Wangxiaobao CLI Shared Rules
Paste the following prompt into your AI chat to install this skill:
Please install @user_2d5fa379/wangxiaobao-shared following https://skillhub.cn/install/skillhub.md.
About this skill
Problem
Wangxiaobao CLI business commands depend on login state, active project, tenant headers, and data permissions. If an agent runs commands directly or invokes blocking xiaobao-cli auth login, it may block polling, misread stderr, leak credentials into context, or mishandle NOT_AUTHENTICATED / NO_ACTIVE_PROJECT. This skill centralizes those cross-command constraints into a readable protocol so other Wangxiaobao skills establish the same invocation preconditions first.
How it works and key steps
- Non-blocking login: use
--no-wait split-flowto obtain the OAuth device flowverification_link, paste it verbatim into the reply body, without URL encoding, rewriting, or code blocks; end the turn after sending and let the user authorize in the browser. - Consume only
stdout: parse success and failure results fromstdout; treatstderras human assistance only. Defaulttoonoptimizes context tokens; use--format jsonwhen strict machine-readable output is needed. - Self-heal via
hint: error objects includeerror,message, andhint. OnNOT_AUTHENTICATEDorNO_ACTIVE_PROJECT, follow thehintaction rather than asking the user for guidance. - Readable local state without exposure: tokens, active project, and pending auth are stored in local JSON files with
0600permissions; agents must not print tokens and should use identity commands such aswhoamifor user info. - Permissions and exceptions: business list commands are filtered by the current user’s authorization scope,
kb *is isolated by active project, andadmin *uses an independent whitelist; time values useyyyy-MM-dd HH:mm:ss.
Use Cases
- Before invoking Wangxiaobao business commands, an agent applies the shared protocol for login, active project, and stdout rules to avoid blocking auth login.
- During OAuth device flow login, the agent sends verification_link verbatim in the reply body and ends the turn so the user can authorize in the browser.
- When commands return NOT_AUTHENTICATED or NO_ACTIVE_PROJECT, the agent follows the error hint to log in or select a project instead of asking the user.
- When parsing audio list, customer list, and similar commands, the agent reads stdout only and distinguishes machine results from stderr hints by toon or json.
Best For
- Agent developers integrating Wangxiaobao CLI who need one shared set of invocation preconditions across business skills.
- Enterprise SaaS developers who need non-blocking OAuth login, token expiry handling, and missing active project recovery.
- Backend or CLI engineers who need consistent stdout parsing and error hint handling without treating stderr as the result.
- Platform tooling developers who need clear boundaries for business list permissions, project-level kb isolation, and admin whitelist access.
Related Skills
Automatically indexes Gradle-cached AAR/JAR dependency classes and returns library coordinates, versions, and public APIs by fully qualified name, using only the Python standard library.
Codifies AMT and YourMT3 training conventions, script patterns, hyperparameters, precision, checkpoints, and NaN safeguards.
Retrieve relevant chunks from a customer-managed PKM dataset by dataset_id and return concise, source-annotated answers.
Convert PRDs, user stories, or functional specs into prioritized test-point checklists covering functional, business-rule, boundary, exception, and non-functional dimensions.