{"id":"8c392d01-8d23-481b-b820-c87123691796","entityType":"agent","slug":"clawhub-dcenatiempo-tandoor-cli","name":"Tandoor Recipe CLI","canonicalUrl":"https://www.xpersona.co/agent/clawhub-dcenatiempo-tandoor-cli","canonicalPath":"/agent/clawhub-dcenatiempo-tandoor-cli","generatedAt":"2026-10-10T21:51:05.612Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T18:06:37.122Z","emptyReason":null},"description":"Manage recipes, meal plans, and shopping lists on a Tandoor Recipe Manager instance via CLI.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.3K downloads reported by the source. Last updated 10/10/2026.","installCommand":"clawhub skill install s174qsh3740skgwa1m8x5xsgpd8641p7:tandoor-cli","sourceUrl":"https://clawhub.ai/dcenatiempo/tandoor-cli","homepage":"https://clawhub.ai/dcenatiempo/skills/tandoor-cli","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/dcenatiempo/tandoor-cli","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/dcenatiempo/skills/tandoor-cli","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":62,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Tandoor Recipe CLI technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-10T18:06:37.122Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T18:06:37.122Z","emptyReason":null},"stars":null,"forks":null,"downloads":1304,"packageName":null,"latestVersion":"1.5.0","tractionLabel":"1.3K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T18:06:37.122Z","emptyReason":null},"lastUpdatedAt":"2026-10-10T18:06:37.122Z","lastCrawledAt":"2026-10-10T18:06:37.122Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-11T18:06:37.122Z","lastVerifiedAt":null,"highlights":[{"version":"1.5.0","createdAt":"2026-05-18T18:59:16.604Z","changelog":"v1.5.0 - Adds `--comment TEXT` to `cooklog add` and `cooklog update` commands for entering comments on cook logs. - `cooklog update` now allows updating individual fields without requiring all parameters, supporting partial updates. - No other significant changes; compatibility and security guidelines remain unchanged.","fileCount":6,"zipByteSize":17806},{"version":"1.4.0","createdAt":"2026-05-18T12:16:11.732Z","changelog":"tandoor-recipe-cli 1.4.0 adds supermarket/grocery ingredient category support: - New commands: `category list` and `category uncategorised` for managing grocery categories. - Write/modify support: Use `category set <food-id|name> --category <name|id>` and `--unset` to assign or remove categories from food items. - Updated documentation to include all new category-related commands and options.","fileCount":5,"zipByteSize":16446},{"version":"1.1.5","createdAt":"2026-05-16T20:43:37.703Z","changelog":"**v1.3.0 includes major changes to the CLI input/output options and deprecates several flags.** - Added support for `--format text|json|api` flag for all commands producing data (replacing `--json`). - Deprecated `--json` (output) and `--json <file>` (input); use `--format api` for output, `--file <path>` for input. - Updated documentation to reflect new output format options and migration path from deprecated flags. - No changes to core commands, but all agent workflows should update to recommended flags to avoid warnings.","fileCount":5,"zipByteSize":16162},{"version":"1.1.4","createdAt":"2026-05-16T15:46:02.555Z","changelog":"tandoor-cli v1.1.4 - Expanded options for `list` and related commands: added `--page`, `--all`, and other filters to recipes, food, and cook log list operations - Updated documentation for improved command references, including new or changed CLI flags for pagination and filtering - No code changes; documentation improvements and command information enhancements only","fileCount":5,"zipByteSize":15726},{"version":"1.1.3","createdAt":"2026-05-06T00:30:59.837Z","changelog":"tandoor-cli 1.1.3 - Version bump to 1.1.3; no user-facing changes or file modifications detected. - All usage, security, and command details remain unchanged from the previous version.","fileCount":5,"zipByteSize":15705},{"version":"1.1.2","createdAt":"2026-05-05T18:28:00.484Z","changelog":"- Version bumped from 1.1.0 to 1.1.2. - No file or functionality changes detected. - All commands, security notes, and usage remain unchanged.","fileCount":5,"zipByteSize":15704},{"version":"1.1.1","createdAt":"2026-05-05T11:58:52.533Z","changelog":"- Added cook log management support: new commands for listing, searching, adding, updating, and deleting cook log entries. - Updated documentation to reflect new cook log commands and options. - No other functional or breaking changes detected.","fileCount":5,"zipByteSize":14761},{"version":"1.0.2","createdAt":"2026-05-05T02:09:00.000Z","changelog":"- Added recommendation to pin the installed `tandoor-cli` version to match the skill version for improved stability. - Included installation instruction for specific CLI versions using `npm install -g tandoor-cli@<version>`. - No changes to commands or overall functionality; documentation improvement only.","fileCount":5,"zipByteSize":14340}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s174qsh3740skgwa1m8x5xsgpd8641p7:tandoor-cli","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s174qsh3740skgwa1m8x5xsgpd8641p7:tandoor-cli` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/dcenatiempo/tandoor-cli before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-dcenatiempo-tandoor-cli/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-dcenatiempo-tandoor-cli/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-dcenatiempo-tandoor-cli/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-dcenatiempo-tandoor-cli/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-dcenatiempo-tandoor-cli/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-dcenatiempo-tandoor-cli/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T21:51:05.608Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-dcenatiempo-tandoor-cli/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-dcenatiempo-tandoor-cli/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-dcenatiempo-tandoor-cli/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-dcenatiempo-tandoor-cli/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-10T18:06:37.122Z","emptyReason":null},"readme":"Skill: Tandoor Recipe CLI\n\nOwner: dcenatiempo\n\nSummary: Manage recipes, meal plans, and shopping lists on a Tandoor Recipe Manager instance via CLI.\n\nTags: latest:1.5.0\n\nVersion history:\n\nv1.5.0 | 2026-05-18T18:59:16.604Z | user\n\nv1.5.0\n\n- Adds `--comment TEXT` to `cooklog add` and `cooklog update` commands for entering comments on cook logs.\n- `cooklog update` now allows updating individual fields without requiring all parameters, supporting partial updates.\n- No other significant changes; compatibility and security guidelines remain unchanged.\n\nv1.4.0 | 2026-05-18T12:16:11.732Z | user\n\ntandoor-recipe-cli 1.4.0 adds supermarket/grocery ingredient category support:\n\n- New commands: `category list` and `category uncategorised` for managing grocery categories.\n- Write/modify support: Use `category set <food-id|name> --category <name|id>` and `--unset` to assign or remove categories from food items.\n- Updated documentation to include all new category-related commands and options.\n\nv1.1.5 | 2026-05-16T20:43:37.703Z | user\n\n**v1.3.0 includes major changes to the CLI input/output options and deprecates several flags.**\n\n- Added support for `--format text|json|api` flag for all commands producing data (replacing `--json`).\n- Deprecated `--json` (output) and `--json <file>` (input); use `--format api` for output, `--file <path>` for input.\n- Updated documentation to reflect new output format options and migration path from deprecated flags.\n- No changes to core commands, but all agent workflows should update to recommended flags to avoid warnings.\n\nv1.1.4 | 2026-05-16T15:46:02.555Z | user\n\ntandoor-cli v1.1.4\n\n- Expanded options for `list` and related commands: added `--page`, `--all`, and other filters to recipes, food, and cook log list operations\n- Updated documentation for improved command references, including new or changed CLI flags for pagination and filtering\n- No code changes; documentation improvements and command information enhancements only\n\nv1.1.3 | 2026-05-06T00:30:59.837Z | user\n\ntandoor-cli 1.1.3\n\n- Version bump to 1.1.3; no user-facing changes or file modifications detected.\n- All usage, security, and command details remain unchanged from the previous version.\n\nv1.1.2 | 2026-05-05T18:28:00.484Z | user\n\n- Version bumped from 1.1.0 to 1.1.2.\n- No file or functionality changes detected.\n- All commands, security notes, and usage remain unchanged.\n\nv1.1.1 | 2026-05-05T11:58:52.533Z | user\n\n- Added cook log management support: new commands for listing, searching, adding, updating, and deleting cook log entries.\n- Updated documentation to reflect new cook log commands and options.\n- No other functional or breaking changes detected.\n\nv1.0.2 | 2026-05-05T02:09:00.000Z | user\n\n- Added recommendation to pin the installed `tandoor-cli` version to match the skill version for improved stability.\n- Included installation instruction for specific CLI versions using `npm install -g tandoor-cli@<version>`.\n- No changes to commands or overall functionality; documentation improvement only.\n\nv1.0.1 | 2026-05-05T02:01:45.146Z | user\n\n- Added SECURITY.md and SECURITY_REVIEW_RESPONSE.md to document security practices and review process.\n- Expanded and clarified security, permission, and agent behavior requirements in the documentation.\n- Improved version compatibility guidance to ensure consistency between CLI and skill versions.\n- Documented the distinction between read, write, destructive, and admin operations, specifying the level of user confirmation required for each.\n- Enhanced recommendations for secure token usage and safe operation.\n\nv0.3.1 | 2026-05-05T00:06:40.589Z | user\n\n- Initial release of tandoor-recipe-cli skill (version 0.3.1).\n- Provides CLI access to Tandoor Recipe Manager for managing recipes, meal plans, shopping lists, households, users, and food ingredients.\n- Supports configuration via environment variables, config file, or .env file.\n- Includes commands for listing, searching, creating, updating, and deleting various Tandoor objects.\n- Enhanced permission guidance and sample usage provided in documentation.\n\nArchive index:\n\nArchive v1.5.0: 6 files, 17806 bytes\n\nFiles: references/SETUP.md (6080b), SECURITY_REVIEW_RESPONSE.md (9354b), SECURITY.md (9632b), skill-card.md (2425b), SKILL.md (17981b), _meta.json (130b)\n\nFile v1.5.0:SKILL.md\n\n---\nname: tandoor-recipe-cli\ndescription: Manage recipes, meal plans, and shopping lists on a Tandoor Recipe Manager instance via CLI.\nversion: 1.5.0\ncompatibility: \">=18\"\nlicense: MIT\nmetadata:\n  author: dcenatiempo\n  repository: https://github.com/dcenatiempo/tandoor-cli\n---\n\n## Tandoor CLI Skill\n\nThis skill provides AI agents with the ability to interact with a Tandoor Recipe Manager instance using the `tandoor-cli` command-line tool.\n\n### Prerequisites\n\nThe `tandoor-cli` tool must be installed and configured.\n\n**Version Compatibility:** This skill documentation corresponds to the version specified in the metadata above. Before using this skill:\n1. Verify your installed CLI version: `tandoor -V`\n2. Ensure the installed version matches the skill version to avoid unexpected behavior or missing commands\n3. If versions don't match, reinstall the CLI tool following the setup instructions in `references/SETUP.md`\n\nIf `tandoor -V` produces no valid version, see the setup instructions in `references/SETUP.md`.\n\n### Security & Permission Model\n\n**⚠️ IMPORTANT: This skill provides mutation authority over your Tandoor instance.**\n\n- **Read operations** (list, search, get, random) are safe and require no confirmation\n- **Write operations** (add, update, import) modify data but are typically reversible\n- **Destructive operations** (delete, clear, household management) require explicit user approval before execution\n- **Bulk operations** (shopping check --all, clear) affect multiple items and require confirmation\n- **Administrative operations** (household management, user assignment, invite creation) require privileged credentials and explicit approval\n\n**Token Security:**\n- Use the **least-privileged token** possible for your use case\n- Prefer read-only tokens if you only need to query recipes\n- Avoid using space-owner or admin tokens unless household management is required\n- Consider short-lived tokens (days/weeks) instead of long-lived tokens (years)\n- Store tokens securely and rotate them regularly\n- Revoke tokens immediately if compromised or no longer needed\n\n**Supply Chain:**\n- This skill uses the `tandoor-cli` npm package\n- Verify the package source before first use: https://www.npmjs.com/package/tandoor-cli\n- Review the package repository: https://github.com/dcenatiempo/tandoor-cli\n- **Recommended:** Pin to the specific version matching this skill (see version in metadata above) to avoid unexpected updates\n- Install pinned version: `npm install -g tandoor-cli@<version>` (replace `<version>` with the skill version)\n\n### Invocation\n\n```bash\ntandoor <command> [options]\n```\n\n### Output formats and deprecated flags\n\nCommands that print data accept **`--format text|json|api`** (default: `text`):\n\n| `--format` | Use for |\n|------------|---------|\n| `text` | Human-readable output (default) |\n| `json` | Slim JSON where supported (recipe add/update shape + `id` on `get`, `list`, `search`, `random`) |\n| `api` | Raw Tandoor API JSON |\n\n**Deprecated (output):** `--json` with no file path — alias for **`--format api`**; stderr warning. Do not use in new agent workflows.\n\n**Recommended (input):** `tandoor add --file recipe.json`, `tandoor update <id> --file patch.json`\n\n**Deprecated (input):** `tandoor add --json <file>`, `tandoor update <id> --json <file>` — still work with stderr warning.\n\n| Deprecated | Use instead |\n|------------|-------------|\n| `tandoor get 1 --json` | `--format api` (full) or `--format json` (slim, for edit round-trips) |\n| `tandoor list --json` | `--format api` |\n| `tandoor add --json recipe.json` | `--file recipe.json` |\n| `tandoor update 42 --json patch.json` | `--file patch.json` |\n\n### Commands\n\n#### Read Operations (Safe)\n\n**Recipes:**\n| Command | Description |\n|---|---|\n| `list [--limit N] [--page N] [--all]` | List recipes (default 20 per page, max 100) |\n| `search <query>` | Search recipes by keyword |\n| `get <id>` | Get full recipe details |\n| `random` | Get a random recipe |\n\n**Meal Plans:**\n| Command | Description |\n|---|---|\n| `mealplan list [--startdate DATE] [--enddate DATE]` | List meal plan entries (optionally filtered by date range) |\n\n**Shopping List:**\n| Command | Description |\n|---|---|\n| `shopping list` | List shopping list entries |\n\n**Food Ingredients:**\n| Command | Description |\n|---|---|\n| `food list [--limit N] [--page N] [--all] [--search TERM] [--ignored] [--onhand]` | List food ingredients |\n\n**Grocery Categories:**\n| Command | Description |\n|---|---|\n| `category list` | List all supermarket categories (sorted A-Z) |\n| `category uncategorised [--search TERM]` | List food items with no category assigned |\n\n**Cook Logs:**\n| Command | Description |\n|---|---|\n| `cooklog list [--recipe ID] [--limit N] [--page N] [--all] [--startdate YYYY-MM-DD] [--enddate YYYY-MM-DD] [--min-rating 1-5] [--max-rating 1-5]` | List cook log entries (sorted by most recent first) |\n| `cooklog ingredient <name> [--limit N] [--startdate YYYY-MM-DD] [--enddate YYYY-MM-DD] [--min-rating 1-5] [--max-rating 1-5]` | Find cook logs by ingredient name (e.g., \"when did we last have eggs?\") |\n\n**Households & Users:**\n| Command | Description |\n|---|---|\n| `household list` | List all households |\n| `household get <id>` | Get household details by ID |\n| `household users list` | List all users in the space |\n| `household users memberships` | List user-space memberships |\n| `household invite list` | List all invite links |\n\n#### Write Operations (Require Confirmation)\n\n| Command | Description | Approval Required |\n|---|---|---|\n| `add [--file file] [--interactive]` | Create a recipe (`--json <file>` deprecated) | ✓ Before execution |\n| `update <id> --file file` | Patch an existing recipe (`--json <file>` deprecated) | ✓ Before execution |\n| `import <url> [--dry-run]` | Import a recipe from a URL | ✓ Before execution |\n| `image <recipeId> <imagePath>` | Upload an image to a recipe | ✓ Before execution |\n| `mealplan add --recipe ID --date YYYY-MM-DD --meal-type N` | Add a meal plan entry | ✓ Before execution |\n| `shopping add --food NAME --amount N --unit UNIT` | Add a shopping list item | ✓ Before execution |\n| `shopping check <id>` | Mark a shopping item as checked | ✓ Before execution |\n| `food edit <id\\|name> --ignore-shopping <true\\|false>` | Edit a food's ignore_shopping flag | ✓ Before execution |\n| `food ignore <id\\|name> [--unset]` | Set or clear ignore_shopping by ID or name | ✓ Before execution |\n| `food onhand <id\\|name> [--unset]` | Set or clear the on-hand flag by ID or name | ✓ Before execution |\n| `category set <food-id\\|name> --category <name\\|id>` | Assign a grocery category to a food item | ✓ Before execution |\n| `category set <food-id\\|name> --unset` | Remove the category from a food item | ✓ Before execution |\n| `cooklog add --recipe ID --servings N [--rating 1-5] [--comment TEXT] [--date ISO8601]` | Add a cook log entry | ✓ Before execution |\n| `cooklog update <id> [--recipe ID] [--servings N] [--rating 1-5] [--comment TEXT] [--date ISO8601]` | Update a cook log entry | ✓ Before execution |\n\n#### Destructive Operations (Require Explicit Confirmation)\n\n| Command | Description | Approval Required |\n|---|---|---|\n| `delete <id> [--force]` | Delete a recipe | ✓✓ Explicit confirmation required |\n| `mealplan delete <id>` | Delete a meal plan entry | ✓✓ Explicit confirmation required |\n| `shopping clear [--force]` | Clear all checked items | ✓✓ Explicit confirmation (bulk operation) |\n| `shopping check --all` | Mark all items as checked | ✓✓ Explicit confirmation (bulk operation) |\n| `cooklog delete <id>` | Delete a cook log entry | ✓✓ Explicit confirmation required |\n\n#### Administrative Operations (Require Privileged Token + Explicit Confirmation)\n\n**Important:** Tandoor uses **households** to organize users and recipes. Users are added to households via **invite links** — you cannot create users directly via the API.\n\n> **Permission Requirements:** Household management commands require special permissions in Tandoor. Most operations need admin/staff privileges. The `household invite create` command specifically requires **space owner** authentication — even superusers or staff members will receive a 403 Permission Denied error if they're not the space owner. If you encounter permission errors, you must use the space owner's API token or contact your Tandoor administrator.\n\n| Command | Description | Approval Required |\n|---|---|---|\n| `household add <name>` | Create a new household | ✓✓ Admin token + explicit confirmation |\n| `household edit <id> --name <name>` | Rename a household | ✓✓ Admin token + explicit confirmation |\n| `household delete <id> [--force]` | Delete a household | ✓✓ Admin token + explicit confirmation |\n| `household users assign <user-space-id> <household-id>` | Assign user to household | ✓✓ Admin token + explicit confirmation |\n| `household invite create <household-id> [--email EMAIL] [--expires DATE] [--group-id ID]` | Create invite link | ✓✓ Space-owner token + explicit confirmation |\n| `household invite delete <id> [--force]` | Delete invite link | ✓✓ Admin token + explicit confirmation |\n\nRead commands accept **`--format json`** (slim, where supported) or **`--format api`** (raw). Deprecated: `--json` (same as `--format api`).