, headers, or
jar-key:

profile change-secret github \
  --passphrase 'my-friendly-phrase' \
  --token ghp_NEW_ROTATED_TOKEN

Preserves a human-set passphrase; re-derives an auto-derived one.
Optional --new-passphrase <phrase> to also rotate the passphrase.

Breaking changes

  • profile allow / allow-path: --token T → --passphrase P
  • profile set-default-header / set-allow-http: same swap
  • jar mark-visible: same swap
  • New verb: profile change-secret
  • New flag on profile add: --passphrase <phrase> (optional, min 12 chars)
  • Secrets struct gains Passphrase + PassphraseAutoDerived fields

Migration

Existing v0.2 profiles auto-migrate on first write (empty Passphrase
gets populated from the primary secret). Nothing to do if you're
happy typing the primary secret into --passphrase. To pick a
friendlier phrase:

profile change-secret myapi \
  --passphrase '<old-primary-secret-as-passphrase>' \
  --token '<same-primary-secret>' \
  --new-passphrase 'friendly-phrase-2026'

Why this change

v0.3 was driven by feedback from a real LLM smoke-test against a
staging API — the user found the pasting-long-tokens UX actively
painful, and a wrong-paste silently broke the profile in a way that
only surfaced at next-fetch time. Moving to verified-passphrase fixes
both.

Security delta: essentially zero. The primary escalation boundary
remains the harness's permission allowlist (SKILL.md), which denies
escalation commands to the LLM. The 12-char minimum + constant-time
compare keep the oracle attack surface manageable even if the harness
leaks.

Install

brew install shhac/tap/agent-deepweb    # new
brew upgrade shhac/tap/agent-deepweb    # existing