Mcp server headers
Skill eugenelim/agent-ready-repo/packages/agentbundle/tests/fixtures/creds/skills/mcp-server-headers
MCP-server class fixture using header-naming flags (`--bearer-header`); AC26(b) ban is scoped to credentialed-cli only — lint must NOT flag this fixture.From its SKILL.md
npx -y skills add eugenelim/agent-ready-repo --skill mcp-server-headersAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 15 stars15 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
1.1 KB, 227 tokens by cl100k_base, as published. Nobody here has run it
MCP-server class primitives legitimately accept header-naming flags
(--bearer-header, --auth-header, --header-prefix). The storage
convention does not apply because nothing is persisted; the SKILL.md
"Don't" block has a parallel form noted in RFC-0006 § 4.
Security rules (non-negotiable)
- Secrets live only in
~/.agentbundle/credentials.env(mode 0600 on POSIX; DACL-restricted on Windows), the OS keyring, or process environment variables. Never read that file, print it, or echo the token. - Never put the token on the command line. The primitive
refuses flags like
--token/--api-token/--bearer/--pat/--passwordand exits — do not work around it. - If
checkexits with the "missing credentials" code, tell the user to runagentbundle creds setup <namespace>themselves. It's interactive — do not run it for them.
What ships with it: 1 file
466 B alongside SKILL.md, 1 of them executable
scripts/
- cli.pyruns466 B