v0.3.0 — --passphrase replaces primary-secret re-assertion
Breaking. Every escalation command now takes --passphrase instead of
re-pasting the primary secret per auth type.
The change
v0.2: profile allow myapi new.host --token $HUGE_BEARER_TOKEN —
re-pasted the full primary secret, overwrote on mismatch, silently
broke the profile on typos.
v0.3: profile allow myapi new.host --passphrase 'my-friendly-phrase'
— constant-time verified, wrong value errors cleanly.
At profile add time, optionally set a short friendly phrase with
--passphrase (min 12 chars). If you don't, the stored passphrase
auto-defaults to your primary secret — so existing profiles still
work, you just keep typing the token into --passphrase until you
run change-secret to pick a friendlier one.
New command: profile change-secret
Rotate the primary secret without losing allowlist, headers, or
jar-key:
profile change-secret github \
--passphrase 'my-friendly-phrase' \
--token ghp_NEW_ROTATED_TOKENPreserves a human-set passphrase; re-derives an auto-derived one.
Optional --new-passphrase <phrase> to also rotate the passphrase.
Breaking changes
profile allow / allow-path:--token T→--passphrase Pprofile set-default-header / set-allow-http: same swapjar mark-visible: same swap- New verb:
profile change-secret - New flag on
profile add:--passphrase <phrase>(optional, min 12 chars) Secretsstruct gainsPassphrase+PassphraseAutoDerivedfields
Migration
Existing v0.2 profiles auto-migrate on first write (empty Passphrase
gets populated from the primary secret). Nothing to do if you're
happy typing the primary secret into --passphrase. To pick a
friendlier phrase:
profile change-secret myapi \
--passphrase '<old-primary-secret-as-passphrase>' \
--token '<same-primary-secret>' \
--new-passphrase 'friendly-phrase-2026'Why this change
v0.3 was driven by feedback from a real LLM smoke-test against a
staging API — the user found the pasting-long-tokens UX actively
painful, and a wrong-paste silently broke the profile in a way that
only surfaced at next-fetch time. Moving to verified-passphrase fixes
both.
Security delta: essentially zero. The primary escalation boundary
remains the harness's permission allowlist (SKILL.md), which denies
escalation commands to the LLM. The 12-char minimum + constant-time
compare keep the oracle attack surface manageable even if the harness
leaks.
Install
brew install shhac/tap/agent-deepweb # new
brew upgrade shhac/tap/agent-deepweb # existing