feat(box): passkey fetch, agent key-approval flow, unified lookups, tmux agent UX

- box passkey [show|fetch] (+ muse passkey): documents VM-only passkey
  (/srv/box/passkey.txt, fallback /etc/netvm/passkey.txt on 34.139.37.135),
  probes VM over SSH with graceful fallback; --json supported. No secrets on bl.
- approvals: request_key_approval / check_node_key_request; KEY_APPROVAL status
  surfaced in `box approvals check`; allow/deny resolve + audit to box-ctl.jsonl;
  never auto-approved. New `box approvals request-key <node> --reason`.
- box lookup (summary|fleet|threads|unread|approvals|key|docs) and docs-lookup
  engine with lookup_internal/ database (docs_internal symlink).
- muse-tmux: non-TTY attach falls back to scrollback capture; prune NameError fix.
- box/muse passthrough for tmux/muse/docs; thread list/view alias + prefix resolve.
- Docs: AGENTS.md, AGENT-TOOLING.md, BOX-WEB-SURFACE-GUIDE.md, README.
- Tests: key-approval + passkey tests; sync stale sidechat UUIDs and manifest name.
- .gitignore runtime trackers (subagent-sessions, conversation-nudge-tracker).
This commit is contained in:
operator
2026-10-05 20:18:47 +00:00
parent 59c9965791
commit adfcd2e602
38 changed files with 5948 additions and 168 deletions
+15
View File
@@ -0,0 +1,15 @@
{
"name": "test-tmux-wo",
"description": "Verification job: execute background tmux task and report output",
"agent": "pip",
"schedule": null,
"timeout": 180,
"prompt_template": "Execute a verification command in your background tmux session and capture the output.\n1. Run [TOOL tmux.new {\"session\": \"worker-pip-test\", \"command\": \"bash\"}]\n2. Run [TOOL tmux.send {\"session\": \"worker-pip-test\", \"keys\": \"hostname && whoami && echo TMUX_VERIFIED_SUCCESS\"}]\n3. Capture the output with [TOOL tmux.capture {\"session\": \"worker-pip-test\", \"lines\": 10}]\n4. When done, reply with [RESULT {job_id}] OK: tmux test verified.",
"sidechat": {
"create": true,
"reuse_key": "test-tmux-wo",
"name_template": "test-tmux-wo-{date}"
},
"chain_next": null,
"on_failure": "alert"
}