MCPcopy Create free account
hub / github.com/UsefulSoftwareCo/executor / smuggleSecretCode

Function smuggleSecretCode

e2e/scenarios/oauth-client-handoff.test.ts:95–110  ·  view source on GitHub ↗
(input: {
  readonly integration: string;
  readonly slug: string;
  readonly clientId: string;
  readonly tokenUrl: string;
})

Source from the content-addressed store, hash-verified

93// the boundary does with the excess field (drop or reject), the secret VALUE
94// must not appear anywhere in the agent-visible result.
95const smuggleSecretCode = (input: {
96 readonly integration: string;
97 readonly slug: string;
98 readonly clientId: string;
99 readonly tokenUrl: string;
100}) => `
101const handoff = await tools.executor.coreTools.oauth.clients.createHandoff({
102 integration: ${JSON.stringify(input.integration)},
103 slug: ${JSON.stringify(input.slug)},
104 grant: "client_credentials",
105 clientId: ${JSON.stringify(input.clientId)},
106 tokenUrl: ${JSON.stringify(input.tokenUrl)},
107 clientSecret: ${JSON.stringify(SMUGGLED_SECRET)},
108});
109return JSON.stringify(handoff);
110`;
111
112scenario(
113 "OAuth client · createHandoff returns a secret-free deep link and is not approval-gated",

Callers 1

Calls

no outgoing calls

Tested by

no test coverage detected