Skip to content

fix(auth): stop blocklisting GH_TOKEN / GITHUB_TOKEN - #12

Merged
sahilm-ti merged 1 commit into
mainfrom
fix/gh-token-blocklist
May 25, 2026
Merged

sahilm-ti merged 1 commit into
mainfrom
fix/gh-token-blocklist

Conversation

@sahilm-ti

Copy link
Copy Markdown
Owner

Why

Kanban workers can't run `gh pr create` / `git push` even with `GH_TOKEN` set in their profile `.env`, because the Copilot provider's `api_key_env_vars` tuple lists `GH_TOKEN` / `GITHUB_TOKEN` → `_build_provider_env_blocklist` strips them from every terminal subprocess. Users have to add a per-profile `terminal.env_passthrough` allowlist to work around it.

`GH_TOKEN` / `GITHUB_TOKEN` are general-purpose `gh` CLI / git auth vars (used by every git remote helper, CI job, and dev machine) — not Hermes-managed provider credentials. Only `COPILOT_GITHUB_TOKEN` is Copilot-specific.

Kanban task: `t_e9b3a894`. Recent symptom: `t_b212a749` where orchestrator had to open the PR by hand.

What

  • `hermes_cli/auth.py` — Copilot `api_key_env_vars` → `("COPILOT_GITHUB_TOKEN",)`.
  • `hermes_cli/providers.py` — matching trim on the `github-copilot` overlay.
  • `tools/environments/local.py` — drop the explicit `GH_TOKEN` from the hardcoded extras in `_build_provider_env_blocklist`.
  • `hermes_cli/config.py` — `GITHUB_TOKEN` OPTIONAL_ENV_VARS entry moved from `category="tool"` to `category="skill"` (the skill bucket exists for vars that legitimately need subprocess passthrough).
  • `hermes_cli/setup.py` — `_model_section_has_credentials()` consults `copilot_auth.COPILOT_ENV_VARS` for the copilot provider so an explicit `model.provider: copilot` config + `GH_TOKEN` still registers as configured.
  • `copilot_auth.COPILOT_ENV_VARS` — unchanged, still the lookup precedence `(COPILOT_GITHUB_TOKEN, GH_TOKEN, GITHUB_TOKEN)`. Copilot users with a generic GitHub token keep working.

Tests

  • New regression `tests/tools/test_env_passthrough.py::test_gh_and_github_token_not_blocklisted` + `test_copilot_auth_lookup_still_finds_generic_github_tokens`.
  • Updated four existing tests that asserted the old wider tuple; each comment explains the split and points at `COPILOT_ENV_VARS` for the docs-facing precedence.

All 500 tests across `tests/hermes_cli/test_provider`, `test_copilot_auth`, `test_setup_openclaw_migration`, `test_setup_model_provider`, `test_doctor`, `tests/tools/test_env_passthrough`, `tests/tools/test_local_env_blocklist` pass locally.

Out of scope

  • The existing per-profile `env_passthrough` workaround for `braintrusteng` / `braintrustorch` (belt-and-braces — leave it).
  • No skill documents the blocklist behaviour; nothing to update there.

@coderabbitai

coderabbitai Bot commented May 25, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

@sahilm-ti, we couldn't start this review because you've used your available PR reviews for now.

Your plan includes 1 review of capacity. Refill in 52 minutes and 48 seconds.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more review capacity refills, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans have higher rate limits than trial, open-source, and free plans. In all cases, review capacity refills continuously over time.

Please see our FAQ for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 5489fdf1-772c-4062-96c8-1f3811276780

📥 Commits

Reviewing files that changed from the base of the PR and between a9aacf0 and 21a51c3.

📒 Files selected for processing (9)
  • hermes_cli/auth.py
  • hermes_cli/config.py
  • hermes_cli/providers.py
  • hermes_cli/setup.py
  • tests/hermes_cli/test_api_key_providers.py
  • tests/hermes_cli/test_copilot_auth.py
  • tests/tools/test_env_passthrough.py
  • tests/tools/test_local_env_blocklist.py
  • tools/environments/local.py
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/gh-token-blocklist

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@sahilm-ti

Copy link
Copy Markdown
Owner Author

auto-review: changes requested.

The PR can't merge as-is. Two blocking findings:

  • scope: PR shows 903 changed files / 271 commits / +146,350 / -3,820. Only 9 files are in the task body's authorized list:

    • hermes_cli/auth.py
    • hermes_cli/providers.py
    • hermes_cli/config.py
    • hermes_cli/setup.py
    • tools/environments/local.py
    • tests/tools/test_env_passthrough.py
    • tests/tools/test_local_env_blocklist.py
    • tests/hermes_cli/test_api_key_providers.py
    • tests/hermes_cli/test_copilot_auth.py

    Everything else (Dockerfile, ntfy platform adapter, TUI banner work, agent/transcription_provider, gateway/, docker/s6-rc.d/, .github/workflows/docker-lint.yml, README updates, etc.) is out of scope per ## Out of scope and the task body's enumerated edit list. Looks like the branch was cut from a stale fork base instead of upstream main.

