Surfaced by a full completeness audit of the telegram skill against
TELEGRAM_PORT_MAP.md (366 tags, ~83% ported, 452/452 tests green).
@api — in-process set_secret(provider, slug, value, *, as_json) writer
mirroring get_secret (0o600 files / 0o700 dirs, no stdout echo). The store
was read-only; this is the GAP1 enabler the telegram mother-bot needs to
persist a created bot's config. 515 @api tests, seedgo 100%.
@skills telegram wave-1 (fix-forward, no deletions):
- GAP2: bot_factory + telegram-bot@.service launched a non-existent
~/.venv/bin/python3; now sys.executable -m ...base_bot (+ lib/__init__.py
and lib/telegram/__init__.py for package resolution).
- Reboot survival: enable_service now installs the unit to
~/.config/systemd/user/ + daemon-reload (was never installed).
- GAP9: gitignore lib/telegram/.local/ so runtime state stops leaking to git.
- prax-monitor: log_streamer now resolves repo-root system_logs (honoring
AIPASS_TEST_LOG_DIR) instead of a hardcoded ~/system_logs.
Verified: telegram 452/452 green (twice), base_bot imports via -m.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01QEQZXCtgnF3NQtcttTErpq
PR #640's only failing required check was Code scanning/CodeQL: 3 HIGH
py/clear-text-logging-sensitive-data alerts where get-secret printed raw secret
values to stdout. Research (OWASP, CodeQL rule source, secret-CLI survey)
confirmed a real exposure — acute for AIPass since it runs inside Claude Code,
which captures command stdout into model context, and the telegram skill
shelled out to get-secret and parsed the token from stdout.
@api (P1):
- NEW apps/modules/secrets.py — in-process cross-branch door (get_secret,
list_secrets) wrapping the auth handler; consumers import this, not the CLI.
- get_secret_cmd rewritten: masked summary by default ('slug: set (N chars)'),
--out FILE writes the raw value 0o600 and prints only the path, --list shows
slug names via console.print. All 3 raw-value print() sinks removed.
- bypass.json reasoning + README + help updated.
@skills (P2):
- telegram config._get_secret / list_bot_configs rewired from subprocess+stdout
parse to the in-process aipass.api.apps.modules.secrets API; subprocess/json
imports dropped. Tests + SKILL.md updated.
Also: seedgo test_checkers_batch2.py — comment the synthetic sk-or-v1 fixture
keys as FAKE (not real credentials).
Verified: @api 504 tests + seedgo 100%; telegram 452/452; skills 252/252; no
secret reaches stdout by any path.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>