AI Agent Hub
Back to skills
Wangxiaobao CLI Shared Rules icon

Wangxiaobao CLI Shared Rules

Development Updated 2026.08.29

Paste the following prompt into your AI chat to install this skill:

Please install @user_2d5fa379/wangxiaobao-shared following https://skillhub.cn/install/skillhub.md.

About this skill

Problem

Wangxiaobao CLI business commands depend on login state, active project, tenant headers, and data permissions. If an agent runs commands directly or invokes blocking xiaobao-cli auth login, it may block polling, misread stderr, leak credentials into context, or mishandle NOT_AUTHENTICATED / NO_ACTIVE_PROJECT. This skill centralizes those cross-command constraints into a readable protocol so other Wangxiaobao skills establish the same invocation preconditions first.

How it works and key steps

  • Non-blocking login: use --no-wait split-flow to obtain the OAuth device flow verification_link, paste it verbatim into the reply body, without URL encoding, rewriting, or code blocks; end the turn after sending and let the user authorize in the browser.
  • Consume only stdout: parse success and failure results from stdout; treat stderr as human assistance only. Default toon optimizes context tokens; use --format json when strict machine-readable output is needed.
  • Self-heal via hint: error objects include error, message, and hint. On NOT_AUTHENTICATED or NO_ACTIVE_PROJECT, follow the hint action rather than asking the user for guidance.
  • Readable local state without exposure: tokens, active project, and pending auth are stored in local JSON files with 0600 permissions; agents must not print tokens and should use identity commands such as whoami for user info.
  • Permissions and exceptions: business list commands are filtered by the current user’s authorization scope, kb * is isolated by active project, and admin * uses an independent whitelist; time values use yyyy-MM-dd HH:mm:ss.

Use Cases

  • Before invoking Wangxiaobao business commands, an agent applies the shared protocol for login, active project, and stdout rules to avoid blocking auth login.
  • During OAuth device flow login, the agent sends verification_link verbatim in the reply body and ends the turn so the user can authorize in the browser.
  • When commands return NOT_AUTHENTICATED or NO_ACTIVE_PROJECT, the agent follows the error hint to log in or select a project instead of asking the user.
  • When parsing audio list, customer list, and similar commands, the agent reads stdout only and distinguishes machine results from stderr hints by toon or json.

Best For

  • Agent developers integrating Wangxiaobao CLI who need one shared set of invocation preconditions across business skills.
  • Enterprise SaaS developers who need non-blocking OAuth login, token expiry handling, and missing active project recovery.
  • Backend or CLI engineers who need consistent stdout parsing and error hint handling without treating stderr as the result.
  • Platform tooling developers who need clear boundaries for business list permissions, project-level kb isolation, and admin whitelist access.