← 返回
AI智能 中文

Side Peace

Minimal secure secret handoff. Zero external deps. Human opens browser form, submits secret, agent receives it via temp file. Secret NEVER appears in stdout/logs.
极简安全秘密传递,零外部依赖。用户通过浏览器表单提交秘密,Agent通过临时文件接收。秘密绝不出现于标准输出或日志中。
bitbrujo
AI智能 clawhub v1.1.1 1 版本 99621.4 Key: 无需
★ 1
Stars
📥 2,348
下载
💾 251
安装
1
版本
#latest

概述

Side_Peace 🍒

Dead simple secret handoff from human to AI. No npm packages to trust — just Node.js built-ins.

Key security feature: Secret is written to a temp file, NEVER printed to stdout. This prevents secrets from appearing in chat logs or command output.

How It Works

  1. Agent runs node drop.js --label "API Key"
  2. Agent shares the URL with human
  3. Human opens URL in browser, pastes secret, submits
  4. Secret is saved to temp file (printed path only, not content)
  5. Agent reads file, uses secret, deletes file

Usage

# Basic - secret saved to random temp file
node skills/side-peace/drop.js --label "CLAWHUB_TOKEN"

# Custom output path
node skills/side-peace/drop.js --label "API_KEY" --output /tmp/my-secret.txt

# Custom port
node skills/side-peace/drop.js --port 4000 --label "TOKEN"

Reading the Secret

After receiving, the secret is in the temp file:

# Read and use (example with clawhub)
SECRET=$(cat /tmp/side-peace-xxx.secret)
npx clawhub login --token "$SECRET" --no-browser
rm /tmp/side-peace-xxx.secret

Or one-liner:

cat /tmp/side-peace-xxx.secret | xargs -I{} npx clawhub login --token {} --no-browser; rm /tmp/side-peace-xxx.secret

Security

  • Zero dependencies — only Node.js built-ins
  • Secret never in stdout — written to file with 0600 permissions
  • Memory only until saved — temp file deleted after use
  • One-time — server exits after receiving
  • ~60 lines — fully auditable

Output

🍒 Side_Peace waiting...
   Label: CLAWHUB_TOKEN
   Output: /tmp/side-peace-a1b2c3d4.secret

   Local:    http://localhost:3000
   Network:  http://192.168.1.94:3000

Waiting for secret...

✓ Secret received and saved.
  File: /tmp/side-peace-a1b2c3d4.secret
  (Secret is NOT printed to stdout for security)

The secret is in the file. Read it, use it, delete it.

版本历史

共 1 个版本

  • v1.1.1 当前
    2026-03-28 14:50 安全 安全

安全检测

腾讯云安全 (Keen)

安全,无风险
查看报告

腾讯云安全 (Sanbu)

安全,无风险
查看报告

🔗 相关推荐

developer-tools

Agent Church

bitbrujo
通过SOUL.md实现AI智能体的身份塑造、肖像生成、复活与进化
★ 5 📥 5,052
ai-intelligence

Self-Improving + Proactive Agent

ivangdavila
自我反思+自我批评+自我学习+自组织记忆。智能体评估自身工作、发现错误并持续改进。
★ 1,350 📥 317,757
ai-intelligence

ontology

oswalpalash
类型化知识图谱,用于结构化智能体记忆与可组合技能。支持创建/查询实体(人员、项目、任务、事件、文档)及关联...
★ 709 📥 243,563