← Matt Skills CuratedCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Matt Skills Curated
Snapshot Sep 30, 2026 · 23:14 UTC · version 1.1.0
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"description": "Generate an interactive bash wizard to guide humans through manual setup, dashboard, or credential steps. Use when setting up API keys, third-party dashboards, CI secrets, or infrastructure where human authentication is required — even if the user says \"create a setup wizard\". Do NOT use for steps the AI agent can execute autonomously.",
"included_files": [
{
"relative_path": "agents/openai.yaml",
"size_in_bytes": 96
},
{
"relative_path": "template.sh",
"size_in_bytes": 9232
}
],
"name": "wizard",
"skill_md_contents": "---\nname: wizard\ndescription: \"Generate an interactive bash wizard to guide humans through manual setup, dashboard, or credential steps. Use when setting up API keys, third-party dashboards, CI secrets, or infrastructure where human authentication is required — even if the user says \\\"create a setup wizard\\\". Do NOT use for steps the AI agent can execute autonomously.\"\n---\n\n# Wizard\n\nGenerate structured, interactive Bash wizards that walk human operators step-by-step through manual dashboard procedures, secret provisioning, and irreversible cutover operations.\n\n---\n\n## Core Invariants\n\n1. **Human-Only Boundary**: Wizards are strictly for tasks that require human interactive authentication, MFA, billing approval, or physical dashboard navigation.\n2. **Immutable Helper Library**: Preserve the standardized UI helper library in `template.sh` above the `STAGES` marker; never modify internal screen-clearing or secret-masking logic.\n3. **URL-First Navigation**: Always open target URLs (`open_url`) before prompting the human for values or confirmation.\n4. **Masked Secret Input**: Use `ask_secret` for all API tokens, private keys, and passwords; persist secrets directly to `.env` or GitHub Secrets (`set_secret`).\n5. **Static Syntax Validation**: Verify all generated wizard scripts with `bash -n <script>` and `shellcheck` before handing off to the user.\n\n---\n\n## Architecture & Map of Content (MOC)\n\n```\n[ Manual Dashboard / Credential Prerequisite ] ──► [ Scope Stages & Target Secrets ] ──► [ Generate Wizard from template.sh ] ──► [ Operator Execution ]\n```\n\n| Component | Responsibility | Reference Template |\n|---|---|---|\n| **Bash Wizard Engine** | UI helpers, secret prompt, .env upsert, GitHub CLI writes | `skills/wizard/template.sh` |\n| **Stage Scaffolding** | Linear step sequence with URL triggers | `scripts/setup-*.sh` |\n| **Verification Pass** | Bash syntax check and dry run | `bash -n <script>` |\n\n---\n\n## Step-by-Step Procedure (TWI)\n\n### Step 1: Scope Manual Stages & Secrets Inventory\n- **Action**: Inspect `.env.example`, `.github/workflows/*`, and documentation to identify all manual inputs and secrets needed.\n- **Key Point**: For every value, determine: (1) Source URL / dashboard path, (2) Destination (`.env`, `gh secret`, or both), (3) Secret visibility.\n- **Why**: Thorough inventory prevents writing incomplete scripts that leave operators blocked midway.\n\n### Step 2: Map Operator Journey per Stage\n- **Action**: Draft clear, sequential instructions: which dashboard menu to click, where keys are generated, and which variable is populated.\n- **Key Point**: Clarify exact UI labels (e.g. \"Settings $\\rightarrow$ API Keys $\\rightarrow$ Create Secret Key\").\n- **Inline Checklist**:\n - [ ] Every stage maps to a single focused task\n - [ ] URLs verified against official documentation\n - [ ] Secret inputs mapped to `ask_secret` and `write_env`\n\n### Step 3: Author Wizard Script from `template.sh`\n- **Action**: Copy `skills/wizard/template.sh` to target path (e.g. `scripts/setup-provider.sh`), set `TOTAL_STAGES`, and author stages below the marker.\n- **Key Point**: Do not touch the helper functions above the `STAGES` marker.\n- **Why**: Consistency in UI helpers ensures uniform, robust terminal behavior across platforms (macOS, Linux, WSL).\n\n### Step 4: Validate Syntax & Deliver Hand-off\n- **Action**: Run `bash -n <script>` and `chmod +x <script>`. Provide the user with the exact execution command.\n- **Key Point**: Do not attempt to run the interactive wizard autonomously inside the agent session.\n- **Why**: The wizard requires interactive terminal input and browser windows that block autonomous agent subshells.\n\n---\n\n## Anti-Rationalization Guardrails\n\n| Tempting Rationalization | Binding Rule | Engineering Rationale |\n|---|---|---|\n| *\"Generate a wizard for steps the agent could do via CLI.\"* | **Execute agent-capable steps directly; reserve wizards for human-only tasks.** | Forcing humans to execute tasks an agent could run wastes human time. |\n| *\"Prompt for secrets with standard `read` without masking.\"* | **Mandatory `ask_secret` for all sensitive credentials.** | Plaintext secret prompts leak API tokens in terminal logs and shoulder surfing. |\n| *\"Attempt to execute the interactive bash wizard in background subshell.\"* | **Hand off wizard script to user with execution command.** | Background subshells hang indefinitely on interactive `read` and `open` calls. |\n\n"
}SHA-256 of public snapshot: c5283ea71865b699a9c059bdc3c4e722c65ae4c2769ed70cc1900bad1522c48d