\n\n### Agent Behavior Rules\n\n**Before executing any command, the agent MUST:**\n\n1. **For read operations:** Proceed without confirmation\n2. **For write operations:** Describe the action and wait for user approval\n3. **For destructive operations:** \n   - Clearly explain what will be deleted/modified\n   - Warn that the action cannot be easily reversed\n   - Wait for explicit user confirmation (e.g., \"yes, delete recipe 42\")\n4. **For bulk operations:**\n   - State how many items will be affected\n   - Wait for explicit confirmation\n5. **For administrative operations:**\n   - Verify the user has provided an admin/space-owner token\n   - Explain the scope of the change (e.g., \"this will move user X to household Y\")\n   - Wait for explicit confirmation\n\n**The agent MUST NOT:**\n- Execute delete, force, bulk, household, invite, or user-assignment commands without explicit user approval\n- Assume the user wants destructive actions even if implied by context\n- Use `--force` flags without explicit user instruction\n- Log or display the `TANDOOR_API_TOKEN` value in any output\n\n### Configuration\n\nThe CLI supports three configuration methods (in precedence order):\n\n1. **Environment variables** — `TANDOOR_URL` and `TANDOOR_API_TOKEN` in the current shell\n2. **Config file** — `~/.config/tandoor-cli/config.json` (created by `tandoor configure`)\n3. **`.env` file** — a `.env` file in the current working directory\n\nRun `tandoor configure` once to save credentials interactively.\n\n### Examples\n\n**Configure credentials:**\n```bash\ntandoor configure\n```\n\n**Read example — list recipes as JSON:**\n```bash\ntandoor list --limit 5 --format api\n```\n\n**Read example — get recipe for editing:**\n```bash\ntandoor get 42 --format json\n```\n\n**Write example — create a recipe from a JSON file:**\n```bash\n# Agent should first ask: \"I will create a new recipe from recipe.json. Proceed?\"\n# Only after user confirms:\ntandoor add --file recipe.json\n```\n\n### Recipe JSON Schema\n\nWhen creating recipes with `tandoor add --file <file>` (or deprecated `--json <file>`), the JSON file must conform to the following structure:\n\n**TypeScript Definition:**\n```typescript\ninterface RecipeCreatePayload {\n  name: string;                    // Required: Recipe name\n  description?: string;            // Optional: Recipe description\n  servings?: number;               // Optional: Number of servings\n  working_time?: number;           // Optional: Active cooking time in minutes\n  waiting_time?: number;           // Optional: Passive time (baking, marinating) in minutes\n  steps: StepCreatePayload[];      // Required: At least one step\n}\n\ninterface StepCreatePayload {\n  instruction: string;             // Required: Step instructions\n  order: number;                   // Required: Step order (1, 2, 3, ...)\n  ingredients: IngredientCreatePayload[];  // Required: Can be empty array\n}\n\ninterface IngredientCreatePayload {\n  food: { name: string };          // Required: Ingredient name\n  unit: { name: string } | null;   // Optional: Unit of measurement (null if not applicable)\n  amount: number;                  // Required: Quantity\n  note?: string;                   // Optional: Additional notes (e.g., \"finely chopped\")\n  order?: number | null;           // Optional: Order within the step\n}\n```\n\n**Example Recipe JSON:**\n```json\n{\n  \"name\": \"Scrambled Eggs\",\n  \"description\": \"Quick and easy scrambled eggs\",\n  \"servings\": 2,\n  \"working_time\": 5,\n  \"steps\": [\n    {\n      \"instruction\": \"Crack eggs into a bowl, add milk and salt. Whisk until well combined.\",\n      \"order\": 1,\n      \"ingredients\": [\n        {\n          \"food\": { \"name\": \"eggs\" },\n          \"unit\": { \"name\": \"whole\" },\n          \"amount\": 4\n        },\n        {\n          \"food\": { \"name\": \"milk\" },\n          \"unit\": { \"name\": \"tbsp\" },\n          \"amount\": 2\n        },\n        {\n          \"food\": { \"name\": \"salt\" },\n          \"unit\": null,\n          \"amount\": 1,\n          \"note\": \"to taste\"\n        }\n      ]\n    },\n    {\n      \"instruction\": \"Heat butter in a pan over medium heat. Pour in egg mixture and stir gently until cooked to desired consistency.\",\n      \"order\": 2,\n      \"ingredients\": [\n        {\n          \"food\": { \"name\": \"butter\" },\n          \"unit\": { \"name\": \"tbsp\" },\n          \"amount\": 1\n        }\n      ]\n    }\n  ]\n}\n```\n\n**Key Points for Agents:**\n- `name` and `steps` are required fields\n- Each step must have `instruction`, `order`, and `ingredients` (can be empty array)\n- Each ingredient must have `food.name` and `amount`\n- Use `null` for `unit` when no unit applies (e.g., \"to taste\", \"pinch\")\n- Common units: `g`, `kg`, `ml`, `l`, `cup`, `tbsp`, `tsp`, `whole`, `pinch`\n- Times are in minutes\n- Steps should be ordered sequentially (1, 2, 3, ...)\n\n**Destructive example — delete a recipe:**\n```bash\n# Agent should first ask: \"This will permanently delete recipe 42. This cannot be undone. Confirm deletion?\"\n# Only after explicit user confirmation:\ntandoor delete 42 --force\n```\n\n**Image example — upload an image to a recipe:**\n```bash\n# Agent should first ask: \"I will upload my-recipe-photo.jpg to recipe 42. Proceed?\"\n# Only after user confirms:\ntandoor image 42 ./my-recipe-photo.jpg\n```\n\n**Household example — create a household and generate an invite link:**\n```bash\n# Agent should first ask: \"I will create a new household named 'My Family'. This requires admin privileges. Proceed?\"\n# Only after user confirms:\ntandoor household add \"My Family\"\n\n# Agent should first ask: \"I will create an invite link for household 1. This requires space-owner token. Proceed?\"\n# Only after user confirms:\ntandoor household invite create 1 --email user@example.com --expires 2026-12-31\n```\n\n**Shopping list example — add items and check them off:**\n```bash\n# Agent should first ask: \"I will add flour (500g) to the shopping list. Proceed?\"\n# Only after user confirms:\ntandoor shopping add --food flour --amount 500 --unit g\n\n# Agent should first ask: \"This will mark ALL shopping items as checked. Confirm?\"\n# Only after explicit confirmation:\ntandoor shopping check --all\n```\n\n**Grocery category example — organise foods for a better shopping list:**\n```bash\n# Read example — see what categories exist:\ntandoor category list\n\n# Read example — find foods with no category yet:\ntandoor category uncategorised\ntandoor category uncategorised --search pasta\n\n# Agent should first ask: \"I will assign 'milk' to the Dairy category. Proceed?\"\n# Only after user confirms:\ntandoor category set milk --category Dairy\ntandoor category set \"olive oil\" --category Oils\ntandoor category set 42 --category \"Canned Goods\"   # by food ID\n\n# Agent should first ask: \"I will remove the category from 'milk'. Proceed?\"\n# Only after user confirms:\ntandoor category set milk --unset\n```\n\n**Cook log example — track when you cook a recipe:**\n```bash\n# Agent should first ask: \"I will add a cook log entry for recipe 42 (4 servings, rating 5). Proceed?\"\n# Only after user confirms:\ntandoor cooklog add --recipe 42 --servings 4 --rating 5\ntandoor cooklog add --recipe 42 --servings 4 --rating 5 --comment \"Kids loved it\"\n\n# Read example — list cook logs for a specific recipe:\ntandoor cooklog list --recipe 42 --format api\n\n# Read example — find when you last had eggs:\ntandoor cooklog ingredient eggs\n\n# Read example — count how many times you had chicken last month:\ntandoor cooklog ingredient chicken --startdate 2026-04-01 --enddate 2026-04-30\n\n# Read example — find highly-rated egg recipes (4-5 stars):\ntandoor cooklog ingredient eggs --min-rating 4\n\n# Read example — find poorly-rated recipes from last month (1-2 stars):\ntandoor cooklog list --startdate 2026-04-01 --enddate 2026-04-30 --max-rating 2\n\n# Agent should first ask: \"I will update cook log 2 with a new comment. Proceed?\"\n# Only after user confirms:\ntandoor cooklog update 2 --comment \"Next time add more garlic\"\n\n# Agent should first ask: \"This will delete cook log entry 2. Confirm?\"\n# Only after explicit confirmation:\ntandoor cooklog delete 2\n```\n\n### Installation & Setup\n\n**Before first use:**\n1. Verify the npm package: https://www.npmjs.com/package/tandoor-cli\n2. Review the source code: https://github.com/dcenatiempo/tandoor-cli\n3. **Recommended:** Install the pinned version matching this skill: `npm install -g tandoor-cli@<version>` (see version in metadata above)\n4. Generate a token with minimal required permissions (see SECURITY.md)\n5. Consider using a test Tandoor instance first\n\n### Reference\n\n- See `references/SETUP.md` for detailed setup documentation including authentication configuration\n- See `SECURITY.md` for comprehensive security guidelines and token management best practices\n\nFile v1.5.0:_meta.json\n\n{\n  \"ownerId\": \"kn7d75mc2rzjgptnfjg8382my9864gnx\",\n  \"slug\": \"tandoor-cli\",\n  \"version\": \"1.5.0\",\n  \"publishedAt\": 1779130756604\n}\n\nFile v1.5.0:references/SETUP.md\n\n# tandoor-cli Setup Guide\n\nA command-line interface for [Tandoor Recipe Manager](https://tandoor.dev).\n\n---\n\n## Prerequisites\n\n- Node.js 18+\n- npm 8+\n- A running Tandoor instance (local or remote)\n\n---\n\n## Installation\n\n### Option 1: Install globally via npm\n\n```bash\nnpm install -g tandoor-cli\n```\n\nAfter the global install, the `tandoor` command becomes available system-wide.\n\n### Option 2: Run without installing\n\n```bash\nnpx tandoor-cli <command>\n```\n\nNo global install is required. `npx` downloads and runs the CLI on demand.\n\n**Note:** The rest of this documentation assumes a global install.\n\n---\n\n## Configuration\n\n`TANDOOR_URL` and at least one authentication method are required.\n\nThe CLI supports three configuration sources, applied in this order (highest priority first):\n\n1. Environment variables\n2. Persistent config file\n3. `.env` file\n\n### Option 1: Environment variables\n\n```bash\nexport TANDOOR_URL=http://localhost:8080\nexport TANDOOR_API_TOKEN=your_token_here\n```\n\nEnvironment variables take precedence over stored config and `.env` settings.\n\n### Option 2: `tandoor configure`\n\nRun the interactive setup command to save credentials to `~/.config/tandoor-cli/config.json`:\n\n```bash\n# without install\nnpx tandoor-cli configure\n\n# with global install\ntandoor configure\n```\n\nYou will be prompted for:\n- `TANDOOR_URL`\n- `TANDOOR_API_TOKEN`\n\nThe file is written with restricted permissions (0600) to protect your credentials.\n\n### Option 3: `.env` file\n\nCreate a `.env` file in your working directory:\n\n```dotenv\nTANDOOR_URL=http://localhost:8080\nTANDOOR_API_TOKEN=your_token_here\nTANDOOR_USERNAME=\nTANDOOR_PASSWORD=\n```\n\nThe CLI loads `.env` automatically when present.\n\n---\n\n## Authentication\n\n### API token (preferred)\n\nUse an OAuth2 access token with Bearer authentication. \n\n**Important:** The regular DRF token shown in Tandoor's Settings → API does **not** work for this CLI. You need an OAuth2 access token.\n\n**⚠️ Security Note:** Use the shortest token lifetime appropriate for your use case. For AI agent use, consider tokens that expire in days or weeks, not years.\n\n#### Generating an OAuth2 token\n\nIf you're running Tandoor in Docker, you can generate an OAuth2 token using the Django shell. Choose the appropriate example based on your needs:\n\n##### Read-Only Token (Safest)\n\nFor querying recipes only:\n\n```bash\ndocker exec <your-container-name> /opt/recipes/venv/bin/python /opt/recipes/manage.py shell -c \"\nfrom oauth2_provider.models import Application, AccessToken\nfrom django.contrib.auth.models import User\nfrom django.utils import timezone\nfrom datetime import timedelta\nimport secrets\n\nuser = User.objects.get(username='YOUR_USERNAME')\n\napp, _ = Application.objects.get_or_create(\n    name='tandoor-cli',\n    defaults=dict(\n        user=user,\n        client_type=Application.CLIENT_CONFIDENTIAL,\n        authorization_grant_type=Application.GRANT_PASSWORD,\n    )\n)\n\ntoken = AccessToken.objects.create(\n    user=user,\n    application=app,\n    token=secrets.token_hex(20),\n    expires=timezone.now() + timedelta(days=7),  # 7 days\n    scope='read',  # Read-only\n)\nprint('ACCESS TOKEN:', token.token)\n\"\n```\n\n##### Read-Write Token (Standard)\n\nFor recipe management (add, edit, delete recipes):\n\n```bash\ndocker exec <your-container-name> /opt/recipes/venv/bin/python /opt/recipes/manage.py shell -c \"\nfrom oauth2_provider.models import Application, AccessToken\nfrom django.contrib.auth.models import User\nfrom django.utils import timezone\nfrom datetime import timedelta\nimport secrets\n\nuser = User.objects.get(username='YOUR_USERNAME')\n\napp, _ = Application.objects.get_or_create(\n    name='tandoor-cli',\n    defaults=dict(\n        user=user,\n        client_type=Application.CLIENT_CONFIDENTIAL,\n        authorization_grant_type=Application.GRANT_PASSWORD,\n    )\n)\n\ntoken = AccessToken.objects.create(\n    user=user,\n    application=app,\n    token=secrets.token_hex(20),\n    expires=timezone.now() + timedelta(days=30),  # 30 days\n    scope='read write',\n)\nprint('ACCESS TOKEN:', token.token)\n\"\n```\n\nReplace `<your-container-name>` with the name of your running Tandoor Docker container and `YOUR_USERNAME` with your Tandoor username. Copy the printed token into `TANDOOR_API_TOKEN`.\n\n**Token Lifetime Recommendations:**\n- **AI agents / automation:** 7-30 days\n- **Personal CLI use:** 30-90 days\n- **Testing / development:** 1-7 days\n- **Administrative tasks:** 1 day (revoke after use)\n\n**Token Security Best Practices:**\n- Store tokens securely (environment variables, secret managers)\n- Never commit tokens to version control\n- Revoke tokens immediately if compromised\n- Rotate tokens regularly\n- Use read-only tokens when possible\n- See `SECURITY.md` for comprehensive security guidance\n\n### Username/password fallback\n\nIf `TANDOOR_API_TOKEN` is missing, the CLI falls back to HTTP Basic Authentication using `TANDOOR_USERNAME` and `TANDOOR_PASSWORD`.\n\n**Note:** This method is less secure and not recommended for production use.\n\n---\n\n## Verification\n\nTest your configuration:\n\n```bash\n# Check version\ntandoor --version\n\n# List recipes (requires valid credentials)\ntandoor list --limit 5\n```\n\nIf you see recipes listed, your configuration is working correctly!\n\n---\n\n## Troubleshooting\n\n### \"TANDOOR_URL is not set\"\n\nRun `tandoor configure` or set the `TANDOOR_URL` environment variable.\n\n### \"Authentication failed\" or 401 errors\n\n- Verify your `TANDOOR_API_TOKEN` is a valid OAuth2 token (not a DRF token)\n- Check that your token hasn't expired\n- Ensure your Tandoor instance is accessible at the configured URL\n\n### \"Permission denied\" or 403 errors\n\nSome commands (especially household management) require admin or space owner privileges. Check your user permissions in Tandoor.\n\n### Command not found\n\nIf `tandoor` command is not found after global install:\n- Verify npm's global bin directory is in your PATH\n- Try `npx tandoor-cli` instead\n- Reinstall: `npm install -g tandoor-cli`\n\n---\n\n## Next Steps\n\nFor command usage examples and full documentation, see the main [README](https://github.com/dcenatiempo/tandoor-cli#readme).\n\nFile v1.5.0:SECURITY_REVIEW_RESPONSE.md\n\n# Response to OlawHub Security Review\n\nThis document summarizes the changes made to address security concerns raised in the OlawHub skill review.\n\n## Review Date\nMay 4, 2026\n\n## Summary of Changes\n\nAll security concerns have been addressed through documentation updates, explicit approval gates, and security best practices guidance.\n\n---\n\n## 1. Tool Misuse and Exploitation (HIGH SEVERITY)\n\n### Original Concern\n> The skill exposes destructive, bulk, and account-administration operations to the agent, but the instructions do not add explicit approval gates or limits for these high-impact actions.\n\n### Resolution\n\n**Files Modified:**\n- `SKILL.md`\n- `references/SETUP.md`\n\n**Changes Made:**\n\n1. **Command Classification System**\n   - All commands now categorized by risk level:\n     - Read operations (safe, no approval)\n     - Write operations (require user confirmation)\n     - Destructive operations (require explicit confirmation)\n     - Administrative operations (require privileged token + explicit confirmation)\n\n2. **Explicit Approval Gates**\n   - Added \"Approval Required\" column to command tables\n   - Documented specific confirmation messages for each destructive operation\n   - Examples:\n     - `delete <id>`: \"This will permanently delete recipe X. Cannot be undone. Confirm?\"\n     - `shopping check --all`: \"This will mark ALL shopping items as checked. Confirm?\"\n     - `household users assign`: \"This will move user X to household Y. Confirm?\"\n\n3. **Agent Behavior Rules Section**\n   - Clear instructions on when to proceed vs. when to ask\n   - Explicit prohibition on using `--force` without user instruction\n   - Requirement to explain impact before destructive operations\n\n4. **Security Warning Banner**\n   - Added prominent warning at top of SKILL.md\n   - States: \"This skill provides mutation authority over your Tandoor instance\"\n   - Directs users to only install if they want agent mutation authority\n\n**User Impact:** Agents can no longer execute destructive operations without explicit user approval. Users maintain full control over high-impact actions.\n\n---\n\n## 2. Agentic Supply Chain Vulnerabilities (LOW SEVERITY)\n\n### Original Concern\n> The skill relies on an external npm package that is not included in the reviewed artifact set; npx may download and run package code on demand.\n\n### Resolution\n\n**Files Modified:**\n- `SKILL.md`\n- `SECURITY.md`\n\n**Changes Made:**\n\n1. **Version Awareness**\n   - Documentation acknowledges the npm package dependency\n   - Recommends version pinning for production use\n\n2. **Verification Links**\n   - Added direct links to npm package: https://www.npmjs.com/package/tandoor-cli\n   - Added direct link to source repository: https://github.com/dcenatiempo/tandoor-cli\n   - Included in \"Before first use\" checklist\n\n3. **Pre-Installation Checklist**\n   - Verify the npm package\n   - Review the source code\n   - Consider using a test instance first\n\n4. **Supply Chain Security Section**\n   - Added to SKILL.md under \"Security & Permission Model\"\n   - Recommends reviewing package before use with privileged credentials\n   - Suggests monitoring npm security advisories\n\n**User Impact:** Users can verify the package source and pin to known-good versions before granting access to their Tandoor instance.\n\n---\n\n## 3. Identity and Privilege Abuse - Space Owner Token (HIGH SEVERITY)\n\n### Original Concern\n> The skill directs use of a highly privileged Tandoor identity for household invite management, which is broader than ordinary recipe and shopping-list management.\n\n### Resolution\n\n**Files Modified:**\n- `SKILL.md`\n- `SECURITY.md`\n- `references/SETUP.md`\n\n**Changes Made:**\n\n1. **Least Privilege Principle**\n   - Added \"Token Security\" section emphasizing least-privileged tokens\n   - Guidance on token scoping:\n     - Read-only tokens for queries\n     - Standard user tokens for recipe management\n     - Admin tokens only for household management\n     - Space-owner tokens only for invite creation\n\n2. **Command-Level Permission Documentation**\n   - Each administrative command now states required permission level\n   - Example: \"household invite create\" explicitly states \"Space-owner token + explicit confirmation\"\n\n3. **Permission Error Guidance**\n   - Users directed to contact administrators if lacking permissions\n   - Clear explanation that 403 errors indicate insufficient privileges\n\n4. **Token Scoping Examples**\n   - SECURITY.md provides three token configuration examples:\n     - Read-only (safest)\n     - Recipe management (standard)\n     - Administrative tasks (restricted)\n\n**User Impact:** Users can create appropriately scoped tokens for their use case, avoiding over-privileged access.\n\n---\n\n## 4. Identity and Privilege Abuse - Long-Lived Tokens (MEDIUM SEVERITY)\n\n### Original Concern\n> The setup guide demonstrates creating a long-lived read/write OAuth2 access token, which would let the CLI perform both read and mutation operations for up to a year if not revoked.\n\n### Resolution\n\n**Files Modified:**\n- `references/SETUP.md`\n- `SECURITY.md`\n\n**Changes Made:**\n\n1. **Token Lifetime Recommendations**\n   - Changed default example from 365 days (1 year) to 7-30 days\n   - Added \"Token Lifetime Recommendations\" section:\n     - AI agents / automation: 7-30 days\n     - Personal CLI use: 30-90 days\n     - Testing / development: 1-7 days\n     - Administrative tasks: 1 day (revoke after use)\n\n2. **Multiple Token Examples**\n   - SETUP.md now provides separate examples for:\n     - Read-only token (7 days, `scope='read'`)\n     - Read-write token (30 days, `scope='read write'`)\n   - Users choose appropriate example for their use case\n\n3. **Token Security Best Practices**\n   - Store tokens securely (environment variables, secret managers)\n   - Never commit tokens to version control\n   - Revoke tokens immediately if compromised\n   - Rotate tokens regularly\n   - Use read-only tokens when possible\n\n4. **Token Management Commands**\n   - SECURITY.md includes commands to:\n     - List active tokens\n     - Revoke unused tokens\n     - Audit token usage\n\n**User Impact:** Users create shorter-lived tokens appropriate for their use case, reducing exposure window if tokens are compromised.\n\n---\n\n## New Documentation\n\n### SECURITY.md (New File)\n\nComprehensive security documentation covering:\n\n1. **Overview of Security Model**\n2. **Detailed Mitigation for Each Concern**\n3. **Recommended Token Configurations**\n   - Read-only, standard, and administrative examples\n4. **Token Storage Best Practices**\n   - Secure vs. insecure methods\n5. **Monitoring and Auditing**\n   - Commands to list and revoke tokens\n   - Incident response procedures\n6. **Agent-Specific Security**\n   - Guidance for AI agent users\n   - Agent behavior validation tests\n7. **Compliance and Governance**\n   - Organizational policies\n   - Personal use guidelines\n8. **Reporting Security Issues**\n\n---\n\n## Testing Recommendations\n\nTo verify the security improvements:\n\n### 1. Test Agent Approval Gates\n\n```bash\n# Should prompt for confirmation, not execute immediately:\n\"Delete recipe 42\"\n\"Clear all shopping items\"\n\"Create a new household\"\n\n# Should proceed without confirmation:\n\"List all recipes\"\n\"Search for pasta recipes\"\n```\n\n### 2. Test Token Scoping\n\n```bash\n# Create a read-only token and verify write operations fail:\nexport TANDOOR_API_TOKEN=<read-only-token>\ntandoor list  # Should work\ntandoor add --json recipe.json  # Should fail with 403\n```\n\n### 3. Test Version Awareness\n\n```bash\n# Verify the CLI version:\ntandoor --version\n```\n\n---\n\n## Compliance Summary\n\n| Concern | Severity | Status | Mitigation |\n|---------|----------|--------|------------|\n| Tool Misuse and Exploitation | HIGH | ✅ Resolved | Explicit approval gates, command classification, agent behavior rules |\n| Agentic Supply Chain | LOW | ✅ Resolved | Verification links, pre-installation checklist, version awareness |\n| Space Owner Token Privilege | HIGH | ✅ Resolved | Least privilege guidance, token scoping examples, permission documentation |\n| Long-Lived Tokens | MEDIUM | ✅ Resolved | Shorter default lifetimes, token rotation guidance, security best practices |\n\n---\n\n## Recommendations for Users\n\n### Before Installation\n\n1. ✅ Read `SECURITY.md` to understand the security model\n2. ✅ Verify the npm package at https://www.npmjs.com/package/tandoor-cli\n3. ✅ Review the source code at https://github.com/dcenatiempo/tandoor-cli\n4. ✅ Decide what level of access you want to grant the agent\n\n### During Setup\n\n1. ✅ Create a token with the minimum required permissions\n2. ✅ Use short token lifetimes (7-30 days for agents)\n3. ✅ Store tokens securely (environment variables, secret managers)\n4. ✅ Test with a non-production Tandoor instance first\n\n### After Installation\n\n1. ✅ Monitor agent behavior for unexpected commands\n2. ✅ Verify agents request approval for destructive operations\n3. ✅ Rotate tokens regularly\n4. ✅ Revoke tokens immediately if compromised\n\n---\n\n## Contact\n\nFor questions about these security improvements:\n- Open an issue in the repository\n- Tag issues with `[SECURITY]` for priority handling\n\nFor security vulnerabilities:\n- Report privately via GitHub Security Advisories\n- Do not disclose publicly until patched\n\n---\n\n## Version History\n\n- **v0.4.0** (May 2026): Security improvements addressing OlawHub review\n- **v0.3.0** (Earlier): Initial skill release\n\nFile v1.5.0:SECURITY.md\n\n# Security Guidelines for Tandoor CLI Skill\n\nThis document addresses security concerns and best practices for using the tandoor-cli skill with AI agents.\n\n## Overview\n\nThe tandoor-cli skill provides programmatic access to your Tandoor Recipe Manager instance. Like any tool with write access to your data, it requires careful configuration and usage to maintain security.\n\n## Addressed Security Concerns\n\n### 1. Tool Misuse and Exploitation (HIGH SEVERITY)\n\n**Concern:** The skill exposes destructive, bulk, and account-administration operations without explicit approval gates.\n\n**Mitigation:**\n- **Command Classification:** All commands are now classified by risk level (read, write, destructive, administrative)\n- **Approval Gates:** The SKILL.md explicitly requires user confirmation before:\n  - Any write operation (add, update, import)\n  - Any destructive operation (delete, clear, bulk operations)\n  - Any administrative operation (household management, user assignment)\n- **Agent Behavior Rules:** Clear instructions prevent agents from executing high-risk commands without explicit user approval\n- **No Automatic --force:** Agents are forbidden from using `--force` flags without explicit user instruction\n\n**User Action Required:**\n- Review the command classification table in SKILL.md\n- Only install this skill if you want the agent to have mutation authority\n- Monitor agent behavior and revoke access if misuse is detected\n\n### 2. Agentic Supply Chain Vulnerabilities (LOW SEVERITY)\n\n**Concern:** The skill relies on an external npm package that could be compromised.\n\n**Mitigation:**\n- **Version Pinning:** The skill explicitly uses `npx tandoor-cli@0.3.1` to pin to a known version\n- **Verification Links:** SKILL.md provides direct links to:\n  - npm package: https://www.npmjs.com/package/tandoor-cli\n  - Source repository: https://github.com/dcenatiempo/tandoor-cli\n- **Pre-Installation Checklist:** Users are instructed to verify the package before first use\n- **No Auto-Updates:** Using `@version` syntax prevents automatic updates to potentially compromised versions\n\n**User Action Required:**\n- Verify the npm package and repository before first installation\n- Review the package source code if using privileged credentials\n- Monitor npm security advisories for the tandoor-cli package\n- Update to newer versions only after reviewing changelogs\n\n### 3. Identity and Privilege Abuse - Space Owner Token (HIGH SEVERITY)\n\n**Concern:** The skill directs use of a highly privileged space-owner token for household invite management.\n\n**Mitigation:**\n- **Least Privilege Principle:** SKILL.md now emphasizes using the least-privileged token possible\n- **Token Scoping Guidance:**\n  - Read-only tokens for query operations\n  - Standard user tokens for recipe management\n  - Admin tokens only when household management is required\n  - Space-owner tokens only for invite link creation\n- **Explicit Warnings:** Administrative commands clearly state they require privileged tokens\n- **Permission Errors:** Users are directed to contact administrators if they lack necessary permissions\n\n**User Action Required:**\n- Create separate tokens for different use cases\n- Use read-only tokens when possible\n- Avoid providing space-owner tokens unless invite management is truly needed\n- Revoke privileged tokens immediately after administrative tasks\n\n### 4. Identity and Privilege Abuse - Long-Lived Tokens (MEDIUM SEVERITY)\n\n**Concern:** The setup guide demonstrates creating long-lived (10-year) read/write OAuth2 tokens.\n\n**Mitigation:**\n- **Token Lifetime Guidance:** SKILL.md now recommends short-lived tokens (days/weeks) instead of long-lived tokens (years)\n- **Security Best Practices Section:** Added explicit guidance on:\n  - Token rotation schedules\n  - Secure token storage\n  - Immediate revocation if compromised\n  - Regular token audits\n- **Alternative Approaches:** Users are encouraged to:\n  - Generate tokens on-demand for specific tasks\n  - Revoke tokens after use\n  - Use environment-specific tokens (dev vs. production)\n\n**User Action Required:**\n- Modify the token generation command to use shorter expiry periods:\n  ```python\n  expires=timezone.now() + timedelta(days=7)  # 7 days instead of 3650\n  ```\n- Implement a token rotation schedule\n- Store tokens securely (environment variables, secret managers, not in code)\n- Revoke unused tokens regularly\n\n## Recommended Token Configuration\n\n### For Read-Only Use (Safest)\n\nIf you only need to query recipes, create a read-only token:\n\n```python\ntoken = AccessToken.objects.create(\n    user=user,\n    application=app,\n    token=secrets.token_hex(20),\n    expires=timezone.now() + timedelta(days=7),  # 7 days\n    scope='read',  # Read-only\n)\n```\n\n### For Recipe Management (Standard)\n\nFor adding/editing recipes but not administrative tasks:\n\n```python\ntoken = AccessToken.objects.create(\n    user=user,\n    application=app,\n    token=secrets.token_hex(20),\n    expires=timezone.now() + timedelta(days=30),  # 30 days\n    scope='read write',\n)\n```\n\nUse a standard user account (not admin/staff).\n\n### For Administrative Tasks (Restricted)\n\nOnly when household management is required:\n\n```python\ntoken = AccessToken.objects.create(\n    user=admin_user,  # Must be admin/staff\n    application=app,\n    token=secrets.token_hex(20),\n    expires=timezone.now() + timedelta(days=1),  # 1 day\n    scope='read write',\n)\n```\n\nRevoke immediately after completing administrative tasks.\n\n## Token Storage Best Practices\n\n### ✅ Secure Methods\n\n- **Environment variables:** `export TANDOOR_API_TOKEN=...` (session-only)\n- **Secret managers:** AWS Secrets Manager, HashiCorp Vault, 1Password CLI\n- **Encrypted config files:** `~/.config/tandoor-cli/config.json` with `0600` permissions\n- **CI/CD secrets:** GitHub Secrets, GitLab CI/CD variables\n\n### ❌ Insecure Methods\n\n- **Plain text in code:** Never commit tokens to version control\n- **Shared config files:** Avoid world-readable files\n- **Chat logs:** Don't paste tokens in Slack, Discord, etc.\n- **Browser history:** Be careful with tokens in URLs\n\n## Monitoring and Auditing\n\n### Regular Security Checks\n\n1. **List active tokens:**\n   ```python\n   docker exec <container> /opt/recipes/venv/bin/python /opt/recipes/manage.py shell -c \"\n   from oauth2_provider.models import AccessToken\n   from django.utils import timezone\n   \n   active = AccessToken.objects.filter(expires__gt=timezone.now())\n   for token in active:\n       print(f'{token.user.username}: {token.scope} (expires {token.expires})')\n   \"\n   ```\n\n2. **Revoke unused tokens:**\n   ```python\n   docker exec <container> /opt/recipes/venv/bin/python /opt/recipes/manage.py shell -c \"\n   from oauth2_provider.models import AccessToken\n   \n   # Revoke all tokens for tandoor-cli app\n   AccessToken.objects.filter(application__name='tandoor-cli').delete()\n   \"\n   ```\n\n3. **Review Tandoor audit logs:** Check for unexpected API activity\n\n### Incident Response\n\nIf a token is compromised:\n\n1. **Immediately revoke the token** using the command above\n2. **Review recent API activity** in Tandoor logs\n3. **Generate a new token** with a different value\n4. **Update all systems** using the old token\n5. **Investigate** how the token was exposed\n\n## Agent-Specific Security\n\n### For AI Agent Users\n\nWhen using this skill with AI agents (Kiro, Claude, etc.):\n\n1. **Start with read-only tokens** to test agent behavior\n2. **Monitor agent commands** before granting write access\n3. **Use approval hooks** to review destructive operations\n4. **Limit token scope** to the minimum required for the task\n5. **Revoke tokens** when the agent task is complete\n\n### Agent Behavior Validation\n\nTest that your agent follows the security rules:\n\n```bash\n# This should prompt for confirmation, not execute immediately\n\"Delete recipe 42\"\n\n# This should refuse without explicit user approval\n\"Clear all shopping items\"\n\n# This should warn about privilege requirements\n\"Create a new household\"\n```\n\nIf your agent executes these without confirmation, the skill is not being used correctly.\n\n## Compliance and Governance\n\n### For Organizations\n\nIf deploying this skill in a team or organization:\n\n- **Access Control:** Limit who can generate API tokens\n- **Token Policies:** Enforce maximum token lifetimes\n- **Audit Logging:** Enable and monitor Tandoor API logs\n- **Incident Response:** Have a plan for token compromise\n- **Training:** Ensure users understand the security model\n\n### For Personal Use\n\nEven for personal Tandoor instances:\n\n- **Principle of Least Privilege:** Use the minimum permissions needed\n- **Defense in Depth:** Don't rely solely on token security\n- **Regular Reviews:** Audit tokens and agent behavior periodically\n- **Backup Strategy:** Maintain backups in case of accidental deletion\n\n## Reporting Security Issues\n\nIf you discover a security vulnerability in:\n\n- **tandoor-cli package:** Report to https://github.com/dcenatiempo/tandoor-cli/security\n- **Tandoor Recipe Manager:** Report to https://github.com/TandoorRecipes/recipes/security\n- **This skill:** Open an issue at your repository with `[SECURITY]` prefix\n\nDo not disclose security vulnerabilities publicly until they are patched.\n\n## Version History\n\n- **v0.4.0** (May 2026): Added comprehensive security documentation and approval gates\n- **v0.3.0** (Earlier): Initial skill release\n\n## Additional Resources\n\n- [Tandoor Security Documentation](https://docs.tandoor.dev/security/)\n- [OAuth2 Best Practices](https://oauth.net/2/oauth-best-practice/)\n- [OWASP API Security Top 10](https://owasp.org/www-project-api-security/)\n- [Agent Skills Security Guidelines](https://agentskills.io/security)\n\nFile v1.5.0:skill-card.md\n\n## Description:\n\nManage recipes, meal plans, and shopping lists on a Tandoor Recipe Manager instance via CLI.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[dcenatiempo](https://clawhub.ai/user/dcenatiempo)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nExternal users and developers use this skill to let an agent operate tandoor-cli against a configured Tandoor Recipe Manager instance for recipe lookup, meal planning, shopping list management, cook logs, and approved write operations.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The CLI can modify or delete Tandoor data when granted write-capable credentials.\n\nMitigation: Use read-only tokens for lookup workflows and require explicit user approval before write, destructive, bulk, household, or invite commands.\n\nRisk: An unpinned npm installation path could run a different tandoor-cli version than the reviewed skill release.\n\nMitigation: Pin the CLI to version 1.5.0 before installing or running it, and review the package and repository before granting credentials.\n\nRisk: Admin or space-owner tokens can grant broader access than normal recipe and shopping-list tasks require.\n\nMitigation: Use short-lived, least-privileged tokens and avoid admin or space-owner credentials unless the specific task requires them.\n\n## Reference(s):\n\n- [Tandoor Recipe CLI on ClawHub](https://clawhub.ai/dcenatiempo/skills/tandoor-cli)\n- [tandoor-cli repository](https://github.com/dcenatiempo/tandoor-cli)\n- [tandoor-cli npm package](https://www.npmjs.com/package/tandoor-cli)\n- [Tandoor Recipe Manager](https://tandoor.dev)\n- [Setup Guide](references/SETUP.md)\n- [Security Guidelines](SECURITY.md)\n\n## Skill Output:\n\n**Output Type(s):** [Text, Markdown, Code, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown guidance with inline shell commands and JSON examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [CLI output may be text, slim JSON, or raw Tandoor API JSON depending on the selected format flag.]\n\n## Skill Version(s):\n\n1.5.0 (source: server release metadata and SKILL.md frontmatter)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v1.4.0: 5 files, 16446 bytes\n\nFiles: references/SETUP.md (6080b), SECURITY_REVIEW_RESPONSE.md (9354b), SECURITY.md (9632b), SKILL.md (17687b), _meta.json (130b)\n\nFile v1.4.0:SKILL.md\n\n---\nname: tandoor-recipe-cli\ndescription: Manage recipes, meal plans, and shopping lists on a Tandoor Recipe Manager instance via CLI.\nversion: 1.4.0\ncompatibility: \">=18\"\nlicense: MIT\nmetadata:\n  author: dcenatiempo\n  repository: https://github.com/dcenatiempo/tandoor-cli\n---\n\n## Tandoor CLI Skill\n\nThis skill provides AI agents with the ability to interact with a Tandoor Recipe Manager instance using the `tandoor-cli` command-line tool.\n\n### Prerequisites\n\nThe `tandoor-cli` tool must be installed and configured.\n\n**Version Compatibility:** This skill documentation corresponds to the version specified in the metadata above. Before using this skill:\n1. Verify your installed CLI version: `tandoor -V`\n2. Ensure the installed version matches the skill version to avoid unexpected behavior or missing commands\n3. If versions don't match, reinstall the CLI tool following the setup instructions in `references/SETUP.md`\n\nIf `tandoor -V` produces no valid version, see the setup instructions in `references/SETUP.md`.\n\n### Security & Permission Model\n\n**⚠️ IMPORTANT: This skill provides mutation authority over your Tandoor instance.**\n\n- **Read operations** (list, search, get, random) are safe and require no confirmation\n- **Write operations** (add, update, import) modify data but are typically reversible\n- **Destructive operations** (delete, clear, household management) require explicit user approval before execution\n- **Bulk operations** (shopping check --all, clear) affect multiple items and require confirmation\n- **Administrative operations** (household management, user assignment, invite creation) require privileged credentials and explicit approval\n\n**Token Security:**\n- Use the **least-privileged token** possible for your use case\n- Prefer read-only tokens if you only need to query recipes\n- Avoid using space-owner or admin tokens unless household management is required\n- Consider short-lived tokens (days/weeks) instead of long-lived tokens (years)\n- Store tokens securely and rotate them regularly\n- Revoke tokens immediately if compromised or no longer needed\n\n**Supply Chain:**\n- This skill uses the `tandoor-cli` npm package\n- Verify the package source before first use: https://www.npmjs.com/package/tandoor-cli\n- Review the package repository: https://github.com/dcenatiempo/tandoor-cli\n- **Recommended:** Pin to the specific version matching this skill (see version in metadata above) to avoid unexpected updates\n- Install pinned version: `npm install -g tandoor-cli@<version>` (replace `<version>` with the skill version)\n\n### Invocation\n\n```bash\ntandoor <command> [options]\n```\n\n### Output formats and deprecated flags\n\nCommands that print data accept **`--format text|json|api`** (default: `text`):\n\n| `--format` | Use for |\n|------------|---------|\n| `text` | Human-readable output (default) |\n| `json` | Slim JSON where supported (recipe add/update shape + `id` on `get`, `list`, `search`, `random`) |\n| `api` | Raw Tandoor API JSON |\n\n**Deprecated (output):** `--json` with no file path — alias for **`--format api`**; stderr warning. Do not use in new agent workflows.\n\n**Recommended (input):** `tandoor add --file recipe.json`, `tandoor update <id> --file patch.json`\n\n**Deprecated (input):** `tandoor add --json <file>`, `tandoor update <id> --json <file>` — still work with stderr warning.\n\n| Deprecated | Use instead |\n|------------|-------------|\n| `tandoor get 1 --json` | `--format api` (full) or `--format json` (slim, for edit round-trips) |\n| `tandoor list --json` | `--format api` |\n| `tandoor add --json recipe.json` | `--file recipe.json` |\n| `tandoor update 42 --json patch.json` | `--file patch.json` |\n\n### Commands\n\n#### Read Operations (Safe)\n\n**Recipes:**\n| Command | Description |\n|---|---|\n| `list [--limit N] [--page N] [--all]` | List recipes (default 20 per page, max 100) |\n| `search <query>` | Search recipes by keyword |\n| `get <id>` | Get full recipe details |\n| `random` | Get a random recipe |\n\n**Meal Plans:**\n| Command | Description |\n|---|---|\n| `mealplan list [--startdate DATE] [--enddate DATE]` | List meal plan entries (optionally filtered by date range) |\n\n**Shopping List:**\n| Command | Description |\n|---|---|\n| `shopping list` | List shopping list entries |\n\n**Food Ingredients:**\n| Command | Description |\n|---|---|\n| `food list [--limit N] [--page N] [--all] [--search TERM] [--ignored] [--onhand]` | List food ingredients |\n\n**Grocery Categories:**\n| Command | Description |\n|---|---|\n| `category list` | List all supermarket categories (sorted A-Z) |\n| `category uncategorised [--search TERM]` | List food items with no category assigned |\n\n**Cook Logs:**\n| Command | Description |\n|---|---|\n| `cooklog list [--recipe ID] [--limit N] [--page N] [--all] [--startdate YYYY-MM-DD] [--enddate YYYY-MM-DD] [--min-rating 1-5] [--max-rating 1-5]` | List cook log entries (sorted by most recent first) |\n| `cooklog ingredient <name> [--limit N] [--startdate YYYY-MM-DD] [--enddate YYYY-MM-DD] [--min-rating 1-5] [--max-rating 1-5]` | Find cook logs by ingredient name (e.g., \"when did we last have eggs?\") |\n\n**Households & Users:**\n| Command | Description |\n|---|---|\n| `household list` | List all households |\n| `household get <id>` | Get household details by ID |\n| `household users list` | List all users in the space |\n| `household users memberships` | List user-space memberships |\n| `household invite list` | List all invite links |\n\n#### Write Operations (Require Confirmation)\n\n| Command | Description | Approval Required |\n|---|---|---|\n| `add [--file file] [--interactive]` | Create a recipe (`--json <file>` deprecated) | ✓ Before execution |\n| `update <id> --file file` | Patch an existing recipe (`--json <file>` deprecated) | ✓ Before execution |\n| `import <url> [--dry-run]` | Import a recipe from a URL | ✓ Before execution |\n| `image <recipeId> <imagePath>` | Upload an image to a recipe | ✓ Before execution |\n| `mealplan add --recipe ID --date YYYY-MM-DD --meal-type N` | Add a meal plan entry | ✓ Before execution |\n| `shopping add --food NAME --amount N --unit UNIT` | Add a shopping list item | ✓ Before execution |\n| `shopping check <id>` | Mark a shopping item as checked | ✓ Before execution |\n| `food edit <id\\|name> --ignore-shopping <true\\|false>` | Edit a food's ignore_shopping flag | ✓ Before execution |\n| `food ignore <id\\|name> [--unset]` | Set or clear ignore_shopping by ID or name | ✓ Before execution |\n| `food onhand <id\\|name> [--unset]` | Set or clear the on-hand flag by ID or name | ✓ Before execution |\n| `category set <food-id\\|name> --category <name\\|id>` | Assign a grocery category to a food item | ✓ Before execution |\n| `category set <food-id\\|name> --unset` | Remove the category from a food item | ✓ Before execution |\n| `cooklog add --recipe ID --servings N [--rating 1-5] [--date ISO8601]` | Add a cook log entry | ✓ Before execution |\n| `cooklog update <id> --recipe ID --servings N [--rating 1-5] [--date ISO8601]` | Update a cook log entry | ✓ Before execution |\n\n#### Destructive Operations (Require Explicit Confirmation)\n\n| Command | Description | Approval Required |\n|---|---|---|\n| `delete <id> [--force]` | Delete a recipe | ✓✓ Explicit confirmation required |\n| `mealplan delete <id>` | Delete a meal plan entry | ✓✓ Explicit confirmation required |\n| `shopping clear [--force]` | Clear all checked items | ✓✓ Explicit confirmation (bulk operation) |\n| `shopping check --all` | Mark all items as checked | ✓✓ Explicit confirmation (bulk operation) |\n| `cooklog delete <id>` | Delete a cook log entry | ✓✓ Explicit confirmation required |\n\n#### Administrative Operations (Require Privileged Token + Explicit Confirmation)\n\n**Important:** Tandoor uses **households** to organize users and recipes. Users are added to households via **invite links** — you cannot create users directly via the API.\n\n> **Permission Requirements:** Household management commands require special permissions in Tandoor. Most operations need admin/staff privileges. The `household invite create` command specifically requires **space owner** authentication — even superusers or staff members will receive a 403 Permission Denied error if they're not the space owner. If you encounter permission errors, you must use the space owner's API token or contact your Tandoor administrator.\n\n| Command | Description | Approval Required |\n|---|---|---|\n| `household add <name>` | Create a new household | ✓✓ Admin token + explicit confirmation |\n| `household edit <id> --name <name>` | Rename a household | ✓✓ Admin token + explicit confirmation |\n| `household delete <id> [--force]` | Delete a household | ✓✓ Admin token + explicit confirmation |\n| `household users assign <user-space-id> <household-id>` | Assign user to household | ✓✓ Admin token + explicit confirmation |\n| `household invite create <household-id> [--email EMAIL] [--expires DATE] [--group-id ID]` | Create invite link | ✓✓ Space-owner token + explicit confirmation |\n| `household invite delete <id> [--force]` | Delete invite link | ✓✓ Admin token + explicit confirmation |\n\nRead commands accept **`--format json`** (slim, where supported) or **`--format api`** (raw). Deprecated: `--json` (same as `--format api`).\n\n### Agent Behavior Rules\n\n**Before executing any command, the agent MUST:**\n\n1. **For read operations:** Proceed without confirmation\n2. **For write operations:** Describe the action and wait for user approval\n3. **For destructive operations:** \n   - Clearly explain what will be deleted/modified\n   - Warn that the action cannot be easily reversed\n   - Wait for explicit user confirmation (e.g., \"yes, delete recipe 42\")\n4. **For bulk operations:**\n   - State how many items will be affected\n   - Wait for explicit confirmation\n5. **For administrative operations:**\n   - Verify the user has provided an admin/space-owner token\n   - Explain the scope of the change (e.g., \"this will move user X to household Y\")\n   - Wait for explicit confirmation\n\n**The agent MUST NOT:**\n- Execute delete, force, bulk, household, invite, or user-assignment commands without explicit user approval\n- Assume the user wants destructive actions even if implied by context\n- Use `--force` flags without explicit user instruction\n- Log or display the `TANDOOR_API_TOKEN` value in any output\n\n### Configuration\n\nThe CLI supports three configuration methods (in precedence order):\n\n1. **Environment variables** — `TANDOOR_URL` and `TANDOOR_API_TOKEN` in the current shell\n2. **Config file** — `~/.config/tandoor-cli/config.json` (created by `tandoor configure`)\n3. **`.env` file** — a `.env` file in the current working directory\n\nRun `tandoor configure` once to save credentials interactively.\n\n### Examples\n\n**Configure credentials:**\n```bash\ntandoor configure\n```\n\n**Read example — list recipes as JSON:**\n```bash\ntandoor list --limit 5 --format api\n```\n\n**Read example — get recipe for editing:**\n```bash\ntandoor get 42 --format json\n```\n\n**Write example — create a recipe from a JSON file:**\n```bash\n# Agent should first ask: \"I will create a new recipe from recipe.json. Proceed?\"\n# Only after user confirms:\ntandoor add --file recipe.json\n```\n\n### Recipe JSON Schema\n\nWhen creating recipes with `tandoor add --file <file>` (or deprecated `--json <file>`), the JSON file must conform to the following structure:\n\n**TypeScript Definition:**\n```typescript\ninterface RecipeCreatePayload {\n  name: string;                    // Required: Recipe name\n  description?: string;            // Optional: Recipe description\n  servings?: number;               // Optional: Number of servings\n  working_time?: number;           // Optional: Active cooking time in minutes\n  waiting_time?: number;           // Optional: Passive time (baking, marinating) in minutes\n  steps: StepCreatePayload[];      // Required: At least one step\n}\n\ninterface StepCreatePayload {\n  instruction: string;             // Required: Step instructions\n  order: number;                   // Required: Step order (1, 2, 3, ...)\n  ingredients: IngredientCreatePayload[];  // Required: Can be empty array\n}\n\ninterface IngredientCreatePayload {\n  food: { name: string };          // Required: Ingredient name\n  unit: { name: string } | null;   // Optional: Unit of measurement (null if not applicable)\n  amount: number;                  // Required: Quantity\n  note?: string;                   // Optional: Additional notes (e.g., \"finely chopped\")\n  order?: number | null;           // Optional: Order within the step\n}\n```\n\n**Example Recipe JSON:**\n```json\n{\n  \"name\": \"Scrambled Eggs\",\n  \"description\": \"Quick and easy scrambled eggs\",\n  \"servings\": 2,\n  \"working_time\": 5,\n  \"steps\": [\n    {\n      \"instruction\": \"Crack eggs into a bowl, add milk and salt. Whisk until well combined.\",\n      \"order\": 1,\n      \"ingredients\": [\n        {\n          \"food\": { \"name\": \"eggs\" },\n          \"unit\": { \"name\": \"whole\" },\n          \"amount\": 4\n        },\n        {\n          \"food\": { \"name\": \"milk\" },\n          \"unit\": { \"name\": \"tbsp\" },\n          \"amount\": 2\n        },\n        {\n          \"food\": { \"name\": \"salt\" },\n          \"unit\": null,\n          \"amount\": 1,\n          \"note\": \"to taste\"\n        }\n      ]\n    },\n    {\n      \"instruction\": \"Heat butter in a pan over medium heat. Pour in egg mixture and stir gently until cooked to desired consistency.\",\n      \"order\": 2,\n      \"ingredients\": [\n        {\n          \"food\": { \"name\": \"butter\" },\n          \"unit\": { \"name\": \"tbsp\" },\n          \"amount\": 1\n        }\n      ]\n    }\n  ]\n}\n```\n\n**Key Points for Agents:**\n- `name` and `steps` are required fields\n- Each step must have `instruction`, `order`, and `ingredients` (can be empty array)\n- Each ingredient must have `food.name` and `amount`\n- Use `null` for `unit` when no unit applies (e.g., \"to taste\", \"pinch\")\n- Common units: `g`, `kg`, `ml`, `l`, `cup`, `tbsp`, `tsp`, `whole`, `pinch`\n- Times are in minutes\n- Steps should be ordered sequentially (1, 2, 3, ...)\n\n**Destructive example — delete a recipe:**\n```bash\n# Agent should first ask: \"This will permanently delete recipe 42. This cannot be undone. Confirm deletion?\"\n# Only after explicit user confirmation:\ntandoor delete 42 --force\n```\n\n**Image example — upload an image to a recipe:**\n```bash\n# Agent should first ask: \"I will upload my-recipe-photo.jpg to recipe 42. Proceed?\"\n# Only after user confirms:\ntandoor image 42 ./my-recipe-photo.jpg\n```\n\n**Household example — create a household and generate an invite link:**\n```bash\n# Agent should first ask: \"I will create a new household named 'My Family'. This requires admin privileges. Proceed?\"\n# Only after user confirms:\ntandoor household add \"My Family\"\n\n# Agent should first ask: \"I will create an invite link for household 1. This requires space-owner token. Proceed?\"\n# Only after user confirms:\ntandoor household invite create 1 --email user@example.com --expires 2026-12-31\n```\n\n**Shopping list example — add items and check them off:**\n```bash\n# Agent should first ask: \"I will add flour (500g) to the shopping list. Proceed?\"\n# Only after user confirms:\ntandoor shopping add --food flour --amount 500 --unit g\n\n# Agent should first ask: \"This will mark ALL shopping items as checked. Confirm?\"\n# Only after explicit confirmation:\ntandoor shopping check --all\n```\n\n**Grocery category example — organise foods for a better shopping list:**\n```bash\n# Read example — see what categories exist:\ntandoor category list\n\n# Read example — find foods with no category yet:\ntandoor category uncategorised\ntandoor category uncategorised --search pasta\n\n# Agent should first ask: \"I will assign 'milk' to the Dairy category. Proceed?\"\n# Only after user confirms:\ntandoor category set milk --category Dairy\ntandoor category set \"olive oil\" --category Oils\ntandoor category set 42 --category \"Canned Goods\"   # by food ID\n\n# Agent should first ask: \"I will remove the category from 'milk'. Proceed?\"\n# Only after user confirms:\ntandoor category set milk --unset\n```\n\n**Cook log example — track when you cook a recipe:**\n```bash\n# Agent should first ask: \"I will add a cook log entry for recipe 42 (4 servings, rating 5). Proceed?\"\n# Only after user confirms:\ntandoor cooklog add --recipe 42 --servings 4 --rating 5\n\n# Read example — list cook logs for a specific recipe:\ntandoor cooklog list --recipe 42 --format api\n\n# Read example — find when you last had eggs:\ntandoor cooklog ingredient eggs\n\n# Read example — count how many times you had chicken last month:\ntandoor cooklog ingredient chicken --startdate 2026-04-01 --enddate 2026-04-30\n\n# Read example — find highly-rated egg recipes (4-5 stars):\ntandoor cooklog ingredient eggs --min-rating 4\n\n# Read example — find poorly-rated recipes from last month (1-2 stars):\ntandoor cooklog list --startdate 2026-04-01 --enddate 2026-04-30 --max-rating 2\n\n# Agent should first ask: \"This will delete cook log entry 2. Confirm?\"\n# Only after explicit confirmation:\ntandoor cooklog delete 2\n```\n\n### Installation & Setup\n\n**Before first use:**\n1. Verify the npm package: https://www.npmjs.com/package/tandoor-cli\n2. Review the source code: https://github.com/dcenatiempo/tandoor-cli\n3. **Recommended:** Install the pinned version matching this skill: `npm install -g tandoor-cli@<version>` (see version in metadata above)\n4. Generate a token with minimal required permissions (see SECURITY.md)\n5. Consider using a test Tandoor instance first\n\n### Reference\n\n- See `references/SETUP.md` for detailed setup documentation including authentication configuration\n- See `SECURITY.md` for comprehensive security guidelines and token management best practices\n\nFile v1.4.0:_meta.json\n\n{\n  \"ownerId\": \"kn7d75mc2rzjgptnfjg8382my9864gnx\",\n  \"slug\": \"tandoor-cli\",\n  \"version\": \"1.4.0\",\n  \"publishedAt\": 1779106571732\n}\n\nFile v1.4.0:references/SETUP.md\n\n# tandoor-cli Setup Guide\n\nA command-line interface for [Tandoor Recipe Manager](https://tandoor.dev).\n\n---\n\n## Prerequisites\n\n- Node.js 18+\n- npm 8+\n- A running Tandoor instance (local or remote)\n\n---\n\n## Installation\n\n### Option 1: Install globally via npm\n\n```bash\nnpm install -g tandoor-cli\n```\n\nAfter the global install, the `tandoor` command becomes available system-wide.\n\n### Option 2: Run without installing\n\n```bash\nnpx tandoor-cli <command>\n```\n\nNo global install is required. `npx` downloads and runs the CLI on demand.\n\n**Note:** The rest of this documentation assumes a global install.\n\n---\n\n## Configuration\n\n`TANDOOR_URL` and at least one authentication method are required.\n\nThe CLI supports three configuration sources, applied in this order (highest priority first):\n\n1. Environment variables\n2. Persistent config file\n3. `.env` file\n\n### Option 1: Environment variables\n\n```bash\nexport TANDOOR_URL=http://localhost:8080\nexport TANDOOR_API_TOKEN=your_token_here\n```\n\nEnvironment variables take precedence over stored config and `.env` settings.\n\n### Option 2: `tandoor configure`\n\nRun the interactive setup command to save credentials to `~/.config/tandoor-cli/config.json`:\n\n```bash\n# without install\nnpx tandoor-cli configure\n\n# with global install\ntandoor configure\n```\n\nYou will be prompted for:\n- `TANDOOR_URL`\n- `TANDOOR_API_TOKEN`\n\nThe file is written with restricted permissions (0600) to protect your credentials.\n\n### Option 3: `.env` file\n\nCreate a `.env` file in your working directory:\n\n```dotenv\nTANDOOR_URL=http://localhost:8080\nTANDOOR_API_TOKEN=your_token_here\nTANDOOR_USERNAME=\nTANDOOR_PASSWORD=\n```\n\nThe CLI loads `.env` automatically when present.\n\n---\n\n## Authentication\n\n### API token (preferred)\n\nUse an OAuth2 access token with Bearer authentication. \n\n**Important:** The regular DRF token shown in Tandoor's Settings → API does **not** work for this CLI. You need an OAuth2 access token.\n\n**⚠️ Security Note:** Use the shortest token lifetime appropriate for your use case. For AI agent use, consider tokens that expire in days or weeks, not years.\n\n#### Generating an OAuth2 token\n\nIf you're running Tandoor in Docker, you can generate an OAuth2 token using the Django shell. Choose the appropriate example based on your needs:\n\n##### Read-Only Token (Safest)\n\nFor querying recipes only:\n\n```bash\ndocker exec <your-container-name> /opt/recipes/venv/bin/python /opt/recipes/manage.py shell -c \"\nfrom oauth2_provider.models import Application, AccessToken\nfrom django.contrib.auth.models import User\nfrom django.utils import timezone\nfrom datetime import timedelta\nimport secrets\n\nuser = User.objects.get(username='YOUR_USERNAME')\n\napp, _ = Application.objects.get_or_create(\n    name='tandoor-cli',\n    defaults=dict(\n        user=user,\n        client_type=Application.CLIENT_CONFIDENTIAL,\n        authorization_grant_type=Application.GRANT_PASSWORD,\n    )\n)\n\ntoken = AccessToken.objects.create(\n    user=user,\n    application=app,\n    token=secrets.token_hex(20),\n    expires=timezone.now() + timedelta(days=7),  # 7 days\n    scope='read',  # Read-only\n)\nprint('ACCESS TOKEN:', token.token)\n\"\n```\n\n##### Read-Write Token (Standard)\n\nFor recipe management (add, edit, delete recipes):\n\n```bash\ndocker exec <your-container-name> /opt/recipes/venv/bin/python /opt/recipes/manage.py shell -c \"\nfrom oauth2_provider.models import Application, AccessToken\nfrom django.contrib.auth.models import User\nfrom django.utils import timezone\nfrom datetime import timedelta\nimport secrets\n\nuser = User.objects.get(username='YOUR_USERNAME')\n\napp, _ = Application.objects.get_or_create(\n    name='tandoor-cli',\n    defaults=dict(\n        user=user,\n        client_type=Application.CLIENT_CONFIDENTIAL,\n        authorization_grant_type=Application.GRANT_PASSWORD,\n    )\n)\n\ntoken = AccessToken.objects.create(\n    user=user,\n    application=app,\n    token=secrets.token_hex(20),\n    expires=timezone.now() + timedelta(days=30),  # 30 days\n    scope='read write',\n)\nprint('ACCESS TOKEN:', token.token)\n\"\n```\n\nReplace `<your-container-name>` with the name of your running Tandoor Docker container and `YOUR_USERNAME` with your Tandoor username. Copy the printed token into `TANDOOR_API_TOKEN`.\n\n**Token Lifetime Recommendations:**\n- **AI agents / automation:** 7-30 days\n- **Personal CLI use:** 30-90 days\n- **Testing / development:** 1-7 days\n- **Administrative tasks:** 1 day (revoke after use)\n\n**Token Security Best Practices:**\n- Store tokens securely (environment variables, secret managers)\n- Never commit tokens to version control\n- Revoke tokens immediately if compromised\n- Rotate tokens regularly\n- Use read-only tokens when possible\n- See `SECURITY.md` for comprehensive security guidance\n\n### Username/password fallback\n\nIf `TANDOOR_API_TOKEN` is missing, the CLI falls back to HTTP Basic Authentication using `TANDOOR_USERNAME` and `TANDOOR_PASSWORD`.\n\n**Note:** This method is less secure and not recommended for production use.