* refactor(skills): shipped-set slim — 15 skills to optional, github six-way merge, pdf absorbs OCR+nano-pdf, channel-gated teams pipeline
Maintainer-directed shipped-skills curation (skills index 1,900 -> ~1,400
tok/call on desktop; every session pays the index, so this is a per-call
diet on all installs):
- optional-skills moves (installable via skills hub, history preserved):
creative comfyui/ascii-art/excalidraw/pretext/sketch/touchdesigner-mcp;
ALL of mlops (huggingface-hub, llama-cpp, serving-llms-vllm,
weights-and-biases, evaluating-llms-harness — subcategory structure
kept); research-paper-writing (55 supporting files, 17.3K-tok load);
openhue; blogwatcher (first taught the cronjob monitor-field watch
pattern + web_extract instead of pre-cron manual workflows)
- DELETED session-librarian (Aug-12 'inspired by Perplexity Computer'
port, never maintainer-intended; session_search covers discovery)
- github: six skills (auth, issues, pr-workflow, issue-to-pr,
code-review, repo-management) merged into ONE software-development/
github skill — routing body + complete per-workflow references;
benbarclay authorship credited; codebase-inspection rides along;
discipline pins from test_github_issue_to_pr_skill.py preserved
against the reference body in the new test_github_skill.py
- pdf absorbs ocr-and-documents + nano-pdf as references/ + scripts
(extract_pymupdf, extract_marker converted to the argparse house
standard its contract test enforces)
- NEW session_platforms frontmatter gate (metadata.hermes): hides a
skill from the index on gateway channels it is not for; fail-open on
unknown platform; teams-meeting-pipeline gated to [teams, cron]
- blocked-page-recovery: research -> new web category; trigger-first
description ('Use when a fetch fails: 403/429, paywall, WAF, bot
wall.') so the model actually reaches for it on blocked fetches
- docs regenerated via generate-skill-docs.py (195 pages); related_skills
swept repo-wide; tests: 1672 passed (2 openclaw failures pre-existing
on clean main, Windows-local)
* chore: ignore .skills_prompt_snapshot.json (local index cache, accidentally committed)
66 lines
1.7 KiB
Python
66 lines
1.7 KiB
Python
#!/usr/bin/env python3
|
|
"""Print the first unambiguous GitHub token in a git credential-store file."""
|
|
|
|
from pathlib import Path
|
|
import re
|
|
import sys
|
|
from urllib.parse import unquote, urlsplit
|
|
|
|
|
|
_TOKEN_PREFIXES = ("ghp_", "github_pat_", "gho_", "ghu_", "ghs_", "ghr_")
|
|
_INVALID_ESCAPE = re.compile(r"%(?![0-9A-Fa-f]{2})")
|
|
|
|
|
|
def _decode(value: str | None) -> str:
|
|
if value is None or _INVALID_ESCAPE.search(value):
|
|
return ""
|
|
decoded = unquote(value)
|
|
if not decoded or any(ord(char) <= 0x1F or 0x7F <= ord(char) <= 0x9F for char in decoded):
|
|
return ""
|
|
return decoded
|
|
|
|
|
|
def _token_from_url(line: str) -> str:
|
|
if "\r" in line or "\n" in line:
|
|
return ""
|
|
try:
|
|
credential = urlsplit(line)
|
|
port = credential.port
|
|
except ValueError:
|
|
return ""
|
|
if credential.scheme != "https" or credential.hostname != "github.com" or port not in (None, 443):
|
|
return ""
|
|
|
|
username = _decode(credential.username)
|
|
password = _decode(credential.password)
|
|
if not username:
|
|
return ""
|
|
if password and password != "x-oauth-basic":
|
|
return password
|
|
if password == "x-oauth-basic":
|
|
return username
|
|
return username if username.startswith(_TOKEN_PREFIXES) else ""
|
|
|
|
|
|
def main() -> int:
|
|
path = Path(sys.argv[1]).expanduser() if len(sys.argv) > 1 else Path.home() / ".git-credentials"
|
|
try:
|
|
lines = path.read_bytes().split(b"\n")
|
|
except OSError:
|
|
return 1
|
|
|
|
for raw_line in lines:
|
|
try:
|
|
line = raw_line.decode("utf-8")
|
|
except UnicodeDecodeError:
|
|
continue
|
|
token = _token_from_url(line)
|
|
if token:
|
|
print(token)
|
|
return 0
|
|
return 1
|
|
|
|
|
|
if __name__ == "__main__":
|
|
raise SystemExit(main())
|