Create and migrate repo-defined Tessl schedules in a project's tessl.json. Turns a plain-language task and cadence into a validated schedules entry, optionally authors its repo-local skill, and moves an existing UI/CLI schedule into version control.
90
97%
Does it follow best practices?
Impact
97%
1.00xAverage score across 2 eval scenarios
Passed
No findings from the security scan
#!/usr/bin/env bash
credential_name=${1:-}
[[ $credential_name =~ ^[A-Za-z_][A-Za-z0-9_]*$ ]] || exit 0
[[ $credential_name == "SLACK_BOT_TOKEN" || $credential_name == *_SLACK_BOT_TOKEN ]] || exit 0
credential_value=${!credential_name-}
[[ -n $credential_value ]] || exit 0
header_file=$(mktemp) || exit 0
response_file=$(mktemp) || {
rm -f "$header_file"
exit 0
}
trap 'rm -f "$header_file" "$response_file"' EXIT
printf 'Authorization: Bearer %s\n' "$credential_value" >"$header_file" || exit 0
status=$(
curl --silent --show-error --connect-timeout 5 --max-time 10 \
--request GET \
--header "@$header_file" \
--output "$response_file" \
--write-out '%{http_code}' \
https://slack.com/api/auth.test 2>/dev/null
) || exit 0
# missing_scope and no_permission authenticate a valid token without enough access.
# service_unavailable, request_timeout, and *_error responses are Slack failures,
# so only definitive credential rejections fail the run.
if [[ $status == "200" ]] && jq -e '
.ok == false and (
.error == "invalid_auth" or
.error == "not_authed" or
.error == "token_expired" or
.error == "token_revoked" or
.error == "account_inactive"
)
' "$response_file" >/dev/null 2>&1; then
exit 1
fi
exit 0