← Atbash SafetyCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Atbash Safety
Snapshot Sep 30, 2026 · 23:15 UTC · version 0.3.3
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "atbash-setup",
"description": "Configure, activate, verify, troubleshoot, or rotate credentials for the Atbash Safety Codex plugin. Use when a user asks how to set up Atbash, enable or disable its hook, configure an organization or private key, check agent status, understand ALLOW/HOLD/BLOCK behavior, or fix configuration, registration, jailed-agent, endpoint, or service errors.",
"included_files": [
{
"relative_path": "agents/openai.yaml",
"size_in_bytes": 183
}
],
"skill_md_contents": "---\nname: atbash-setup\ndescription: Configure, activate, verify, troubleshoot, or rotate credentials for the Atbash Safety Codex plugin. Use when a user asks how to set up Atbash, enable or disable its hook, configure an organization or private key, check agent status, understand ALLOW/HOLD/BLOCK behavior, or fix configuration, registration, jailed-agent, endpoint, or service errors.\n---\n\n# Atbash Setup\n\nKeep Atbash enforcement separate from this skill. The plugin's catch-all `PreToolUse` hook automatically judges supported tool calls whenever the plugin and hook are enabled and trusted; do not decide case by case whether to invoke Atbash.\n\n## Protect credentials\n\n- Never ask the user to paste, upload, or reveal an Atbash private key in chat.\n- Never read, print, log, inspect, or transmit the user's Atbash config file.\n- Never place a private key in a prompt, tool argument, command-line argument, shell history, manifest, repository file, or `.env` file.\n- Ask the user to edit the config locally themselves. If a private key has appeared in chat, logs, or version control, advise the user to revoke or rotate it before continuing.\n- Explain that the SDK uses the private key locally for agent identity and cryptographic signing and derives the public key locally. The configuration file remains on the user's machine; the plugin does not operate a credential-holding MCP server.\n\n## Configure before trusting the hook\n\nTell the user to create the SDK config outside the Codex conversation before trusting the hook. The organization name is required and must exactly match the organization where the agent's derived public key is onboarded.\n\nUse this JSON shape at `~/.config/atbash/config.json` on macOS/Linux or `%USERPROFILE%\\.config\\atbash\\config.json` on Windows:\n\n```json\n{\n \"agentKey\": \"<your-agent-private-key>\",\n \"orgName\": \"<your-exact-organization-name>\"\n}\n```\n\nGive the user these manual setup commands without executing them or asking for their resulting file contents.\n\nmacOS/Linux:\n\n```bash\nmkdir -p ~/.config/atbash\nchmod 700 ~/.config/atbash\n${EDITOR:-vi} ~/.config/atbash/config.json\nchmod 600 ~/.config/atbash/config.json\n```\n\nWindows PowerShell:\n\n```powershell\nNew-Item -ItemType Directory -Force \"$HOME\\.config\\atbash\"\nnotepad \"$HOME\\.config\\atbash\\config.json\"\n```\n\nEnvironment variables `ATBASH_AGENT_KEY` and `ATBASH_ORG_NAME` are a session-only alternative. Prefer the config file for Codex desktop because environment changes do not reach an already-running desktop process.\n\nIf the already-trusted fail-closed hook prevents setup actions, tell the user to disable or untrust the Atbash hook, complete configuration manually outside Codex, restart Codex, and trust the hook again through `/hooks`.\n\n## Activate or deactivate\n\nTreat Atbash as active only when all of these are true:\n\n1. The `atbash` plugin is installed and enabled.\n2. Codex lifecycle hooks are enabled.\n3. The Atbash `PreToolUse` command is trusted in `/hooks`.\n4. Local Atbash credentials and organization configuration are valid.\n\nTo deactivate Atbash, tell the user to disable the plugin or untrust/disable its hook in Codex. Do not describe deactivation as bypassing an individual verdict; it disables enforcement for subsequent tool calls.\n\n## Verify and troubleshoot\n\nAfter configuration and activation, use a harmless tool call such as listing the current directory to verify that the hook allows an ordinary action. Do not use destructive or privileged commands as tests.\n\nIf working from a source checkout, the user can run:\n\n```bash\nnpm run status --workspace @atbash/codex-plugin\n```\n\nInterpret status results as follows:\n\n- `ready`: configuration, registration, and service access are working.\n- `configuration_error`: correct the local key, exact organization name, or optional endpoint settings.\n- `agent_not_registered`: onboard the public key derived from this private key into the named organization.\n- `agent_jailed`: resolve the agent state in Atbash before retrying.\n- `service_error`: check connectivity, endpoint/chain settings, and Atbash service availability.\n\nNever diagnose key mismatch by asking to inspect the private key. Ask the user to compare the locally derived public key with the public key registered in the Atbash dashboard.\n\n## Explain verdicts\n\n- `ALLOW` with `allow: true`: Codex continues the pending tool call.\n- `HOLD`: Codex blocks this attempt pending operator review. After approval in Atbash, the user must explicitly retry the original request.\n- `BLOCK`: Codex blocks the tool call.\n- `ERROR`, timeout, malformed output, missing configuration, or inconsistent output: Codex blocks the tool call because the hook is fail closed.\n\nDo not claim that the plugin covers plain text responses, hosted tools that opt out of hooks, or every possible Codex capability. It guards tool calls exposed to the `PreToolUse` lifecycle hook.\n\n## Rotate a key\n\nAsk the user to rotate or revoke the old key in Atbash, replace `agentKey` in the local config themselves, verify the derived public key is onboarded to the exact organization, and start a new Codex task. Never handle either key value in the conversation.\n"
}SHA-256: 012e089ea8a15ace886568f9f4b8350dffdde80f36126d618404150d8d66ddd6