Skip to content
Back to skills

Side Peace

BSecurity

Minimal secure secret handoff. Zero external deps. Human opens browser form, submits secret, agent receives it via temp file. Secret NEVER appears in stdout/logs.

  • 10 stars
  • 0 votes
  • 0 copies
  • 9 views
  • Added May 30, 2026
securityrustbashnodeapisecurity

Works with

  • api

Security analysis

B88/100
  • criticalSends environment variables or credentials to an external URL

Pro scans all 3 files and shows the line behind each finding

Scanned May 30, 2026

npx -y skills add Demerzels-lab/elsamultiskillagent --skill side-peace --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Side Peace?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Side Peace
[![Security: B โ€” Skills Directory](https://www.skillsdirectory.com/api/skills/demerzels-lab-side-peace/badge)](https://www.skillsdirectory.com/skills/demerzels-lab-side-peace)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: side-peace
version: 1.1.0
description: Minimal secure secret handoff. Zero external deps. Human opens browser form, submits secret, agent receives it via temp file. Secret NEVER appears in stdout/logs.
---

# Side_Peace ๐Ÿ’

Dead simple secret handoff from human to AI. No npm packages to trust โ€” just Node.js built-ins.

**Key security feature:** Secret is written to a temp file, NEVER printed to stdout. This prevents secrets from appearing in chat logs or command output.

## How It Works

1. Agent runs `node drop.js --label "API Key"`
2. Agent shares the URL with human
3. Human opens URL in browser, pastes secret, submits
4. Secret is saved to temp file (printed path only, not content)
5. Agent reads file, uses secret, deletes file

## Usage

```bash
# Basic - secret saved to random temp file
node skills/side-peace/drop.js --label "CLAWHUB_TOKEN"

# Custom output path
node skills/side-peace/drop.js --label "API_KEY" --output /tmp/my-secret.txt

# Custom port
node skills/side-peace/drop.js --port 4000 --label "TOKEN"
```

## Reading the Secret

After receiving, the secret is in the temp file:

```bash
# Read and use (example with clawhub)
SECRET=$(cat /tmp/side-peace-xxx.secret)
npx clawhub login --token "$SECRET" --no-browser
rm /tmp/side-peace-xxx.secret
```

Or one-liner:
```bash
cat /tmp/side-peace-xxx.secret | xargs -I{} npx clawhub login --token {} --no-browser; rm /tmp/side-peace-xxx.secret
```

## Security

- **Zero dependencies** โ€” only Node.js built-ins
- **Secret never in stdout** โ€” written to file with 0600 permissions
- **Memory only until saved** โ€” temp file deleted after use
- **One-time** โ€” server exits after receiving
- **~60 lines** โ€” fully auditable

## Output

```
๐Ÿ’ Side_Peace waiting...
   Label: CLAWHUB_TOKEN
   Output: /tmp/side-peace-a1b2c3d4.secret

   Local:    http://localhost:3000
   Network:  http://192.168.1.94:3000

Waiting for secret...

โœ“ Secret received and saved.
  File: /tmp/side-peace-a1b2c3d4.secret
  (Secret is NOT printed to stdout for security)
```

The secret is in the file. Read it, use it, delete it.

Files in this skill

  • SKILL.md2.1 KB
  • _meta.json280 B
  • drop.js3.5 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading commentsโ€ฆ