Originally created by: kumaakh
| Tool | Description |
|---|---|
| credential_store_set | Collect secret OOB, store encrypted (session or persistent) |
| credential_store_list | List stored credentials by name/scope — no values returned |
| credential_store_delete | Delete a named credential |
| Tool | Field(s) |
|---|---|
| execute_command | command, restart_command |
| register_member | password |
| update_member | password |
| provision_vcs_auth | token (GitHub), api_token (Bitbucket), pat (Azure DevOps) |
| provision_auth | api_key |
Tokens resolved server-side — LLM never sees plaintext. Output redacted ([REDACTED:NAME]) including monitor_task output. Network egress policy (allow/confirm/deny) with OOB TTY confirmation.
Reviewed by fleet-rev — APPROVED. All 9 findings addressed (2 HIGH, 4 MED, 3 LOW).
🤖 Generated with Claude Code
Tickets: #109
Tickets: #134
Tickets: #142
Tickets: #92
Tickets: #96
Ticket changed by: kumaakh