From 3f2474f08baf7c7234cabf383504432f67754dae Mon Sep 17 00:00:00 2001 From: Santiago Medina Rolong Date: Sun, 11 Oct 2026 01:26:43 +0000 Subject: [PATCH] Ask about remembering the X Chat key as a separate question The PIN secret-request only has a masked field, so a remember question inside that card never gets an answer. Send a Yes/No question widget alongside it and add --remember-key only on a clear Yes. --- third_party/x/.cursor-plugin/plugin.json | 2 +- third_party/x/CHANGELOG.md | 4 ++++ third_party/x/skills/x-api-mcp-guide/SKILL.md | 6 +++--- 3 files changed, 8 insertions(+), 4 deletions(-) diff --git a/third_party/x/.cursor-plugin/plugin.json b/third_party/x/.cursor-plugin/plugin.json index 3ac3ade26..4de9b94fc 100644 --- a/third_party/x/.cursor-plugin/plugin.json +++ b/third_party/x/.cursor-plugin/plugin.json @@ -1,7 +1,7 @@ { "name": "x", "displayName": "X", - "version": "2.6.0", + "version": "2.6.1", "minClientVersions": { "cursor": "3.13.0" }, diff --git a/third_party/x/CHANGELOG.md b/third_party/x/CHANGELOG.md index 849409f41..cd2474037 100644 --- a/third_party/x/CHANGELOG.md +++ b/third_party/x/CHANGELOG.md @@ -2,6 +2,10 @@ All notable changes to this plugin will be documented here. +## 2.6.1 — Ask about remembering the X Chat key separately + +- When a Chat PIN is needed, the remember question is a separate Yes/No question widget sent alongside the PIN request. `--remember-key` is added only on a clear Yes. No does not save the key. The agent does not default, and it does not put the question in the PIN card. + ## 2.6.0 — Remember the X Chat key and read every chat - Every Chat PIN request also asks whether to remember the X Chat key on this computer so the owner won't need the PIN next time, noting that anyone with access to the computer could then read their X Chats. Default is no. When a saved key works, the agent uses it without asking for the PIN and mentions that `forget` removes it. diff --git a/third_party/x/skills/x-api-mcp-guide/SKILL.md b/third_party/x/skills/x-api-mcp-guide/SKILL.md index d8806ecd8..c5c1cb1ee 100644 --- a/third_party/x/skills/x-api-mcp-guide/SKILL.md +++ b/third_party/x/skills/x-api-mcp-guide/SKILL.md @@ -461,11 +461,11 @@ If the owner agrees, the helper keeps their X Chat private key on this computer Run `unlock-check` before asking for the PIN. If it prints `"key_source": "saved"`, use the saved key and do not ask for the PIN. -Every time you secret-request the Chat PIN, ask in that same prompt: +Every time you secret-request the Chat PIN, also send a separate yes/no question widget alongside it, with options Yes and No. Do not put the question in the PIN card's description. Ask: > Should I remember your X Chat key on this computer so you won't need your PIN next time? Anyone with access to this computer could then read your X Chats. -Default is no: add `--remember-key` to the next `unlock-check` only if the owner clearly says yes. Never ask about remembering at any other time. +Wait for the answer. Add `--remember-key` to the next `unlock-check` only on a clear Yes. On No, do not save the key. Do not default. Never ask about remembering at any other time. The first time in a session that `unlock-check` prints `"key_saved": true`, tell the owner: @@ -481,7 +481,7 @@ When they ask, run `$HELPER $SCRIPT forget`. If a run with `--remember-key` prin 4. Persist `juicebox_config` as JSON (chmod 600). 5. Note `public_key_version` as `--key-version`. 6. `unlock-check`. If it prints `"key_source": "saved"`, use the saved key: do not ask for the PIN, and skip step 7. -7. If it stops because `CHAT_PIN` is not set (it does when a saved key no longer matches and no PIN is stored), secret-request **Chat PIN** → `CHAT_PIN` and ask the [Saved key](#saved-key) question in the same prompt. Then run `unlock-check` again, with `--remember-key` only if the owner said yes. +7. If it stops because `CHAT_PIN` is not set (it does when a saved key no longer matches and no PIN is stored), secret-request **Chat PIN** → `CHAT_PIN` and send the [Saved key](#saved-key) yes/no question widget alongside it. Then run `unlock-check` again, with `--remember-key` only on a clear Yes. 8. On unlock failure: wrong PIN, wrong `--user-id` (must be the X id from `get_users_me`, not the OS `$UID`), incomplete Chat onboarding, or stale juicebox — refresh public key / juicebox; do not brute-force the PIN. ### Read / summarize