  • mergeability: mergeStateStatus: DIRTY, mergeable: CONFLICTING. Cannot be merged.

Fix: rebase the auth fix onto a fresh main (the 9 enumerated files only) in a clean branch, force-push, and re-request review. The fix itself looks right at the source-file level — it's just buried under 270 unrelated commits.

@sahilm-ti
sahilm-ti force-pushed the main branch 2 times, most recently from 2953b46 to c2bc7a0 Compare May 25, 2026 15:12
@sahilm-ti
sahilm-ti force-pushed the fix/gh-token-blocklist branch from edfd71b to ae93de0 Compare May 25, 2026 16:23
@github-actions

Copy link
Copy Markdown

🚨 CRITICAL Supply Chain Risk Detected

This PR contains a pattern that has been used in real supply chain attacks. A maintainer must review the flagged code carefully before merging.

🚨 CRITICAL: Install-hook file added or modified

These files can execute code during package installation or interpreter startup.

Files:

hermes_cli/setup.py

Scanner only fires on high-signal indicators: .pth files, base64+exec/eval combos, subprocess with encoded commands, or install-hook files. Low-signal warnings were removed intentionally — if you're seeing this comment, the finding is worth inspecting.

@github-actions

github-actions Bot commented May 25, 2026 •

Copy link
Copy Markdown

🔎 Lint report: fix/gh-token-blocklist vs origin/main

ruff

Total: 0 on HEAD, 0 on base (➖ 0)

🆕 New issues: none

✅ Fixed issues: none

Unchanged: 0 pre-existing issues carried over.

ty (type checker)

Total: 9370 on HEAD, 9370 on base (➖ 0)

🆕 New issues: none

✅ Fixed issues: none

Unchanged: 4954 pre-existing issues carried over.

Diagnostics are surfaced as warnings — this check never fails the build.

@sahilm-ti

Copy link
Copy Markdown
Owner Author

auto-review: changes requested.

Scope + diff are clean now (9 in-scope files only, +99/-12, mergeable). Two required CI checks are blocking:

  • check-attribution (FAILED): commit ae93de0 is authored as braintrusteng-worker <braintrusteng@hermes.local> and that email is not in scripts/release.py AUTHOR_MAP. The workflow fails the PR until the mapping is added. Either:

    • add "braintrusteng@hermes.local": "<github-login>" to AUTHOR_MAP in scripts/release.py in a separate prior PR so this PR doesn't pick up an out-of-scope edit; or
    • amend the commit with --author="Sahil Marwaha <…@users.noreply.github.com>" (or any already-mapped identity) and force-push.
  • Supply Chain Audit (FAILED, CRITICAL): scanner fires on hermes_cli/setup.py because the filename matches the install-hook heuristic. This file is a hermes_cli module, not a distutils setup.py — false positive, but the check is required. Needs either a scanner allowlist for this path (separate PR against the workflow) or human override from a maintainer.

Tests workflow was still IN_PROGRESS at review time; if any test (*) job ends red, fix that too before re-requesting review.

GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.
@sahilm-ti
sahilm-ti force-pushed the fix/gh-token-blocklist branch from dcc8ec9 to 21a51c3 Compare May 25, 2026 17:20
@sahilm-ti

Copy link
Copy Markdown
Owner Author

auto-review: approved, awaiting human merge + kanban_approve.

Scope: 9 in-scope files only (+99/-12), matches AC exactly.
Mergeability: MERGEABLE / CLEAN.
CI: all required checks SUCCESS (check-attribution, supply-chain, ruff, ty, test 1-6, nix ubuntu+macos, e2e, common-ancestor, PyPI bounds, Windows footguns, CodeRabbit).
Author: Sahil Marwaha sahil@nousresearch.com (in AUTHOR_MAP).
Regression test covers GH_TOKEN/GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup preservation.

@sahilm-ti
sahilm-ti merged commit 03e3bb6 into main May 25, 2026
22 checks passed
sahilm-ti added a commit that referenced this pull request May 28, 2026
GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.

Co-authored-by: Sahil Marwaha <sahil@nousresearch.com>
sahilm-ti added a commit that referenced this pull request May 28, 2026
GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.

Co-authored-by: Sahil Marwaha <sahil@nousresearch.com>
sahilm-ti added a commit that referenced this pull request May 28, 2026
GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.

