Skip to content
Back to skills

Account Rotation

ASecurity

Switch coding-agent accounts and verify runtime identity. Use when: the caller requests an account change; never rotate automatically to evade a quota.

  • 446 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 2, 2026
ai-agentsgoapi

Works with

  • api

Security analysis

A100/100

Scanned September 12, 2026

npx -y skills add boshu2/agentops --skill account-rotation --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Account Rotation?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Account Rotation
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/boshu2-account-rotation/badge)](https://www.skillsdirectory.com/skills/boshu2-account-rotation)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: account-rotation
user-invocable: true
skill_api_version: 1
hexagonal_role: supporting
consumes: []
produces: []
context_rel: []
metadata:
  dependencies: []
  capabilities: [account_rotation]
  effects: [rotate_agent_account]
  canonical_status: canonical
  disposition: keep_optional_adapter
  tier: execution
description: 'Switch coding-agent accounts and verify runtime identity. Use when: the caller requests an account change; never rotate automatically to evade a quota.'
practices:
- pragmatic-programmer
output_contract: observed account identity and command status
---
# Account rotation — credential adapter

Choose the credential tool from both host and agent family, perform only the
explicit account switch, and report the identity observed by the matching
runtime.

Verifying identity through the target runtime works because the runtime is the
only party whose opinion matters: credential files can be swapped perfectly
and still authenticate as the old account in an already-running process.

Named failure mode — **stale-process identity**: declaring the rotation done
while every live session still holds the previous account's tokens in memory.

Anti-pattern: confirming a switch by diffing credential file bytes.
Corrective: ask the matching runtime who it is now, and report whether a new
process is required for the answer to hold.

## Boundary

- Perform only the account switch the caller explicitly authorized; rotation
  mutates host credential state and is never implied by repository access.
- The credential tool is caller- or operator-selected per host and agent family;
  the names below are this operator's routes, not a universal prescription. On
  macOS with Claude credentials the route is `claude-acct` (Keychain-backed);
  file-backed Codex, Gemini, Linux, or WSL credentials use `caam`. Never use
  `caam` for macOS Claude account operations.
- Verify account identity through the target runtime; token bytes are not account
  identity.
- If neither the selected credential tool nor a runtime identity probe is
  available, report that absence as a disclosed fact and stop. Never fall back to
  diffing credential-file bytes to declare a switch done.
- Existing processes retain credentials already loaded in memory. Rotation
  affects a new process.
- This skill does not restart work, resume a task, select a pane, move repository
  state, or decide what happens after the switch.

Return the host, agent family, selected tool, requested account/profile, the
identity observed before and after the switch, whether any live runtime still
holds the previous account (a partial rotation), the command exit code, and
whether a new process is required for the new identity to hold.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…