\n\n---\n\n## Verification\n\nTest your configuration:\n\n```bash\n# Check version\ntandoor --version\n\n# List recipes (requires valid credentials)\ntandoor list --limit 5\n```\n\nIf you see recipes listed, your configuration is working correctly!\n\n---\n\n## Troubleshooting\n\n### \"TANDOOR_URL is not set\"\n\nRun `tandoor configure` or set the `TANDOOR_URL` environment variable.\n\n### \"Authentication failed\" or 401 errors\n\n- Verify your `TANDOOR_API_TOKEN` is a valid OAuth2 token (not a DRF token)\n- Check that your token hasn't expired\n- Ensure your Tandoor instance is accessible at the configured URL\n\n### \"Permission denied\" or 403 errors\n\nSome commands (especially household management) require admin or space owner privileges. Check your user permissions in Tandoor.\n\n### Command not found\n\nIf `tandoor` command is not found after global install:\n- Verify npm's global bin directory is in your PATH\n- Try `npx tandoor-cli` instead\n- Reinstall: `npm install -g tandoor-cli`\n\n---\n\n## Next Steps\n\nFor command usage examples and full documentation, see the main [README](https://github.com/dcenatiempo/tandoor-cli#readme).\n\nFile v1.4.0:SECURITY_REVIEW_RESPONSE.md\n\n# Response to OlawHub Security Review\n\nThis document summarizes the changes made to address security concerns raised in the OlawHub skill review.\n\n## Review Date\nMay 4, 2026\n\n## Summary of Changes\n\nAll security concerns have been addressed through documentation updates, explicit approval gates, and security best practices guidance.\n\n---\n\n## 1. Tool Misuse and Exploitation (HIGH SEVERITY)\n\n### Original Concern\n> The skill exposes destructive, bulk, and account-administration operations to the agent, but the instructions do not add explicit approval gates or limits for these high-impact actions.\n\n### Resolution\n\n**Files Modified:**\n- `SKILL.md`\n- `references/SETUP.md`\n\n**Changes Made:**\n\n1. **Command Classification System**\n   - All commands now categorized by risk level:\n     - Read operations (safe, no approval)\n     - Write operations (require user confirmation)\n     - Destructive operations (require explicit confirmation)\n     - Administrative operations (require privileged token + explicit confirmation)\n\n2. **Explicit Approval Gates**\n   - Added \"Approval Required\" column to command tables\n   - Documented specific confirmation messages for each destructive operation\n   - Examples:\n     - `delete <id>`: \"This will permanently delete recipe X. Cannot be undone. Confirm?\"\n     - `shopping check --all`: \"This will mark ALL shopping items as checked. Confirm?\"\n     - `household users assign`: \"This will move user X to household Y. Confirm?\"\n\n3. **Agent Behavior Rules Section**\n   - Clear instructions on when to proceed vs. when to ask\n   - Explicit prohibition on using `--force` without user instruction\n   - Requirement to explain impact before destructive operations\n\n4. **Security Warning Banner**\n   - Added prominent warning at top of SKILL.md\n   - States: \"This skill provides mutation authority over your Tandoor instance\"\n   - Directs users to only install if they want agent mutation authority\n\n**User Impact:** Agents can no longer execute destructive operations without explicit user approval. Users maintain full control over high-impact actions.\n\n---\n\n## 2. Agentic Supply Chain Vulnerabilities (LOW SEVERITY)\n\n### Original Concern\n> The skill relies on an external npm package that is not included in the reviewed artifact set; npx may download and run package code on demand.\n\n### Resolution\n\n**Files Modified:**\n- `SKILL.md`\n- `SECURITY.md`\n\n**Changes Made:**\n\n1. **Version Awareness**\n   - Documentation acknowledges the npm package dependency\n   - Recommends version pinning for production use\n\n2. **Verification Links**\n   - Added direct links to npm package: https://www.npmjs.com/package/tandoor-cli\n   - Added direct link to source repository: https://github.com/dcenatiempo/tandoor-cli\n   - Included in \"Before first use\" checklist\n\n3. **Pre-Installation Checklist**\n   - Verify the npm package\n   - Review the source code\n   - Consider using a test instance first\n\n4. **Supply Chain Security Section**\n   - Added to SKILL.md under \"Security & Permission Model\"\n   - Recommends reviewing package before use with privileged credentials\n   - Suggests monitoring npm security advisories\n\n**User Impact:** Users can verify the package source and pin to known-good versions before granting access to their Tandoor instance.\n\n---\n\n## 3. Identity and Privilege Abuse - Space Owner Token (HIGH SEVERITY)\n\n### Original Concern\n> The skill directs use of a highly privileged Tandoor identity for household invite management, which is broader than ordinary recipe and shopping-list management.\n\n### Resolution\n\n**Files Modified:**\n- `SKILL.md`\n- `SECURITY.md`\n- `references/SETUP.md`\n\n**Changes Made:**\n\n1. **Least Privilege Principle**\n   - Added \"Token Security\" section emphasizing least-privileged tokens\n   - Guidance on token scoping:\n     - Read-only tokens for queries\n     - Standard user tokens for recipe management\n     - Admin tokens only for household management\n     - Space-owner tokens only for invite creation\n\n2. **Command-Level Permission Documentation**\n   - Each administrative command now states required permission level\n   - Example: \"household invite create\" explicitly states \"Space-owner token + explicit confirmation\"\n\n3. **Permission Error Guidance**\n   - Users directed to contact administrators if lacking permissions\n   - Clear explanation that 403 errors indicate insufficient privileges\n\n4. **Token Scoping Examples**\n   - SECURITY.md provides three token configuration examples:\n     - Read-only (safest)\n     - Recipe management (standard)\n     - Administrative tasks (restricted)\n\n**User Impact:** Users can create appropriately scoped tokens for their use case, avoiding over-privileged access.\n\n---\n\n## 4. Identity and Privilege Abuse - Long-Lived Tokens (MEDIUM SEVERITY)\n\n### Original Concern\n> The setup guide demonstrates creating a long-lived read/write OAuth2 access token, which would let the CLI perform both read and mutation operations for up to a year if not revoked.\n\n### Resolution\n\n**Files Modified:**\n- `references/SETUP.md`\n- `SECURITY.md`\n\n**Changes Made:**\n\n1. **Token Lifetime Recommendations**\n   - Changed default example from 365 days (1 year) to 7-30 days\n   - Added \"Token Lifetime Recommendations\" section:\n     - AI agents / automation: 7-30 days\n     - Personal CLI use: 30-90 days\n     - Testing / development: 1-7 days\n     - Administrative tasks: 1 day (revoke after use)\n\n2. **Multiple Token Examples**\n   - SETUP.md now provides separate examples for:\n     - Read-only token (7 days, `scope='read'`)\n     - Read-write token (30 days, `scope='read write'`)\n   - Users choose appropriate example for their use case\n\n3. **Token Security Best Practices**\n   - Store tokens securely (environment variables, secret managers)\n   - Never commit tokens to version control\n   - Revoke tokens immediately if compromised\n   - Rotate tokens regularly\n   - Use read-only tokens when possible\n\n4. **Token Management Commands**\n   - SECURITY.md includes commands to:\n     - List active tokens\n     - Revoke unused tokens\n     - Audit token usage\n\n**User Impact:** Users create shorter-lived tokens appropriate for their use case, reducing exposure window if tokens are compromised.\n\n---\n\n## New Documentation\n\n### SECURITY.md (New File)\n\nComprehensive security documentation covering:\n\n1. **Overview of Security Model**\n2. **Detailed Mitigation for Each Concern**\n3. **Recommended Token Configurations**\n   - Read-only, standard, and administrative examples\n4. **Token Storage Best Practices**\n   - Secure vs. insecure methods\n5. **Monitoring and Auditing**\n   - Commands to list and revoke tokens\n   - Incident response procedures\n6. **Agent-Specific Security**\n   - Guidance for AI agent users\n   - Agent behavior validation tests\n7. **Compliance and Governance**\n   - Organizational policies\n   - Personal use guidelines\n8. **Reporting Security Issues**\n\n---\n\n## Testing Recommendations\n\nTo verify the security improvements:\n\n### 1. Test Agent Approval Gates\n\n```bash\n# Should prompt for confirmation, not execute immediately:\n\"Delete recipe 42\"\n\"Clear all shopping items\"\n\"Create a new household\"\n\n# Should proceed without confirmation:\n\"List all recipes\"\n\"Search for pasta recipes\"\n```\n\n### 2. Test Token Scoping\n\n```bash\n# Create a read-only token and verify write operations fail:\nexport TANDOOR_API_TOKEN=<read-only-token>\ntandoor list  # Should work\ntandoor add --json recipe.json  # Should fail with 403\n```\n\n### 3. Test Version Awareness\n\n```bash\n# Verify the CLI version:\ntandoor --version\n```\n\n---\n\n## Compliance Summary\n\n| Concern | Severity | Status | Mitigation |\n|---------|----------|--------|------------|\n| Tool Misuse and Exploitation | HIGH | ✅ Resolved | Explicit approval gates, command classification, agent behavior rules |\n| Agentic Supply Chain | LOW | ✅ Resolved | Verification links, pre-installation checklist, version awareness |\n| Space Owner Token Privilege | HIGH | ✅ Resolved | Least privilege guidance, token scoping examples, permission documentation |\n| Long-Lived Tokens | MEDIUM | ✅ Resolved | Shorter default lifetimes, token rotation guidance, security best practices |\n\n---\n\n## Recommendations for Users\n\n### Before Installation\n\n1. ✅ Read `SECURITY.md` to understand the security model\n2. ✅ Verify the npm package at https://www.npmjs.com/package/tandoor-cli\n3. ✅ Review the source code at https://github.com/dcenatiempo/tandoor-cli\n4. ✅ Decide what level of access you want to grant the agent\n\n### During Setup\n\n1. ✅ Create a token with the minimum required permissions\n2. ✅ Use short token lifetimes (7-30 days for agents)\n3. ✅ Store tokens securely (environment variables, secret managers)\n4. ✅ Test with a non-production Tandoor instance first\n\n### After Installation\n\n1. ✅ Monitor agent behavior for unexpected commands\n2. ✅ Verify agents request approval for destructive operations\n3. ✅ Rotate tokens regularly\n4. ✅ Revoke tokens immediately if compromised\n\n---\n\n## Contact\n\nFor questions about these security improvements:\n- Open an issue in the repository\n- Tag issues with `[SECURITY]` for priority handling\n\nFor security vulnerabilities:\n- Report privately via GitHub Security Advisories\n- Do not disclose publicly until patched\n\n---\n\n## Version History\n\n- **v0.4.0** (May 2026): Security improvements addressing OlawHub review\n- **v0.3.0** (Earlier): Initial skill release\n\nFile v1.4.0:SECURITY.md\n\n# Security Guidelines for Tandoor CLI Skill\n\nThis document addresses security concerns and best practices for using the tandoor-cli skill with AI agents.\n\n## Overview\n\nThe tandoor-cli skill provides programmatic access to your Tandoor Recipe Manager instance. Like any tool with write access to your data, it requires careful configuration and usage to maintain security.\n\n## Addressed Security Concerns\n\n### 1. Tool Misuse and Exploitation (HIGH SEVERITY)\n\n**Concern:** The skill exposes destructive, bulk, and account-administration operations without explicit approval gates.\n\n**Mitigation:**\n- **Command Classification:** All commands are now classified by risk level (read, write, destructive, administrative)\n- **Approval Gates:** The SKILL.md explicitly requires user confirmation before:\n  - Any write operation (add, update, import)\n  - Any destructive operation (delete, clear, bulk operations)\n  - Any administrative operation (household management, user assignment)\n- **Agent Behavior Rules:** Clear instructions prevent agents from executing high-risk commands without explicit user approval\n- **No Automatic --force:** Agents are forbidden from using `--force` flags without explicit user instruction\n\n**User Action Required:**\n- Review the command classification table in SKILL.md\n- Only install this skill if you want the agent to have mutation authority\n- Monitor agent behavior and revoke access if misuse is detected\n\n### 2. Agentic Supply Chain Vulnerabilities (LOW SEVERITY)\n\n**Concern:** The skill relies on an external npm package that could be compromised.\n\n**Mitigation:**\n- **Version Pinning:** The skill explicitly uses `npx tandoor-cli@0.3.1` to pin to a known version\n- **Verification Links:** SKILL.md provides direct links to:\n  - npm package: https://www.npmjs.com/package/tandoor-cli\n  - Source repository: https://github.com/dcenatiempo/tandoor-cli\n- **Pre-Installation Checklist:** Users are instructed to verify the package before first use\n- **No Auto-Updates:** Using `@version` syntax prevents automatic updates to potentially compromised versions\n\n**User Action Required:**\n- Verify the npm package and repository before first installation\n- Review the package source code if using privileged credentials\n- Monitor npm security advisories for the tandoor-cli package\n- Update to newer versions only after reviewing changelogs\n\n### 3. Identity and Privilege Abuse - Space Owner Token (HIGH SEVERITY)\n\n**Concern:** The skill directs use of a highly privileged space-owner token for household invite management.\n\n**Mitigation:**\n- **Least Privilege Principle:** SKILL.md now emphasizes using the least-privileged token possible\n- **Token Scoping Guidance:**\n  - Read-only tokens for query operations\n  - Standard user tokens for recipe management\n  - Admin tokens only when household management is required\n  - Space-owner tokens only for invite link creation\n- **Explicit Warnings:** Administrative commands clearly state they require privileged tokens\n- **Permission Errors:** Users are directed to contact administrators if they lack necessary permissions\n\n**User Action Required:**\n- Create separate tokens for different use cases\n- Use read-only tokens when possible\n- Avoid providing space-owner tokens unless invite management is truly needed\n- Revoke privileged tokens immediately after administrative tasks\n\n### 4. Identity and Privilege Abuse - Long-Lived Tokens (MEDIUM SEVERITY)\n\n**Concern:** The setup guide demonstrates creating long-lived (10-year) read/write OAuth2 tokens.\n\n**Mitigation:**\n- **Token Lifetime Guidance:** SKILL.md now recommends short-lived tokens (days/weeks) instead of long-lived tokens (years)\n- **Security Best Practices Section:** Added explicit guidance on:\n  - Token rotation schedules\n  - Secure token storage\n  - Immediate revocation if compromised\n  - Regular token audits\n- **Alternative Approaches:** Users are encouraged to:\n  - Generate tokens on-demand for specific tasks\n  - Revoke tokens after use\n  - Use environment-specific tokens (dev vs. production)\n\n**User Action Required:**\n- Modify the token generation command to use shorter expiry periods:\n  ```python\n  expires=timezone.now() + timedelta(days=7)  # 7 days instead of 3650\n  ```\n- Implement a token rotation schedule\n- Store tokens securely (environment variables, secret managers, not in code)\n- Revoke unused tokens regularly\n\n## Recommended Token Configuration\n\n### For Read-Only Use (Safest)\n\nIf you only need to query recipes, create a read-only token:\n\n```python\ntoken = AccessToken.objects.create(\n    user=user,\n    application=app,\n    token=secrets.token_hex(20),\n    expires=timezone.now() + timedelta(days=7),  # 7 days\n    scope='read',  # Read-only\n)\n```\n\n### For Recipe Management (Standard)\n\nFor adding/editing recipes but not administrative tasks:\n\n```python\ntoken = AccessToken.objects.create(\n    user=user,\n    application=app,\n    token=secrets.token_hex(20),\n    expires=timezone.now() + timedelta(days=30),  # 30 days\n    scope='read write',\n)\n```\n\nUse a standard user account (not admin/staff).\n\n### For Administrative Tasks (Restricted)\n\nOnly when household management is required:\n\n```python\ntoken = AccessToken.objects.create(\n    user=admin_user,  # Must be admin/staff\n    application=app,\n    token=secrets.token_hex(20),\n    expires=timezone.now() + timedelta(days=1),  # 1 day\n    scope='read write',\n)\n```\n\nRevoke immediately after completing administrative tasks.\n\n## Token Storage Best Practices\n\n### ✅ Secure Methods\n\n- **Environment variables:** `export TANDOOR_API_TOKEN=...` (session-only)\n- **Secret managers:** AWS Secrets Manager, HashiCorp Vault, 1Password CLI\n- **Encrypted config files:** `~/.config/tandoor-cli/config.json` with `0600` permissions\n- **CI/CD secrets:** GitHub Secrets, GitLab CI/CD variables\n\n### ❌ Insecure Methods\n\n- **Plain text in code:** Never commit tokens to version control\n- **Shared config files:** Avoid world-readable files\n- **Chat logs:** Don't paste tokens in Slack, Discord, etc.\n- **Browser history:** Be careful with tokens in URLs\n\n## Monitoring and Auditing\n\n### Regular Security Checks\n\n1. **List active tokens:**\n   ```python\n   docker exec <container> /opt/recipes/venv/bin/python /opt/recipes/manage.py shell -c \"\n   from oauth2_provider.models import AccessToken\n   from django.utils import timezone\n   \n   active = AccessToken.objects.filter(expires__gt=timezone.now())\n   for token in active:\n       print(f'{token.user.username}: {token.scope} (expires {token.expires})')\n   \"\n   ```\n\n2. **Revoke unused tokens:**\n   ```python\n   docker exec <container> /opt/recipes/venv/bin/python /opt/recipes/manage.py shell -c \"\n   from oauth2_provider.models import AccessToken\n   \n   # Revoke all tokens for tandoor-cli app\n   AccessToken.objects.filter(application__name='tandoor-cli').delete()\n   \"\n   ```\n\n3. **Review Tandoor audit logs:** Check for unexpected API activity\n\n### Incident Response\n\nIf a token is compromised:\n\n1. **Immediately revoke the token** using the command above\n2. **Review recent API activity** in Tandoor logs\n3. **Generate a new token** with a different value\n4. **Update all systems** using the old token\n5. **Investigate** how the token was exposed\n\n## Agent-Specific Security\n\n### For AI Agent Users\n\nWhen using this skill with AI agents (Kiro, Claude, etc.):\n\n1. **Start with read-only tokens** to test agent behavior\n2. **Monitor agent commands** before granting write access\n3. **Use approval hooks** to review destructive operations\n4. **Limit token scope** to the minimum required for the task\n5. **Revoke tokens** when the agent task is complete\n\n### Agent Behavior Validation\n\nTest that your agent follows the security rules:\n\n```bash\n# This should prompt for confirmation, not execute immediately\n\"Delete recipe 42\"\n\n# This should refuse without explicit user approval\n\"Clear all shopping items\"\n\n# This should warn about privilege requirements\n\"Create a new household\"\n```\n\nIf your agent executes these without confirmation, the skill is not being used correctly.\n\n## Compliance and Governance\n\n### For Organizations\n\nIf deploying this skill in a team or organization:\n\n- **Access Control:** Limit who can generate API tokens\n- **Token Policies:** Enforce maximum token lifetimes\n- **Audit Logging:** Enable and monitor Tandoor API logs\n- **Incident Response:** Have a plan for token compromise\n- **Training:** Ensure users understand the security model\n\n### For Personal Use\n\nEven for personal Tandoor instances:\n\n- **Principle of Least Privilege:** Use the minimum permissions needed\n- **Defense in Depth:** Don't rely solely on token security\n- **Regular Reviews:** Audit tokens and agent behavior periodically\n- **Backup Strategy:** Maintain backups in case of accidental deletion\n\n## Reporting Security Issues\n\nIf you discover a security vulnerability in:\n\n- **tandoor-cli package:** Report to https://github.com/dcenatiempo/tandoor-cli/security\n- **Tandoor Recipe Manager:** Report to https://github.com/TandoorRecipes/recipes/security\n- **This skill:** Open an issue at your repository with `[SECURITY]` prefix\n\nDo not disclose security vulnerabilities publicly until they are patched.\n\n## Version History\n\n- **v0.4.0** (May 2026): Added comprehensive security documentation and approval gates\n- **v0.3.0** (Earlier): Initial skill release\n\n## Additional Resources\n\n- [Tandoor Security Documentation](https://docs.tandoor.dev/security/)\n- [OAuth2 Best Practices](https://oauth.net/2/oauth-best-practice/)\n- [OWASP API Security Top 10](https://owasp.org/www-project-api-security/)\n- [Agent Skills Security Guidelines](https://agentskills.io/security)\n\nArchive v1.1.5: 5 files, 16162 bytes\n\nFiles: references/SETUP.md (6080b), SECURITY_REVIEW_RESPONSE.md (9354b), SECURITY.md (9632b), SKILL.md (16548b), _meta.json (130b)\n\nFile v1.1.5:SKILL.md\n\n---\nname: tandoor-recipe-cli\ndescription: Manage recipes, meal plans, and shopping lists on a Tandoor Recipe Manager instance via CLI.\nversion: 1.3.0\ncompatibility: \">=18\"\nlicense: MIT\nmetadata:\n  author: dcenatiempo\n  repository: https://github.com/dcenatiempo/tandoor-cli\n---\n\n## Tandoor CLI Skill\n\nThis skill provides AI agents with the ability to interact with a Tandoor Recipe Manager instance using the `tandoor-cli` command-line tool.\n\n### Prerequisites\n\nThe `tandoor-cli` tool must be installed and configured.\n\n**Version Compatibility:** This skill documentation corresponds to the version specified in the metadata above. Before using this skill:\n1. Verify your installed CLI version: `tandoor -V`\n2. Ensure the installed version matches the skill version to avoid unexpected behavior or missing commands\n3. If versions don't match, reinstall the CLI tool following the setup instructions in `references/SETUP.md`\n\nIf `tandoor -V` produces no valid version, see the setup instructions in `references/SETUP.md`.\n\n### Security & Permission Model\n\n**⚠️ IMPORTANT: This skill provides mutation authority over your Tandoor instance.**\n\n- **Read operations** (list, search, get, random) are safe and require no confirmation\n- **Write operations** (add, update, import) modify data but are typically reversible\n- **Destructive operations** (delete, clear, household management) require explicit user approval before execution\n- **Bulk operations** (shopping check --all, clear) affect multiple items and require confirmation\n- **Administrative operations** (household management, user assignment, invite creation) require privileged credentials and explicit approval\n\n**Token Security:**\n- Use the **least-privileged token** possible for your use case\n- Prefer read-only tokens if you only need to query recipes\n- Avoid using space-owner or admin tokens unless household management is required\n- Consider short-lived tokens (days/weeks) instead of long-lived tokens (years)\n- Store tokens securely and rotate them regularly\n- Revoke tokens immediately if compromised or no longer needed\n\n**Supply Chain:**\n- This skill uses the `tandoor-cli` npm package\n- Verify the package source before first use: https://www.npmjs.com/package/tandoor-cli\n- Review the package repository: https://github.com/dcenatiempo/tandoor-cli\n- **Recommended:** Pin to the specific version matching this skill (see version in metadata above) to avoid unexpected updates\n- Install pinned version: `npm install -g tandoor-cli@<version>` (replace `<version>` with the skill version)\n\n### Invocation\n\n```bash\ntandoor <command> [options]\n```\n\n### Output formats and deprecated flags\n\nCommands that print data accept **`--format text|json|api`** (default: `text`):\n\n| `--format` | Use for |\n|------------|---------|\n| `text` | Human-readable output (default) |\n| `json` | Slim JSON where supported (recipe add/update shape + `id` on `get`, `list`, `search`, `random`) |\n| `api` | Raw Tandoor API JSON |\n\n**Deprecated (output):** `--json` with no file path — alias for **`--format api`**; stderr warning. Do not use in new agent workflows.\n\n**Recommended (input):** `tandoor add --file recipe.json`, `tandoor update <id> --file patch.json`\n\n**Deprecated (input):** `tandoor add --json <file>`, `tandoor update <id> --json <file>` — still work with stderr warning.\n\n| Deprecated | Use instead |\n|------------|-------------|\n| `tandoor get 1 --json` | `--format api` (full) or `--format json` (slim, for edit round-trips) |\n| `tandoor list --json` | `--format api` |\n| `tandoor add --json recipe.json` | `--file recipe.json` |\n| `tandoor update 42 --json patch.json` | `--file patch.json` |\n\n### Commands\n\n#### Read Operations (Safe)\n\n**Recipes:**\n| Command | Description |\n|---|---|\n| `list [--limit N] [--page N] [--all]` | List recipes (default 20 per page, max 100) |\n| `search <query>` | Search recipes by keyword |\n| `get <id>` | Get full recipe details |\n| `random` | Get a random recipe |\n\n**Meal Plans:**\n| Command | Description |\n|---|---|\n| `mealplan list [--startdate DATE] [--enddate DATE]` | List meal plan entries (optionally filtered by date range) |\n\n**Shopping List:**\n| Command | Description |\n|---|---|\n| `shopping list` | List shopping list entries |\n\n**Food Ingredients:**\n| Command | Description |\n|---|---|\n| `food list [--limit N] [--page N] [--all] [--search TERM] [--ignored] [--onhand]` | List food ingredients |\n\n**Cook Logs:**\n| Command | Description |\n|---|---|\n| `cooklog list [--recipe ID] [--limit N] [--page N] [--all] [--startdate YYYY-MM-DD] [--enddate YYYY-MM-DD] [--min-rating 1-5] [--max-rating 1-5]` | List cook log entries (sorted by most recent first) |\n| `cooklog ingredient <name> [--limit N] [--startdate YYYY-MM-DD] [--enddate YYYY-MM-DD] [--min-rating 1-5] [--max-rating 1-5]` | Find cook logs by ingredient name (e.g., \"when did we last have eggs?\") |\n\n**Households & Users:**\n| Command | Description |\n|---|---|\n| `household list` | List all households |\n| `household get <id>` | Get household details by ID |\n| `household users list` | List all users in the space |\n| `household users memberships` | List user-space memberships |\n| `household invite list` | List all invite links |\n\n#### Write Operations (Require Confirmation)\n\n| Command | Description | Approval Required |\n|---|---|---|\n| `add [--file file] [--interactive]` | Create a recipe (`--json <file>` deprecated) | ✓ Before execution |\n| `update <id> --file file` | Patch an existing recipe (`--json <file>` deprecated) | ✓ Before execution |\n| `import <url> [--dry-run]` | Import a recipe from a URL | ✓ Before execution |\n| `image <recipeId> <imagePath>` | Upload an image to a recipe | ✓ Before execution |\n| `mealplan add --recipe ID --date YYYY-MM-DD --meal-type N` | Add a meal plan entry | ✓ Before execution |\n| `shopping add --food NAME --amount N --unit UNIT` | Add a shopping list item | ✓ Before execution |\n| `shopping check <id>` | Mark a shopping item as checked | ✓ Before execution |\n| `food edit <id\\|name> --ignore-shopping <true\\|false>` | Edit a food's ignore_shopping flag | ✓ Before execution |\n| `food ignore <id\\|name> [--unset]` | Set or clear ignore_shopping by ID or name | ✓ Before execution |\n| `food onhand <id\\|name> [--unset]` | Set or clear the on-hand flag by ID or name | ✓ Before execution |\n| `cooklog add --recipe ID --servings N [--rating 1-5] [--date ISO8601]` | Add a cook log entry | ✓ Before execution |\n| `cooklog update <id> --recipe ID --servings N [--rating 1-5] [--date ISO8601]` | Update a cook log entry | ✓ Before execution |\n\n#### Destructive Operations (Require Explicit Confirmation)\n\n| Command | Description | Approval Required |\n|---|---|---|\n| `delete <id> [--force]` | Delete a recipe | ✓✓ Explicit confirmation required |\n| `mealplan delete <id>` | Delete a meal plan entry | ✓✓ Explicit confirmation required |\n| `shopping clear [--force]` | Clear all checked items | ✓✓ Explicit confirmation (bulk operation) |\n| `shopping check --all` | Mark all items as checked | ✓✓ Explicit confirmation (bulk operation) |\n| `cooklog delete <id>` | Delete a cook log entry | ✓✓ Explicit confirmation required |\n\n#### Administrative Operations (Require Privileged Token + Explicit Confirmation)\n\n**Important:** Tandoor uses **households** to organize users and recipes. Users are added to households via **invite links** — you cannot create users directly via the API.\n\n> **Permission Requirements:** Household management commands require special permissions in Tandoor. Most operations need admin/staff privileges. The `household invite create` command specifically requires **space owner** authentication — even superusers or staff members will receive a 403 Permission Denied error if they're not the space owner. If you encounter permission errors, you must use the space owner's API token or contact your Tandoor administrator.\n\n| Command | Description | Approval Required |\n|---|---|---|\n| `household add <name>` | Create a new household | ✓✓ Admin token + explicit confirmation |\n| `household edit <id> --name <name>` | Rename a household | ✓✓ Admin token + explicit confirmation |\n| `household delete <id> [--force]` | Delete a household | ✓✓ Admin token + explicit confirmation |\n| `household users assign <user-space-id> <household-id>` | Assign user to household | ✓✓ Admin token + explicit confirmation |\n| `household invite create <household-id> [--email EMAIL] [--expires DATE] [--group-id ID]` | Create invite link | ✓✓ Space-owner token + explicit confirmation |\n| `household invite delete <id> [--force]` | Delete invite link | ✓✓ Admin token + explicit confirmation |\n\nRead commands accept **`--format json`** (slim, where supported) or **`--format api`** (raw). Deprecated: `--json` (same as `--format api`).\n\n### Agent Behavior Rules\n\n**Before executing any command, the agent MUST:**\n\n1. **For read operations:** Proceed without confirmation\n2. **For write operations:** Describe the action and wait for user approval\n3. **For destructive operations:** \n   - Clearly explain what will be deleted/modified\n   - Warn that the action cannot be easily reversed\n   - Wait for explicit user confirmation (e.g., \"yes, delete recipe 42\")\n4. **For bulk operations:**\n   - State how many items will be affected\n   - Wait for explicit confirmation\n5. **For administrative operations:**\n   - Verify the user has provided an admin/space-owner token\n   - Explain the scope of the change (e.g., \"this will move user X to household Y\")\n   - Wait for explicit confirmation\n\n**The agent MUST NOT:**\n- Execute delete, force, bulk, household, invite, or user-assignment commands without explicit user approval\n- Assume the user wants destructive actions even if implied by context\n- Use `--force` flags without explicit user instruction\n- Log or display the `TANDOOR_API_TOKEN` value in any output\n\n### Configuration\n\nThe CLI supports three configuration methods (in precedence order):\n\n1. **Environment variables** — `TANDOOR_URL` and `TANDOOR_API_TOKEN` in the current shell\n2. **Config file** — `~/.config/tandoor-cli/config.json` (created by `tandoor configure`)\n3. **`.env` file** — a `.env` file in the current working directory\n\nRun `tandoor configure` once to save credentials interactively.\n\n### Examples\n\n**Configure credentials:**\n```bash\ntandoor configure\n```\n\n**Read example — list recipes as JSON:**\n```bash\ntandoor list --limit 5 --format api\n```\n\n**Read example — get recipe for editing:**\n```bash\ntandoor get 42 --format json\n```\n\n**Write example — create a recipe from a JSON file:**\n```bash\n# Agent should first ask: \"I will create a new recipe from recipe.json. Proceed?\"\n# Only after user confirms:\ntandoor add --file recipe.json\n```\n\n### Recipe JSON Schema\n\nWhen creating recipes with `tandoor add --file <file>` (or deprecated `--json <file>`), the JSON file must conform to the following structure:\n\n**TypeScript Definition:**\n```typescript\ninterface RecipeCreatePayload {\n  name: string;                    // Required: Recipe name\n  description?: string;            // Optional: Recipe description\n  servings?: number;               // Optional: Number of servings\n  working_time?: number;           // Optional: Active cooking time in minutes\n  waiting_time?: number;           // Optional: Passive time (baking, marinating) in minutes\n  steps: StepCreatePayload[];      // Required: At least one step\n}\n\ninterface StepCreatePayload {\n  instruction: string;             // Required: Step instructions\n  order: number;                   // Required: Step order (1, 2, 3, ...)\n  ingredients: IngredientCreatePayload[];  // Required: Can be empty array\n}\n\ninterface IngredientCreatePayload {\n  food: { name: string };          // Required: Ingredient name\n  unit: { name: string } | null;   // Optional: Unit of measurement (null if not applicable)\n  amount: number;                  // Required: Quantity\n  note?: string;                   // Optional: Additional notes (e.g., \"finely chopped\")\n  order?: number | null;           // Optional: Order within the step\n}\n```\n\n**Example Recipe JSON:**\n```json\n{\n  \"name\": \"Scrambled Eggs\",\n  \"description\": \"Quick and easy scrambled eggs\",\n  \"servings\": 2,\n  \"working_time\": 5,\n  \"steps\": [\n    {\n      \"instruction\": \"Crack eggs into a bowl, add milk and salt. Whisk until well combined.\",\n      \"order\": 1,\n      \"ingredients\": [\n        {\n          \"food\": { \"name\": \"eggs\" },\n          \"unit\": { \"name\": \"whole\" },\n          \"amount\": 4\n        },\n        {\n          \"food\": { \"name\": \"milk\" },\n          \"unit\": { \"name\": \"tbsp\" },\n          \"amount\": 2\n        },\n        {\n          \"food\": { \"name\": \"salt\" },\n          \"unit\": null,\n          \"amount\": 1,\n          \"note\": \"to taste\"\n        }\n      ]\n    },\n    {\n      \"instruction\": \"Heat butter in a pan over medium heat. Pour in egg mixture and stir gently until cooked to desired consistency.\",\n      \"order\": 2,\n      \"ingredients\": [\n        {\n          \"food\": { \"name\": \"butter\" },\n          \"unit\": { \"name\": \"tbsp\" },\n          \"amount\": 1\n        }\n      ]\n    }\n  ]\n}\n```\n\n**Key Points for Agents:**\n- `name` and `steps` are required fields\n- Each step must have `instruction`, `order`, and `ingredients` (can be empty array)\n- Each ingredient must have `food.name` and `amount`\n- Use `null` for `unit` when no unit applies (e.g., \"to taste\", \"pinch\")\n- Common units: `g`, `kg`, `ml`, `l`, `cup`, `tbsp`, `tsp`, `whole`, `pinch`\n- Times are in minutes\n- Steps should be ordered sequentially (1, 2, 3, ...)\n\n**Destructive example — delete a recipe:**\n```bash\n# Agent should first ask: \"This will permanently delete recipe 42. This cannot be undone. Confirm deletion?\"\n# Only after explicit user confirmation:\ntandoor delete 42 --force\n```\n\n**Image example — upload an image to a recipe:**\n```bash\n# Agent should first ask: \"I will upload my-recipe-photo.jpg to recipe 42. Proceed?\"\n# Only after user confirms:\ntandoor image 42 ./my-recipe-photo.jpg\n```\n\n**Household example — create a household and generate an invite link:**\n```bash\n# Agent should first ask: \"I will create a new household named 'My Family'. This requires admin privileges. Proceed?\"\n# Only after user confirms:\ntandoor household add \"My Family\"\n\n# Agent should first ask: \"I will create an invite link for household 1. This requires space-owner token. Proceed?\"\n# Only after user confirms:\ntandoor household invite create 1 --email user@example.com --expires 2026-12-31\n```\n\n**Shopping list example — add items and check them off:**\n```bash\n# Agent should first ask: \"I will add flour (500g) to the shopping list. Proceed?\"\n# Only after user confirms:\ntandoor shopping add --food flour --amount 500 --unit g\n\n# Agent should first ask: \"This will mark ALL shopping items as checked. Confirm?\"\n# Only after explicit confirmation:\ntandoor shopping check --all\n```\n\n**Cook log example — track when you cook a recipe:**\n```bash\n# Agent should first ask: \"I will add a cook log entry for recipe 42 (4 servings, rating 5). Proceed?\"\n# Only after user confirms:\ntandoor cooklog add --recipe 42 --servings 4 --rating 5\n\n# Read example — list cook logs for a specific recipe:\ntandoor cooklog list --recipe 42 --format api\n\n# Read example — find when you last had eggs:\ntandoor cooklog ingredient eggs\n\n# Read example — count how many times you had chicken last month:\ntandoor cooklog ingredient chicken --startdate 2026-04-01 --enddate 2026-04-30\n\n# Read example — find highly-rated egg recipes (4-5 stars):\ntandoor cooklog ingredient eggs --min-rating 4\n\n# Read example — find poorly-rated recipes from last month (1-2 stars):\ntandoor cooklog list --startdate 2026-04-01 --enddate 2026-04-30 --max-rating 2\n\n# Agent should first ask: \"This will delete cook log entry 2. Confirm?\"\n# Only after explicit confirmation:\ntandoor cooklog delete 2\n```\n\n### Installation & Setup\n\n**Before first use:**\n1. Verify the npm package: https://www.npmjs.com/package/tandoor-cli\n2. Review the source code: https://github.com/dcenatiempo/tandoor-cli\n3. **Recommended:** Install the pinned version matching this skill: `npm install -g tandoor-cli@<version>` (see version in metadata above)\n4. Generate a token with minimal required permissions (see SECURITY.md)\n5. Consider using a test Tandoor instance first\n\n### Reference\n\n- See `references/SETUP.md` for detailed setup documentation including authentication configuration\n- See `SECURITY.md` for comprehensive security guidelines and token management best practices\n\nFile v1.1.5:_meta.json\n\n{\n  \"ownerId\": \"kn7d75mc2rzjgptnfjg8382my9864gnx\",\n  \"slug\": \"tandoor-cli\",\n  \"version\": \"1.1.5\",\n  \"publishedAt\": 1778964217703\n}\n\nFile v1.1.5:references/SETUP.md\n\n# tandoor-cli Setup Guide\n\nA command-line interface for [Tandoor Recipe Manager](https://tandoor.dev).\n\n---\n\n## Prerequisites\n\n- Node.js 18+\n- npm 8+\n- A running Tandoor instance (local or remote)\n\n---\n\n## Installation\n\n### Option 1: Install globally via npm\n\n```bash\nnpm install -g tandoor-cli\n```\n\nAfter the global install, the `tandoor` command becomes available system-wide.\n\n### Option 2: Run without installing\n\n```bash\nnpx tandoor-cli <command>\n```\n\nNo global install is required. `npx` downloads and runs the CLI on demand.\n\n**Note:** The rest of this documentation assumes a global install.\n\n---\n\n## Configuration\n\n`TANDOOR_URL` and at least one authentication method are required.\n\nThe CLI supports three configuration sources, applied in this order (highest priority first):\n\n1. Environment variables\n2. Persistent config file\n3. `.env` file\n\n### Option 1: Environment variables\n\n```bash\nexport TANDOOR_URL=http://localhost:8080\nexport TANDOOR_API_TOKEN=your_token_here\n```\n\nEnvironment variables take precedence over stored config and `.env` settings.\n\n### Option 2: `tandoor configure`\n\nRun the interactive setup command to save credentials to `~/.config/tandoor-cli/config.json`:\n\n```bash\n# without install\nnpx tandoor-cli configure\n\n# with global install\ntandoor configure\n```\n\nYou will be prompted for:\n- `TANDOOR_URL`\n- `TANDOOR_API_TOKEN`\n\nThe file is written with restricted permissions (0600) to protect your credentials.\n\n### Option 3: `.env` file\n\nCreate a `.env` file in your working directory:\n\n```dotenv\nTANDOOR_URL=http://localhost:8080\nTANDOOR_API_TOKEN=your_token_here\nTANDOOR_USERNAME=\nTANDOOR_PASSWORD=\n```\n\nThe CLI loads `.env` automatically when present.\n\n---\n\n## Authentication\n\n### API token (preferred)\n\nUse an OAuth2 access token with Bearer authentication. \n\n**Important:** The regular DRF token shown in Tandoor's Settings → API does **not** work for this CLI. You need an OAuth2 access token.\n\n**⚠️ Security Note:** Use the shortest token lifetime appropriate for your use case. For AI agent use, consider tokens that expire in days or weeks, not years.\n\n#### Generating an OAuth2 token\n\nIf you're running Tandoor in Docker, you can generate an OAuth2 token using the Django shell. Choose the appropriate example based on your needs:\n\n##### Read-Only Token (Safest)\n\nFor querying recipes only:\n\n```bash\ndocker exec <your-container-name> /opt/recipes/venv/bin/python /opt/recipes/manage.py shell -c \"\nfrom oauth2_provider.models import Application, AccessToken\nfrom django.contrib.auth.models import User\nfrom django.utils import timezone\nfrom datetime import timedelta\nimport secrets\n\nuser = User.objects.get(username='YOUR_USERNAME')\n\napp, _ = Application.objects.get_or_create(\n    name='tandoor-cli',\n    defaults=dict(\n        user=user,\n        client_type=Application.CLIENT_CONFIDENTIAL,\n        authorization_grant_type=Application.GRANT_PASSWORD,\n    )\n)\n\ntoken = AccessToken.objects.create(\n    user=user,\n    application=app,\n    token=secrets.token_hex(20),\n    expires=timezone.now() + timedelta(days=7),  # 7 days\n    scope='read',  # Read-only\n)\nprint('ACCESS TOKEN:', token.token)\n\"\n```\n\n##### Read-Write Token (Standard)\n\nFor recipe management (add, edit, delete recipes):\n\n```bash\ndocker exec <your-container-name> /opt/recipes/venv/bin/python /opt/recipes/manage.py shell -c \"\nfrom oauth2_provider.models import Application, AccessToken\nfrom django.contrib.auth.models import User\nfrom django.utils import timezone\nfrom datetime import timedelta\nimport secrets\n\nuser = User.objects.get(username='YOUR_USERNAME')\n\napp, _ = Application.objects.get_or_create(\n    name='tandoor-cli',\n    defaults=dict(\n        user=user,\n        client_type=Application.CLIENT_CONFIDENTIAL,\n        authorization_grant_type=Application.GRANT_PASSWORD,\n    )\n)\n\ntoken = AccessToken.objects.create(\n    user=user,\n    application=app,\n    token=secrets.token_hex(20),\n    expires=timezone.now() + timedelta(days=30),  # 30 days\n    scope='read write',\n)\nprint('ACCESS TOKEN:', token.token)\n\"\n```\n\nReplace `<your-container-name>` with the name of your running Tandoor Docker container and `YOUR_USERNAME` with your Tandoor username. Copy the printed token into `TANDOOR_API_TOKEN`.\n\n**Token Lifetime Recommendations:**\n- **AI agents / automation:** 7-30 days\n- **Personal CLI use:** 30-90 days\n- **Testing / development:** 1-7 days\n- **Administrative tasks:** 1 day (revoke after use)\n\n**Token Security Best Practices:**\n- Store tokens securely (environment variables, secret managers)\n- Never commit tokens to version control\n- Revoke tokens immediately if compromised\n- Rotate tokens regularly\n- Use read-only tokens when possible\n- See `SECURITY.md` for comprehensive security guidance\n\n### Username/password fallback\n\nIf `TANDOOR_API_TOKEN` is missing, the CLI falls back to HTTP Basic Authentication using `TANDOOR_USERNAME` and `TANDOOR_PASSWORD`.\n\n**Note:** This method is less secure and not recommended for production use.\n\n---\n\n## Verification\n\nTest your configuration:\n\n```bash\n# Check version\ntandoor --version\n\n# List recipes (requires valid credentials)\ntandoor list --limit 5\n```\n\nIf you see recipes listed, your configuration is working correctly!\n\n---\n\n## Troubleshooting\n\n### \"TANDOOR_URL is not set\"\n\nRun `tandoor configure` or set the `TANDOOR_URL` environment variable.\n\n### \"Authentication failed\" or 401 errors\n\n- Verify your `TANDOOR_API_TOKEN` is a valid OAuth2 token (not a DRF token)\n- Check that your token hasn't expired\n- Ensure your Tandoor instance is accessible at the configured URL\n\n### \"Permission denied\" or 403 errors\n\nSome commands (especially household management) require admin or space owner privileges. Check your user permissions in Tandoor.\n\n### Command not found\n\nIf `tandoor` command is not found after global install:\n- Verify npm's global bin directory is in your PATH\n- Try `npx tandoor-cli` instead\n- Reinstall: `npm install -g tandoor-cli`\n\n---\n\n## Next Steps\n\nFor command usage examples and full documentation, see the main [README](https://github.com/dcenatiempo/tandoor-cli#readme).\n\nFile v1.1.5:SECURITY_REVIEW_RESPONSE.md\n\n# Response to OlawHub Security Review\n\nThis document summarizes the changes made to address security concerns raised in the OlawHub skill review.\n\n## Review Date\nMay 4, 2026\n\n## Summary of Changes\n\nAll security concerns have been addressed through documentation updates, explicit approval gates, and security best practices guidance.\n\n---\n\n## 1. Tool Misuse and Exploitation (HIGH SEVERITY)\n\n### Original Concern\n> The skill exposes destructive, bulk, and account-administration operations to the agent, but the instructions do not add explicit approval gates or limits for these high-impact actions.\n\n### Resolution\n\n**Files Modified:**\n- `SKILL.md`\n- `references/SETUP.md`\n\n**Changes Made:**\n\n1. **Command Classification System**\n   - All commands now categorized by risk level:\n     - Read operations (safe, no approval)\n     - Write operations (require user confirmation)\n     - Destructive operations (require explicit confirmation)\n     - Administrative operations (require privileged token + explicit confirmation)\n\n2. **Explicit Approval Gates**\n   - Added \"Approval Required\" column to command tables\n   - Documented specific confirmation messages for each destructive operation\n   - Examples:\n     - `delete <id>`: \"This will permanently delete recipe X. Cannot be undone. Confirm?\"\n     - `shopping check --all`: \"This will mark ALL shopping items as checked. Confirm?\"\n     - `household users assign`: \"This will move user X to household Y. Confirm?\"\n\n3. **Agent Behavior Rules Section**\n   - Clear instructions on when to proceed vs. when to ask\n   - Explicit prohibition on using `--force` without user instruction\n   - Requirement to explain impact before destructive operations\n\n4. **Security Warning Banner**\n   - Added prominent warning at top of SKILL.md\n   - States: \"This skill provides mutation authority over your Tandoor instance\"\n   - Directs users to only install if they want agent mutation authority\n\n**User Impact:** Agents can no longer execute destructive operations without explicit user approval. Users maintain full control over high-impact actions.\n\n---\n\n## 2. Agentic Supply Chain Vulnerabilities (LOW SEVERITY)\n\n### Original Concern\n> The skill relies on an external npm package that is not included in the reviewed artifact set; npx may download and run package code on demand.\n\n### Resolution\n\n**Files Modified:**\n- `SKILL.md`\n- `SECURITY.md`\n\n**Changes Made:**\n\n1. **Version Awareness**\n   - Documentation acknowledges the npm package dependency\n   - Recommends version pinning for production use\n\n2. **Verification Links**\n   - Added direct links to npm package: https://www.npmjs.com/package/tandoor-cli\n   - Added direct link to source repository: https://github.com/dcenatiempo/tandoor-cli\n   - Included in \"Before first use\" checklist\n\n3. **Pre-Installation Checklist**\n   - Verify the npm package\n   - Review the source code\n   - Consider using a test instance first\n\n4. **Supply Chain Security Section**\n   - Added to SKILL.md under \"Security & Permission Model\"\n   - Recommends reviewing package before use with privileged credentials\n   - Suggests monitoring npm security advisories\n\n**User Impact:** Users can verify the package source and pin to known-good versions before granting access to their Tandoor instance.\n\n---\n\n## 3. Identity and Privilege Abuse - Space Owner Token (HIGH SEVERITY)\n\n### Original Concern\n> The skill directs use of a highly privileged Tandoor identity for household invite management, which is broader than ordinary recipe and shopping-list management.\n\n### Resolution\n\n**Files Modified:**\n- `SKILL.md`\n- `SECURITY.md`\n- `references/SETUP.md`\n\n**Changes Made:**\n\n1. **Least Privilege Principle**\n   - Added \"Token Security\" section emphasizing least-privileged tokens\n   - Guidance on token scoping:\n     - Read-only tokens for queries\n     - Standard user tokens for recipe management\n     - Admin tokens only for household management\n     - Space-owner tokens only for invite creation\n\n2. **Command-Level Permission Documentation**\n   - Each administrative command now states required permission level\n   - Example: \"household invite create\" explicitly states \"Space-owner token + explicit confirmation\"\n\n3. **Permission Error Guidance**\n   - Users directed to contact administrators if lacking permissions\n   - Clear explanation that 403 errors indicate insufficient privileges\n\n4. **Token Scoping Examples**\n   - SECURITY.md provides three token configuration examples:\n     - Read-only (safest)\n     - Recipe management (standard)\n     - Administrative tasks (restricted)\n\n**User Impact:** Users can create appropriately scoped tokens for their use case, avoiding over-privileged access.\n\n---\n\n## 4. Identity and Privilege Abuse - Long-Lived Tokens (MEDIUM SEVERITY)\n\n### Original Concern\n> The setup guide demonstrates creating a long-lived read/write OAuth2 access token, which would let the CLI perform both read and mutation operations for up to a year if not revoked.\n\n### Resolution\n\n**Files Modified:**\n- `references/SETUP.md`\n- `SECURITY.md`\n\n**Changes Made:**\n\n1. **Token Lifetime Recommendations**\n   - Changed default example from 365 days (1 year) to 7-30 days\n   - Added \"Token Lifetime Recommendations\" section:\n     - AI agents / automation: 7-30 days\n     - Personal CLI use: 30-90 days\n     - Testing / development: 1-7 days\n     - Administrative tasks: 1 day (revoke after use)\n\n2. **Multiple Token Examples**\n   - SETUP.md now provides separate examples for:\n     - Read-only token (7 days, `scope='read'`)\n     - Read-write token (30 days, `scope='read write'`)\n   - Users choose appropriate example for their use case\n\n3. **Token Security Best Practices**\n   - Store tokens securely (environment variables, secret managers)\n   - Never commit tokens to version control\n   - Revoke tokens immediately if compromised\n   - Rotate tokens regularly\n   - Use read-only tokens when possible\n\n4. **Token Management Commands**\n   - SECURITY.md includes commands to:\n     - List active tokens\n     - Revoke unused tokens\n     - Audit token usage\n\n**User Impact:** Users create shorter-lived tokens appropriate for their use case, reducing exposure window if tokens are compromised.\n\n---\n\n## New Documentation\n\n### SECURITY.md (New File)\n\nComprehensive security documentation covering:\n\n1. **Overview of Security Model**\n2. **Detailed Mitigation for Each Concern**\n3. **Recommended Token Configurations**\n   - Read-only, standard, and administrative examples\n4. **Token Storage Best Practices**\n   - Secure vs. insecure methods\n5. **Monitoring and Auditing**\n   - Commands to list and revoke tokens\n   - Incident response procedures\n6. **Agent-Specific Security**\n   - Guidance for AI agent users\n   - Agent behavior validation tests\n7. **Compliance and Governance**\n   - Organizational policies\n   - Personal use guidelines\n8. **Reporting Security Issues**\n\n---\n\n## Testing Recommendations\n\nTo verify the security improvements:\n\n### 1. Test Agent Approval Gates\n\n```bash\n# Should prompt for confirmation, not execute immediately:\n\"Delete recipe 42\"\n\"Clear all shopping items\"\n\"Create a new household\"\n\n# Should proceed without confirmation:\n\"List all recipes\"\n\"Search for pasta recipes\"\n```\n\n### 2. Test Token Scoping\n\n```bash\n# Create a read-only token and verify write operations fail:\nexport TANDOOR_API_TOKEN=<read-only-token>\ntandoor list  # Should work\ntandoor add --json recipe.json  # Should fail with 403\n```\n\n### 3. Test Version Awareness\n\n```bash\n# Verify the CLI version:\ntandoor --version\n```\n\n---\n\n## Compliance Summary\n\n| Concern | Severity | Status | Mitigation |\n|---------|----------|--------|------------|\n| Tool Misuse and Exploitation | HIGH | ✅ Resolved | Explicit approval gates, command classification, agent behavior rules |\n| Agentic Supply Chain | LOW | ✅ Resolved | Verification links, pre-installation checklist, version awareness |\n| Space Owner Token Privilege | HIGH | ✅ Resolved | Least privilege guidance, token scoping examples, permission documentation |\n| Long-Lived Tokens | MEDIUM | ✅ Resolved | Shorter default lifetimes, token rotation guidance, security best practices |\n\n---\n\n## Recommendations for Users\n\n### Before Installation\n\n1. ✅ Read `SECURITY.md` to understand the security model\n2. ✅ Verify the npm package at https://www.npmjs.com/package/tandoor-cli\n3. ✅ Review the source code at https://github.com/dcenatiempo/tandoor-cli\n4. ✅ Decide what level of access you want to grant the agent\n\n### During Setup\n\n1. ✅ Create a token with the minimum required permissions\n2. ✅ Use short token lifetimes (7-30 days for agents)\n3. ✅ Store tokens securely (environment variables, secret managers)\n4. ✅ Test with a non-production Tandoor instance first\n\n### After Installation\n\n1. ✅ Monitor agent behavior for unexpected commands\n2. ✅ Verify agents request approval for destructive operations\n3. ✅ Rotate tokens regularly\n4. ✅ Revoke tokens immediately if compromised\n\n---\n\n## Contact\n\nFor questions about these security improvements:\n- Open an issue in the repository\n- Tag issues with `[SECURITY]` for priority handling\n\nFor security vulnerabilities:\n- Report privately via GitHub Security Advisories\n- Do not disclose publicly until patched\n\n---\n\n## Version History\n\n- **v0.4.0** (May 2026): Security improvements addressing OlawHub review\n- **v0.3.0** (Earlier): Initial skill release\n\nFile v1.1.5:SECURITY.md\n\n# Security Guidelines for Tandoor CLI Skill\n\nThis document addresses security concerns and best practices for using the tandoor-cli skill with AI agents.\n\n## Overview\n\nThe tandoor-cli skill provides programmatic access to your Tandoor Recipe Manager instance. Like any tool with write access to your data, it requires careful configuration and usage to maintain security.\n\n## Addressed Security Concerns\n\n### 1. Tool Misuse and Exploitation (HIGH SEVERITY)\n\n**Concern:** The skill exposes destructive, bulk, and account-administration operations without explicit approval gates.\n\n**Mitigation:**\n- **Command Classification:** All commands are now classified by risk level (read, write, destructive, administrative)\n- **Approval Gates:** The SKILL.md explicitly requires user confirmation before:\n  - Any write operation (add, update, import)\n  - Any destructive operation (delete, clear, bulk operations)\n  - Any administrative operation (household management, user assignment)\n- **Agent Behavior Rules:** Clear instructions prevent agents from executing high-risk commands without explicit user approval\n- **No Automatic --force:** Agents are forbidden from using `--force` flags without explicit user instruction\n\n**User Action Required:**\n- Review the command classification table in SKILL.md\n- Only install this skill if you want the agent to have mutation authority\n- Monitor agent behavior and revoke access if misuse is detected\n\n### 2. Agentic Supply Chain Vulnerabilities (LOW SEVERITY)\n\n**Concern:** The skill relies on an external npm package that could be compromised.\n\n**Mitigation:**\n- **Version Pinning:** The skill explicitly uses `npx tandoor-cli@0.3.1` to pin to a known version\n- **Verification Links:** SKILL.md provides direct links to:\n  - npm package: https://www.npmjs.com/package/tandoor-cli\n  - Source repository: https://github.com/dcenatiempo/tandoor-cli\n- **Pre-Installation Checklist:** Users are instructed to verify the package before first use\n- **No Auto-Updates:** Using `@version` syntax prevents automatic updates to potentially compromised versions\n\n**User Action Required:**\n- Verify the npm package and repository before first installation\n- Review the package source code if using privileged credentials\n- Monitor npm security advisories for the tandoor-cli package\n- Update to newer versions only after reviewing changelogs\n\n### 3. Identity and Privilege Abuse - Space Owner Token (HIGH SEVERITY)\n\n**Concern:** The skill directs use of a highly privileged space-owner token for household invite management.\n\n**Mitigation:**\n- **Least Privilege Principle:** SKILL.md now emphasizes using the least-privileged token possible\n- **Token Scoping Guidance:**\n  - Read-only tokens for query operations\n  - Standard user tokens for recipe management\n  - Admin tokens only when household management is required\n  - Space-owner tokens only for invite link creation\n- **Explicit Warnings:** Administrative commands clearly state they require privileged tokens\n- **Permission Errors:** Users are directed to contact administrators if they lack necessary permissions\n\n**User Action Required:**\n- Create separate tokens for different use cases\n- Use read-only tokens when possible\n- Avoid providing space-owner tokens unless invite management is truly needed\n- Revoke privileged tokens immediately after administrative tasks\n\n### 4. Identity and Privilege Abuse - Long-Lived Tokens (MEDIUM SEVERITY)\n\n**Concern:** The setup guide demonstrates creating long-lived (10-year) read/write OAuth2 tokens.\n\n**Mitigation:**\n- **Token Lifetime Guidance:** SKILL.md now recommends short-lived tokens (days/weeks) instead of long-lived tokens (years)\n- **Security Best Practices Section:** Added explicit guidance on:\n  - Token rotation schedules\n  - Secure token storage\n  - Immediate revocation if compromised\n  - Regular token audits\n- **Alternative Approaches:** Users are encouraged to:\n  - Generate tokens on-demand for specific tasks\n  - Revoke tokens after use\n  - Use environment-specific tokens (dev vs. production)\n\n**User Action Required:**\n- Modify the token generation command to use shorter expiry periods:\n  ```python\n  expires=timezone.now() + timedelta(days=7)  # 7 days instead of 3650\n  ```\n- Implement a token rotation schedule\n- Store tokens securely (environment variables, secret managers, not in code)\n- Revoke unused tokens regularly\n\n## Recommended Token Configuration\n\n### For Read-Only Use (Safest)\n\nIf you only need to query recipes, create a read-only token:\n\n```python\ntoken = AccessToken.objects.create(\n    user=user,\n    application=app,\n    token=secrets.token_hex(20),\n    expires=timezone.now() + timedelta(days=7),  # 7 days\n    scope='read',  # Read-only\n)\n```\n\n### For Recipe Management (Standard)\n\nFor adding/editing recipes but not administrative tasks:\n\n```python\ntoken = AccessToken.objects.create(\n    user=user,\n    application=app,\n    token=secrets.token_hex(20),\n    expires=timezone.now() + timedelta(days=30),  # 30 days\n    scope='read write',\n)\n```\n\nUse a standard user account (not admin/staff).\n\n### For Administrative Tasks (Restricted)\n\nOnly when household management is required:\n\n```python\ntoken = AccessToken.objects.create(\n    user=admin_user,  # Must be admin/staff\n    application=app,\n    token=secrets.token_hex(20),\n    expires=timezone.now() + timedelta(days=1),  # 1 day\n    scope='read write',\n)\n```\n\nRevoke immediately after completing administrative tasks.\n\n## Token Storage Best Practices\n\n### ✅ Secure Methods\n\n- **Environment variables:** `export TANDOOR_API_TOKEN=...` (session-only)\n- **Secret managers:** AWS Secrets Manager, HashiCorp Vault, 1Password CLI\n- **Encrypted config files:** `~/.config/tandoor-cli/config.json` with `0600` permissions\n- **CI/CD secrets:** GitHub Secrets, GitLab CI/CD variables\n\n### ❌ Insecure Methods\n\n- **Plain text in code:** Never commit tokens to version control\n- **Shared config files:** Avoid world-readable files\n- **Chat logs:** Don't paste tokens in Slack, Discord, etc.