Co-authored-by: Sahil Marwaha <sahil@nousresearch.com>
sahilm-ti added a commit that referenced this pull request May 29, 2026
GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.

Co-authored-by: Sahil Marwaha <sahil@nousresearch.com>
sahilm-ti added a commit that referenced this pull request Jun 3, 2026
GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.

Co-authored-by: Sahil Marwaha <sahil@nousresearch.com>
sahilm-ti added a commit that referenced this pull request Jun 5, 2026
GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.

Co-authored-by: Sahil Marwaha <sahil@nousresearch.com>
sahilm-ti added a commit that referenced this pull request Jun 15, 2026
GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.

Co-authored-by: Sahil Marwaha <sahil@nousresearch.com>
sahilm-ti added a commit that referenced this pull request Jun 17, 2026
GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.

Co-authored-by: Sahil Marwaha <sahil@nousresearch.com>
sahilm-ti added a commit that referenced this pull request Jun 22, 2026
GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.

Co-authored-by: Sahil Marwaha <sahil@nousresearch.com>
sahilm-ti added a commit that referenced this pull request Jul 3, 2026
GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.

Co-authored-by: Sahil Marwaha <sahil@nousresearch.com>
sahilm-ti added a commit that referenced this pull request Jul 9, 2026
GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.

Co-authored-by: Sahil Marwaha <sahil@nousresearch.com>
sahilm-ti added a commit that referenced this pull request Jul 10, 2026
GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.

Co-authored-by: Sahil Marwaha <sahil@nousresearch.com>
sahilm-ti added a commit that referenced this pull request Jul 11, 2026
GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.

Co-authored-by: Sahil Marwaha <sahil@nousresearch.com>
sahilm-ti added a commit that referenced this pull request Jul 13, 2026
GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.

Co-authored-by: Sahil Marwaha <sahil@nousresearch.com>
sahilm-ti added a commit that referenced this pull request Jul 15, 2026
GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.

Co-authored-by: Sahil Marwaha <sahil@nousresearch.com>
sahilm-ti added a commit that referenced this pull request Jul 17, 2026
GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.

Co-authored-by: Sahil Marwaha <sahil@nousresearch.com>
sahilm-ti added a commit that referenced this pull request Jul 21, 2026
GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.

Co-authored-by: Sahil Marwaha <sahil@nousresearch.com>
sahilm-ti added a commit that referenced this pull request Jul 23, 2026
GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.

Co-authored-by: Sahil Marwaha <sahil@nousresearch.com>
sahilm-ti added a commit that referenced this pull request Jul 28, 2026
GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.

Co-authored-by: Sahil Marwaha <sahil@nousresearch.com>
sahilm-ti added a commit that referenced this pull request Aug 24, 2026
GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.

Co-authored-by: Sahil Marwaha <sahil@nousresearch.com>
sahilm-ti added a commit that referenced this pull request Sep 2, 2026
GH_TOKEN and GITHUB_TOKEN are general-purpose gh CLI / git auth
variables — used by every git remote helper, CI job, and developer
machine. Listing them on the Copilot provider's api_key_env_vars
propagated them into _HERMES_PROVIDER_ENV_BLOCKLIST and silently
stripped them from every terminal subprocess, breaking 'gh pr
create', 'git push', 'gh auth status' for kanban workers.

Changes:
- hermes_cli/auth.py: Copilot provider api_key_env_vars scoped to
  ('COPILOT_GITHUB_TOKEN',). Generic GitHub tokens stay reachable
  via copilot_auth.COPILOT_ENV_VARS (lookup precedence unchanged).
- hermes_cli/providers.py: same trim on the github-copilot overlay
  extra_env_vars tuple.
- tools/environments/local.py: drop the explicit 'GH_TOKEN' entry
  from the hardcoded extras set in _build_provider_env_blocklist.
- hermes_cli/config.py: re-category GITHUB_TOKEN from 'tool' to
  'skill' so OPTIONAL_ENV_VARS no longer feeds it into the blocklist
  (the 'skill' category exists precisely for vars that legitimately
  need subprocess passthrough).
- hermes_cli/setup.py: _model_section_has_credentials() now consults
  copilot_auth.COPILOT_ENV_VARS when checking the copilot provider so
  an explicit copilot config + GH_TOKEN still counts as configured.

Tests:
- tests/tools/test_env_passthrough.py: new regression covering
  GH_TOKEN / GITHUB_TOKEN passthrough + COPILOT_ENV_VARS lookup.
- Updated affected blocklist/api-key tests to assert the new shape
  while pointing at copilot_auth.COPILOT_ENV_VARS for the full
  lookup precedence (docs-facing list unchanged in behaviour).

Refs kanban task t_e9b3a894.

Co-authored-by: Sahil Marwaha <sahil@nousresearch.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant