Per official docs, agents are invoked via /agent, naming them in a prompt
("Use the conductor agent to..."), or --agent=NAME — never @name. Replaced
all @conductor-style examples. Also documented an observed limitation:
plugin-sourced agents are launchable (by name or --agent flag, both
verified live) but copilot's own 'plugins list' explicitly says custom-agent
introspection isn't finished yet, which likely explains why they aren't
proactively suggested/listed even though they work when named explicitly.
scripts/setup-npm-registry.mjs configures npm to pull @redsentech
packages (e.g. @redsentech/lean-harness) from GitHub Packages:
- Discovers a token: --token flag > env (NPM_REGISTRY_TOKEN/
GITHUB_TOKEN/GH_TOKEN) > `gh auth token` > interactive masked prompt
(raw-mode stdin, no echo, no external deps).
- Verifies the token against the GitHub API, reports the authenticated
login, and warns if the OAuth scopes are missing read:packages/
write:packages.
- Writes/updates only its own two lines in .npmrc (scope registry +
auth token), preserving every other line; idempotent on rerun.
- Never prints the full token (masked in all output).
- --dry-run, --unset (clean removal), --local, --scope, --registry,
--skip-verify, --npmrc <path> flags.
- Confirms the result with `npm whoami --registry ...`.
Verified live end-to-end: real GitHub PAT via `gh auth token` ->
verified against api.github.com -> written to a scratch .npmrc ->
`npm whoami` succeeded. Also confirmed the scope-warning is accurate:
installing @redsentech/lean-harness with a token lacking read:packages
correctly 403s, exactly as the script warns it will.
Adds tests/setup-npm-registry.test.mjs (7 hermetic tests: dry-run,
write+preserve, token never printed, idempotent rerun, --unset,
custom scope/registry, clean failure with no token). Adds
"setup-npm-registry" npm script. Documents the script in README (The
`lh` CLI section) and docs/QUICKSTART.md (install + troubleshooting).
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
- Add exhaustive table of every lh subcommand: who runs it automatically
(agents, per their own instructions) vs what you run yourself (init,
doctor, report).
- Reorder quickstart to lead with copilot plugin install (marketplace
path, verified end-to-end on this machine), with onboarding script and
clone+link as alternatives and explicit guidance on when to use each.
- Clarify the two-layer install model: plugin install only adds the
behaviour layer; lh CLI (determinism layer) is a separate step until
published to npm.
- README install section and troubleshooting table updated to match.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>