Claude opencode Skill

account-rotation

Switch a caller-selected coding-agent account and report the observed identity. Triggers: "switch account", "rotate coding-agent account".

LLM Mart · 0 points · 12 views 38 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download boshu2-agentops-skills_account-rotation-9ac484e.zip · 1 KB
boshu2/agentops 445 41 forks Apache-2.0 Updated 1d ago
Part of boshu2/agentops — 73 skills

Install

skills CLI npx skills add https://github.com/boshu2/agentops/tree/main/skills/account-rotation
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install boshu2-agentops@llmmart
Git git clone https://github.com/boshu2/agentops.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole boshu2/agentops collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Account rotation — credential adapter

Choose the credential tool from both host and agent family, perform only the explicit account switch, and report the identity observed by the matching runtime.

Verifying identity through the target runtime works because the runtime is the only party whose opinion matters: credential files can be swapped perfectly and still authenticate as the old account in an already-running process.

Named failure mode — stale-process identity: declaring the rotation done while every live session still holds the previous account's tokens in memory.

Anti-pattern: confirming a switch by diffing credential file bytes. Corrective: ask the matching runtime who it is now, and report whether a new process is required for the answer to hold.

Boundary

  • Perform only the account switch the caller explicitly authorized; rotation mutates host credential state and is never implied by repository access.
  • The credential tool is caller- or operator-selected per host and agent family; the names below are this operator's routes, not a universal prescription. On macOS with Claude credentials the route is claude-acct (Keychain-backed); file-backed Codex, Gemini, Linux, or WSL credentials use caam. Never use caam for macOS Claude account operations.
  • Verify account identity through the target runtime; token bytes are not account identity.
  • If neither the selected credential tool nor a runtime identity probe is available, report that absence as a disclosed fact and stop. Never fall back to diffing credential-file bytes to declare a switch done.
  • Existing processes retain credentials already loaded in memory. Rotation affects a new process.
  • This skill does not restart work, resume a task, select a pane, move repository state, or decide what happens after the switch.

Return the host, agent family, selected tool, requested account/profile, the identity observed before and after the switch, whether any live runtime still holds the previous account (a partial rotation), the command exit code, and whether a new process is required for the new identity to hold.

Files (agentops)
  • SKILL.md 2.7 KB
    ---
    name: account-rotation
    user-invocable: true
    skill_api_version: 1
    hexagonal_role: supporting
    consumes: []
    produces: []
    context_rel: []
    metadata:
      dependencies: []
      capabilities: [account_rotation]
      effects: [rotate_agent_account]
      canonical_status: canonical
      disposition: keep_optional_adapter
      tier: execution
    description: 'Switch coding-agent accounts and verify runtime identity. Use when: the caller requests an account change; never rotate automatically to evade a quota.'
    practices:
    - pragmatic-programmer
    output_contract: observed account identity and command status
    ---
    # Account rotation — credential adapter
    
    Choose the credential tool from both host and agent family, perform only the
    explicit account switch, and report the identity observed by the matching
    runtime.
    
    Verifying identity through the target runtime works because the runtime is the
    only party whose opinion matters: credential files can be swapped perfectly
    and still authenticate as the old account in an already-running process.
    
    Named failure mode — **stale-process identity**: declaring the rotation done
    while every live session still holds the previous account's tokens in memory.
    
    Anti-pattern: confirming a switch by diffing credential file bytes.
    Corrective: ask the matching runtime who it is now, and report whether a new
    process is required for the answer to hold.
    
    ## Boundary
    
    - Perform only the account switch the caller explicitly authorized; rotation
      mutates host credential state and is never implied by repository access.
    - The credential tool is caller- or operator-selected per host and agent family;
      the names below are this operator's routes, not a universal prescription. On
      macOS with Claude credentials the route is `claude-acct` (Keychain-backed);
      file-backed Codex, Gemini, Linux, or WSL credentials use `caam`. Never use
      `caam` for macOS Claude account operations.
    - Verify account identity through the target runtime; token bytes are not account
      identity.
    - If neither the selected credential tool nor a runtime identity probe is
      available, report that absence as a disclosed fact and stop. Never fall back to
      diffing credential-file bytes to declare a switch done.
    - Existing processes retain credentials already loaded in memory. Rotation
      affects a new process.
    - This skill does not restart work, resume a task, select a pane, move repository
      state, or decide what happens after the switch.
    
    Return the host, agent family, selected tool, requested account/profile, the
    identity observed before and after the switch, whether any live runtime still
    holds the previous account (a partial rotation), the command exit code, and
    whether a new process is required for the new identity to hold.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related