account-rotation
GitHub用于显式切换编码代理账户并验证运行时身份,防止因内存中残留旧令牌导致的身份混淆。
Trigger Scenarios
Install
npx skills add boshu2/agentops --skill account-rotation -g -y
SKILL.md
Frontmatter
{
"name": "account-rotation",
"consumes": [],
"metadata": {
"tier": "execution",
"effects": [
"rotate_agent_account"
],
"disposition": "keep_optional_adapter",
"capabilities": [
"account_rotation"
],
"dependencies": [],
"canonical_status": "canonical"
},
"produces": [],
"practices": [
"pragmatic-programmer"
],
"context_rel": [],
"description": "Switch coding-agent accounts and verify runtime identity. Use when: the caller requests an account change; never rotate automatically to evade a quota.",
"hexagonal_role": "supporting",
"user-invocable": true,
"output_contract": "observed account identity and command status",
"skill_api_version": 1
}
Account rotation — credential adapter
Choose the credential tool from both host and agent family, perform only the explicit account switch, and report the identity observed by the matching runtime.
Verifying identity through the target runtime works because the runtime is the only party whose opinion matters: credential files can be swapped perfectly and still authenticate as the old account in an already-running process.
Named failure mode — stale-process identity: declaring the rotation done while every live session still holds the previous account's tokens in memory.
Anti-pattern: confirming a switch by diffing credential file bytes. Corrective: ask the matching runtime who it is now, and report whether a new process is required for the answer to hold.
Boundary
- Perform only the account switch the caller explicitly authorized; rotation mutates host credential state and is never implied by repository access.
- The credential tool is caller- or operator-selected per host and agent family;
the names below are this operator's routes, not a universal prescription. On
macOS with Claude credentials the route is
claude-acct(Keychain-backed); file-backed Codex, Gemini, Linux, or WSL credentials usecaam. Never usecaamfor macOS Claude account operations. - Verify account identity through the target runtime; token bytes are not account identity.
- If neither the selected credential tool nor a runtime identity probe is available, report that absence as a disclosed fact and stop. Never fall back to diffing credential-file bytes to declare a switch done.
- Existing processes retain credentials already loaded in memory. Rotation affects a new process.
- This skill does not restart work, resume a task, select a pane, move repository state, or decide what happens after the switch.
Return the host, agent family, selected tool, requested account/profile, the identity observed before and after the switch, whether any live runtime still holds the previous account (a partial rotation), the command exit code, and whether a new process is required for the new identity to hold.
Version History
-
9f8a711
Current 2026-09-22 10:59
整合 AgentOps 技能目录,将重叠入口合并,优化路由与描述。
-
7b07a7d
2026-08-19 21:58
完善边界定义,明确不同平台凭证工具选择规则,细化身份验证与结果报告要求。
- 3f402e5 2026-07-24 22:06


