Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion third_party/x/.cursor-plugin/plugin.json
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
{
"name": "x",
"displayName": "X",
"version": "2.6.0",
"version": "2.6.1",
"minClientVersions": {
"cursor": "3.13.0"
},
Expand Down
4 changes: 4 additions & 0 deletions third_party/x/CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,10 @@

All notable changes to this plugin will be documented here.

## 2.6.1 — Ask about remembering the X Chat key separately

- When a Chat PIN is needed, the remember question is a separate Yes/No question widget sent alongside the PIN request. `--remember-key` is added only on a clear Yes. No does not save the key. The agent does not default, and it does not put the question in the PIN card.

## 2.6.0 — Remember the X Chat key and read every chat

- Every Chat PIN request also asks whether to remember the X Chat key on this computer so the owner won't need the PIN next time, noting that anyone with access to the computer could then read their X Chats. Default is no. When a saved key works, the agent uses it without asking for the PIN and mentions that `forget` removes it.
Expand Down
6 changes: 3 additions & 3 deletions third_party/x/skills/x-api-mcp-guide/SKILL.md
Original file line number Diff line number Diff line change
Expand Up @@ -461,11 +461,11 @@ If the owner agrees, the helper keeps their X Chat private key on this computer

Run `unlock-check` before asking for the PIN. If it prints `"key_source": "saved"`, use the saved key and do not ask for the PIN.

Every time you secret-request the Chat PIN, ask in that same prompt:
Every time you secret-request the Chat PIN, also send a separate yes/no question widget alongside it, with options Yes and No. Do not put the question in the PIN card's description. Ask:

> Should I remember your X Chat key on this computer so you won't need your PIN next time? Anyone with access to this computer could then read your X Chats.

Default is no: add `--remember-key` to the next `unlock-check` only if the owner clearly says yes. Never ask about remembering at any other time.
Wait for the answer. Add `--remember-key` to the next `unlock-check` only on a clear Yes. On No, do not save the key. Do not default. Never ask about remembering at any other time.

The first time in a session that `unlock-check` prints `"key_saved": true`, tell the owner:

Expand All @@ -481,7 +481,7 @@ When they ask, run `$HELPER $SCRIPT forget`. If a run with `--remember-key` prin
4. Persist `juicebox_config` as JSON (chmod 600).
5. Note `public_key_version` as `--key-version`.
6. `unlock-check`. If it prints `"key_source": "saved"`, use the saved key: do not ask for the PIN, and skip step 7.
7. If it stops because `CHAT_PIN` is not set (it does when a saved key no longer matches and no PIN is stored), secret-request **Chat PIN** → `CHAT_PIN` and ask the [Saved key](#saved-key) question in the same prompt. Then run `unlock-check` again, with `--remember-key` only if the owner said yes.
7. If it stops because `CHAT_PIN` is not set (it does when a saved key no longer matches and no PIN is stored), secret-request **Chat PIN** → `CHAT_PIN` and send the [Saved key](#saved-key) yes/no question widget alongside it. Then run `unlock-check` again, with `--remember-key` only on a clear Yes.
8. On unlock failure: wrong PIN, wrong `--user-id` (must be the X id from `get_users_me`, not the OS `$UID`), incomplete Chat onboarding, or stale juicebox — refresh public key / juicebox; do not brute-force the PIN.

### Read / summarize
Expand Down
Loading