Syndroodocs

Use with an Agent

Syndroo contains no language model and no natural-language step. An agent calls the same three commands a person does and reads a stable JSON envelope instead of English. The protocol is the contract; the prose in a terminal is a convenience.

Always ask for JSON

--json is a global flag, so it is accepted before or after the command. On success the envelope carries the operation name and the result; on failure it carries a stable code and a fixed message that was never built from a stack, a path or an argument.

{
  "protocolVersion": 1,
  "operation": "publish",
  "ok": true,
  "result": { "status": "confirmation_required" },
  "error": null
}

The failure shape is the same envelope with ok set to false, result as null, and an error object holding a code and a message. Branch on code; do not parse the message.

Read the exit code as a family

0 means the call was handled as documented, which can still be a pending authorization or a preview that needs confirmation. Exit 4 means a write may have reached the provider and no result is known. Exit 6 means an execution finished and is known not to be fully successful. The other values cover usage and preflight refusals, an explicit decline, an internal failure and an interrupted process; the CLI reference lists all seven.

Two phases, and a token that stays on stdin

Prepare first, execute second. The prepared result carries the frozen preview and a single-use approvalToken, and the execute request may only be read from standard input:

syndroo publish --input post.json --json > prepared.json
syndroo publish --input - --json < execute.json

An execute request that arrives from a file path or from --data is refused, so a live token cannot be left in the process arguments of a background call. Nothing is sent between the two phases: the content is frozen at prepare time and the second phase cannot re-read the original input.

Give each logical call a stable identity

--request-id names one logical intent. Repeating the same call with the same id returns the recorded outcome instead of sending a second time, and reusing an id with different content is refused rather than silently overwriting the earlier record. For a connection, the same guarantee is built in: a repeated connect request replays the stored step.

Never put a credential in the request document

Credentials travel in SYNDROO_CREDENTIALS or a private file, never in the publish document and never in --data. If the content must stay out of the process arguments, read the request from standard input with --input - instead of passing it inline.

The packaged Skill

The packed CLI ships a skills/ directory, so an agent harness can install the Skill together with the binary. The Skill text itself is maintained in the product repository rather than duplicated here, and this site does not restate its workflow as verified. UNRESOLVED.

Confirmation is not user authorization

A confirmation prompt is a local guardrail, not a grant of authority. An agent that runs without a human present is responsible for deciding whether the publication is allowed in the first place; the CLI only guarantees that nothing is sent before the prepare phase has produced a token for exactly this content and these targets.