\n- **Browser history:** Be careful with tokens in URLs\n\n## Monitoring and Auditing\n\n### Regular Security Checks\n\n1. **List active tokens:**\n   ```python\n   docker exec <container> /opt/recipes/venv/bin/python /opt/recipes/manage.py shell -c \"\n   from oauth2_provider.models import AccessToken\n   from django.utils import timezone\n   \n   active = AccessToken.objects.filter(expires__gt=timezone.now())\n   for token in active:\n       print(f'{token.user.username}: {token.scope} (expires {token.expires})')\n   \"\n   ```\n\n2. **Revoke unused tokens:**\n   ```python\n   docker exec <container> /opt/recipes/venv/bin/python /opt/recipes/manage.py shell -c \"\n   from oauth2_provider.models import AccessToken\n   \n   # Revoke all tokens for tandoor-cli app\n   AccessToken.objects.filter(application__name='tandoor-cli').delete()\n   \"\n   ```\n\n3. **Review Tandoor audit logs:** Check for unexpected API activity\n\n### Incident Response\n\nIf a token is compromised:\n\n1. **Immediately revoke the token** using the command above\n2. **Review recent API activity** in Tandoor logs\n3. **Generate a new token** with a different value\n4. **Update all systems** using the old token\n5. **Investigate** how the token was exposed\n\n## Agent-Specific Security\n\n### For AI Agent Users\n\nWhen using this skill with AI agents (Kiro, Claude, etc.):\n\n1. **Start with read-only tokens** to test agent behavior\n2. **Monitor agent commands** before granting write access\n3. **Use approval hooks** to review destructive operations\n4. **Limit token scope** to the minimum required for the task\n5. **Revoke tokens** when the agent task is complete\n\n### Agent Behavior Validation\n\nTest that your agent follows the security rules:\n\n```bash\n# This should prompt for confirmation, not execute immediately\n\"Delete recipe 42\"\n\n# This should refuse without explicit user approval\n\"Clear all shopping items\"\n\n# This should warn about privilege requirements\n\"Create a new household\"\n```\n\nIf your agent executes these without confirmation, the skill is not being used correctly.\n\n## Compliance and Governance\n\n### For Organizations\n\nIf deploying this skill in a team or organization:\n\n- **Access Control:** Limit who can generate API tokens\n- **Token Policies:** Enforce maximum token lifetimes\n- **Audit Logging:** Enable and monitor Tandoor API logs\n- **Incident Response:** Have a plan for token compromise\n- **Training:** Ensure users understand the security model\n\n### For Personal Use\n\nEven for personal Tandoor instances:\n\n- **Principle of Least Privilege:** Use the minimum permissions needed\n- **Defense in Depth:** Don't rely solely on token security\n- **Regular Reviews:** Audit tokens and agent behavior periodically\n- **Backup Strategy:** Maintain backups in case of accidental deletion\n\n## Reporting Security Issues\n\nIf you discover a security vulnerability in:\n\n- **tandoor-cli package:** Report to https://github.com/dcenatiempo/tandoor-cli/security\n- **Tandoor Recipe Manager:** Report to https://github.com/TandoorRecipes/recipes/security\n- **This skill:** Open an issue at your repository with `[SECURITY]` prefix\n\nDo not disclose security vulnerabilities publicly until they are patched.\n\n## Version History\n\n- **v0.4.0** (May 2026): Added comprehensive security documentation and approval gates\n- **v0.3.0** (Earlier): Initial skill release\n\n## Additional Resources\n\n- [Tandoor Security Documentation](https://docs.tandoor.dev/security/)\n- [OAuth2 Best Practices](https://oauth.net/2/oauth-best-practice/)\n- [OWASP API Security Top 10](https://owasp.org/www-project-api-security/)\n- [Agent Skills Security Guidelines](https://agentskills.io/security)\n\nArchive v1.1.4: 5 files, 15726 bytes\n\nFiles: references/SETUP.md (6080b), SECURITY_REVIEW_RESPONSE.md (9354b), SECURITY.md (9632b), SKILL.md (15245b), _meta.json (130b)\n\nFile v1.1.4:SKILL.md\n\n---\nname: tandoor-recipe-cli\ndescription: Manage recipes, meal plans, and shopping lists on a Tandoor Recipe Manager instance via CLI.\nversion: 1.1.4\ncompatibility: \">=18\"\nlicense: MIT\nmetadata:\n  author: dcenatiempo\n  repository: https://github.com/dcenatiempo/tandoor-cli\n---\n\n## Tandoor CLI Skill\n\nThis skill provides AI agents with the ability to interact with a Tandoor Recipe Manager instance using the `tandoor-cli` command-line tool.\n\n### Prerequisites\n\nThe `tandoor-cli` tool must be installed and configured.\n\n**Version Compatibility:** This skill documentation corresponds to the version specified in the metadata above. Before using this skill:\n1. Verify your installed CLI version: `tandoor -V`\n2. Ensure the installed version matches the skill version to avoid unexpected behavior or missing commands\n3. If versions don't match, reinstall the CLI tool following the setup instructions in `references/SETUP.md`\n\nIf `tandoor -V` produces no valid version, see the setup instructions in `references/SETUP.md`.\n\n### Security & Permission Model\n\n**⚠️ IMPORTANT: This skill provides mutation authority over your Tandoor instance.**\n\n- **Read operations** (list, search, get, random) are safe and require no confirmation\n- **Write operations** (add, update, import) modify data but are typically reversible\n- **Destructive operations** (delete, clear, household management) require explicit user approval before execution\n- **Bulk operations** (shopping check --all, clear) affect multiple items and require confirmation\n- **Administrative operations** (household management, user assignment, invite creation) require privileged credentials and explicit approval\n\n**Token Security:**\n- Use the **least-privileged token** possible for your use case\n- Prefer read-only tokens if you only need to query recipes\n- Avoid using space-owner or admin tokens unless household management is required\n- Consider short-lived tokens (days/weeks) instead of long-lived tokens (years)\n- Store tokens securely and rotate them regularly\n- Revoke tokens immediately if compromised or no longer needed\n\n**Supply Chain:**\n- This skill uses the `tandoor-cli` npm package\n- Verify the package source before first use: https://www.npmjs.com/package/tandoor-cli\n- Review the package repository: https://github.com/dcenatiempo/tandoor-cli\n- **Recommended:** Pin to the specific version matching this skill (see version in metadata above) to avoid unexpected updates\n- Install pinned version: `npm install -g tandoor-cli@<version>` (replace `<version>` with the skill version)\n\n### Invocation\n\n```bash\ntandoor <command> [options]\n```\n\n### Commands\n\n#### Read Operations (Safe)\n\n**Recipes:**\n| Command | Description |\n|---|---|\n| `list [--limit N] [--page N] [--all]` | List recipes (default 20 per page, max 100) |\n| `search <query>` | Search recipes by keyword |\n| `get <id>` | Get full recipe details |\n| `random` | Get a random recipe |\n\n**Meal Plans:**\n| Command | Description |\n|---|---|\n| `mealplan list [--startdate DATE] [--enddate DATE]` | List meal plan entries (optionally filtered by date range) |\n\n**Shopping List:**\n| Command | Description |\n|---|---|\n| `shopping list` | List shopping list entries |\n\n**Food Ingredients:**\n| Command | Description |\n|---|---|\n| `food list [--limit N] [--page N] [--all] [--search TERM] [--ignored] [--onhand]` | List food ingredients |\n\n**Cook Logs:**\n| Command | Description |\n|---|---|\n| `cooklog list [--recipe ID] [--limit N] [--page N] [--all] [--startdate YYYY-MM-DD] [--enddate YYYY-MM-DD] [--min-rating 1-5] [--max-rating 1-5]` | List cook log entries (sorted by most recent first) |\n| `cooklog ingredient <name> [--limit N] [--startdate YYYY-MM-DD] [--enddate YYYY-MM-DD] [--min-rating 1-5] [--max-rating 1-5]` | Find cook logs by ingredient name (e.g., \"when did we last have eggs?\") |\n\n**Households & Users:**\n| Command | Description |\n|---|---|\n| `household list` | List all households |\n| `household get <id>` | Get household details by ID |\n| `household users list` | List all users in the space |\n| `household users memberships` | List user-space memberships |\n| `household invite list` | List all invite links |\n\n#### Write Operations (Require Confirmation)\n\n| Command | Description | Approval Required |\n|---|---|---|\n| `add [--json file]` | Create a recipe | ✓ Before execution |\n| `update <id> --json file` | Patch an existing recipe | ✓ Before execution |\n| `import <url> [--dry-run]` | Import a recipe from a URL | ✓ Before execution |\n| `image <recipeId> <imagePath>` | Upload an image to a recipe | ✓ Before execution |\n| `mealplan add --recipe ID --date YYYY-MM-DD --meal-type N` | Add a meal plan entry | ✓ Before execution |\n| `shopping add --food NAME --amount N --unit UNIT` | Add a shopping list item | ✓ Before execution |\n| `shopping check <id>` | Mark a shopping item as checked | ✓ Before execution |\n| `food edit <id\\|name> --ignore-shopping <true\\|false>` | Edit a food's ignore_shopping flag | ✓ Before execution |\n| `food ignore <id\\|name> [--unset]` | Set or clear ignore_shopping by ID or name | ✓ Before execution |\n| `food onhand <id\\|name> [--unset]` | Set or clear the on-hand flag by ID or name | ✓ Before execution |\n| `cooklog add --recipe ID --servings N [--rating 1-5] [--date ISO8601]` | Add a cook log entry | ✓ Before execution |\n| `cooklog update <id> --recipe ID --servings N [--rating 1-5] [--date ISO8601]` | Update a cook log entry | ✓ Before execution |\n\n#### Destructive Operations (Require Explicit Confirmation)\n\n| Command | Description | Approval Required |\n|---|---|---|\n| `delete <id> [--force]` | Delete a recipe | ✓✓ Explicit confirmation required |\n| `mealplan delete <id>` | Delete a meal plan entry | ✓✓ Explicit confirmation required |\n| `shopping clear [--force]` | Clear all checked items | ✓✓ Explicit confirmation (bulk operation) |\n| `shopping check --all` | Mark all items as checked | ✓✓ Explicit confirmation (bulk operation) |\n| `cooklog delete <id>` | Delete a cook log entry | ✓✓ Explicit confirmation required |\n\n#### Administrative Operations (Require Privileged Token + Explicit Confirmation)\n\n**Important:** Tandoor uses **households** to organize users and recipes. Users are added to households via **invite links** — you cannot create users directly via the API.\n\n> **Permission Requirements:** Household management commands require special permissions in Tandoor. Most operations need admin/staff privileges. The `household invite create` command specifically requires **space owner** authentication — even superusers or staff members will receive a 403 Permission Denied error if they're not the space owner. If you encounter permission errors, you must use the space owner's API token or contact your Tandoor administrator.\n\n| Command | Description | Approval Required |\n|---|---|---|\n| `household add <name>` | Create a new household | ✓✓ Admin token + explicit confirmation |\n| `household edit <id> --name <name>` | Rename a household | ✓✓ Admin token + explicit confirmation |\n| `household delete <id> [--force]` | Delete a household | ✓✓ Admin token + explicit confirmation |\n| `household users assign <user-space-id> <household-id>` | Assign user to household | ✓✓ Admin token + explicit confirmation |\n| `household invite create <household-id> [--email EMAIL] [--expires DATE] [--group-id ID]` | Create invite link | ✓✓ Space-owner token + explicit confirmation |\n| `household invite delete <id> [--force]` | Delete invite link | ✓✓ Admin token + explicit confirmation |\n\nAll read commands accept `--json` for machine-readable output suitable for agent pipelines.\n\n### Agent Behavior Rules\n\n**Before executing any command, the agent MUST:**\n\n1. **For read operations:** Proceed without confirmation\n2. **For write operations:** Describe the action and wait for user approval\n3. **For destructive operations:** \n   - Clearly explain what will be deleted/modified\n   - Warn that the action cannot be easily reversed\n   - Wait for explicit user confirmation (e.g., \"yes, delete recipe 42\")\n4. **For bulk operations:**\n   - State how many items will be affected\n   - Wait for explicit confirmation\n5. **For administrative operations:**\n   - Verify the user has provided an admin/space-owner token\n   - Explain the scope of the change (e.g., \"this will move user X to household Y\")\n   - Wait for explicit confirmation\n\n**The agent MUST NOT:**\n- Execute delete, force, bulk, household, invite, or user-assignment commands without explicit user approval\n- Assume the user wants destructive actions even if implied by context\n- Use `--force` flags without explicit user instruction\n- Log or display the `TANDOOR_API_TOKEN` value in any output\n\n### Configuration\n\nThe CLI supports three configuration methods (in precedence order):\n\n1. **Environment variables** — `TANDOOR_URL` and `TANDOOR_API_TOKEN` in the current shell\n2. **Config file** — `~/.config/tandoor-cli/config.json` (created by `tandoor configure`)\n3. **`.env` file** — a `.env` file in the current working directory\n\nRun `tandoor configure` once to save credentials interactively.\n\n### Examples\n\n**Configure credentials:**\n```bash\ntandoor configure\n```\n\n**Read example — list recipes as JSON:**\n```bash\ntandoor list --limit 5 --json\n```\n\n**Write example — create a recipe from a JSON file:**\n```bash\n# Agent should first ask: \"I will create a new recipe from recipe.json. Proceed?\"\n# Only after user confirms:\ntandoor add --json recipe.json\n```\n\n### Recipe JSON Schema\n\nWhen creating recipes with `tandoor add --json <file>`, the JSON file must conform to the following structure:\n\n**TypeScript Definition:**\n```typescript\ninterface RecipeCreatePayload {\n  name: string;                    // Required: Recipe name\n  description?: string;            // Optional: Recipe description\n  servings?: number;               // Optional: Number of servings\n  working_time?: number;           // Optional: Active cooking time in minutes\n  waiting_time?: number;           // Optional: Passive time (baking, marinating) in minutes\n  steps: StepCreatePayload[];      // Required: At least one step\n}\n\ninterface StepCreatePayload {\n  instruction: string;             // Required: Step instructions\n  order: number;                   // Required: Step order (1, 2, 3, ...)\n  ingredients: Ingredient\n\nArchive v1.1.3: 5 files, 15705 bytes\n\nFiles: references/SETUP.md (6080b), SECURITY_REVIEW_RESPONSE.md (9354b), SECURITY.md (9632b), SKILL.md (15168b), _meta.json (130b)\n\nArchive v1.1.2: 5 files, 15704 bytes\n\nFiles: references/SETUP.md (6080b), SECURITY_REVIEW_RESPONSE.md (9354b), SECURITY.md (9632b), SKILL.md (15168b), _meta.json (130b)\n\nArchive v1.1.1: 5 files, 14761 bytes\n\nFiles: references/SETUP.md (6080b), SECURITY_REVIEW_RESPONSE.md (9354b), SECURITY.md (9632b), SKILL.md (12404b), _meta.json (130b)\n\nArchive v1.0.2: 5 files, 14340 bytes\n\nFiles: references/SETUP.md (6080b), SECURITY_REVIEW_RESPONSE.md (9354b), SECURITY.md (9632b), SKILL.md (10637b), _meta.json (130b)\n\nArchive v1.0.1: 5 files, 14258 bytes\n\nFiles: references/SETUP.md (6080b), SECURITY_REVIEW_RESPONSE.md (9354b), SECURITY.md (9632b), SKILL.md (10330b), _meta.json (130b)\n\nArchive v0.3.1: 3 files, 4549 bytes\n\nFiles: references/SETUP.md (4512b), SKILL.md (5055b), _meta.json (130b)","readmeExcerpt":"Skill: Tandoor Recipe CLI Owner: dcenatiempo Summary: Manage recipes, meal plans, and shopping lists on a Tandoor Recipe Manager instance via CLI. Tags: latest:1.5.0 Version history: v1.5.0 | 2026-05-18T18:59:16.604Z | user v1.5.0 - Adds --comment TEXT to cooklog add and cooklog update commands for entering comments on cook logs. - cooklog update now allows updating individual fields without requiring all parameters,","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"tandoor <command> [options]"},{"language":"bash","snippet":"tandoor configure"},{"language":"bash","snippet":"tandoor list --limit 5 --format api"},{"language":"bash","snippet":"tandoor get 42 --format json"},{"language":"bash","snippet":"# Agent should first ask: \"I will create a new recipe from recipe.json. Proceed?\"\n# Only after user confirms:\ntandoor add --file recipe.json"},{"language":"typescript","snippet":"interface RecipeCreatePayload {\n  name: string;                    // Required: Recipe name\n  description?: string;            // Optional: Recipe description\n  servings?: number;               // Optional: Number of servings\n  working_time?: number;           // Optional: Active cooking time in minutes\n  waiting_time?: number;           // Optional: Passive time (baking, marinating) in minutes\n  steps: StepCreatePayload[];      // Required: At least one step\n}\n\ninterface StepCreatePayload {\n  instruction: string;             // Required: Step instructions\n  order: number;                   // Required: Step order (1, 2, 3, ...)\n  ingredients: IngredientCreatePayload[];  // Required: Can be empty array\n}\n\ninterface IngredientCreatePayload {\n  food: { name: string };          // Required: Ingredient name\n  unit: { name: string } | null;   // Optional: Unit of measurement (null if not applicable)\n  amount: number;                  // Required: Quantity\n  note?: string;                   // Optional: Additional notes (e.g., \"finely chopped\")\n  order?: number | null;           // Optional: Order within the step\n}"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: tandoor-recipe-cli\ndescription: Manage recipes, meal plans, and shopping lists on a Tandoor Recipe Manager instance via CLI.\nversion: 1.5.0\ncompatibility: \">=18\"\nlicense: MIT\nmetadata:\n  author: dcenatiempo\n  repository: https://github.com/dcenatiempo/tandoor-cli\n---\n\n## Tandoor CLI Skill\n\nThis skill provides AI agents with the ability to interact with a Tandoor Recipe Manager instance using the `tandoor-cli` command-line tool.\n\n### Prerequisites\n\nThe `tandoor-cli` tool must be installed and configured.\n\n**Version Compatibility:** This skill documentation corresponds to the version specified in the metadata above. Before using this skill:\n1. Verify your installed CLI version: `tandoor -V`\n2. Ensure the installed version matches the skill version to avoid unexpected behavior or missing commands\n3. If versions don't match, reinstall the CLI tool following the setup instructions in `references/SETUP.md`\n\nIf `tandoor -V` produces no valid version, see the setup instructions in `references/SETUP.md`.\n\n### Security & Permission Model\n\n**⚠️ IMPORTANT: This skill provides mutation authority over your Tandoor instance.**\n\n- **Read operations** (list, search, get, random) are safe and require no confirmation\n- **Write operations** (add, update, import) modify data but are typically reversible\n- **Destructive operations** (delete, clear, household management) require explicit user approval before execution\n- **Bulk operations** (shopping check --all, clear) affect multiple items and require confirmation\n- **Administrative operations** (household management, user assignment, invite creation) require privileged credentials and explicit approval\n\n**Token Security:**\n- Use the **least-privileged token** possible for your use case\n- Prefer read-only tokens if you only need to query recipes\n- Avoid using space-owner or admin tokens unless household management is required\n- Consider short-lived tokens (days/weeks) instead of long-lived tokens (years)\n- Store tokens securely and rotate them regularly\n- Revoke tokens immediately if compromised or no longer needed\n\n**Supply Chain:**\n- This skill uses the `tandoor-cli` npm package\n- Verify the package source before first use: https://www.npmjs.com/package/tandoor-cli\n- Review the package repository: https://github.com/dcenatiempo/tandoor-cli\n- **Recommended:** Pin to the specific version matching this skill (see version in metadata above) to avoid unexpected updates\n- Install pinned version: `npm install -g tandoor-cli@<version>` (replace `<version>` with the skill version)\n\n### Invocation\n\n```bash\ntandoor <command> [options]\n```\n\n### Output formats and deprecated flags\n\nCommands that print data accept **`--format text|json|api`** (default: `text`):\n\n| `--format` | Use for |\n|------------|---------|\n| `text` | Human-readable output (default) |\n| `json` | Slim JSON where supported (recipe add/update shape + `id` on `get`, `list`, `search`, `random`) |\n| `api` | Raw Tandoor API JSON |\n\n**Deprecated (output):**"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7d75mc2rzjgptnfjg8382my9864gnx\",\n  \"slug\": \"tandoor-cli\",\n  \"version\": \"1.5.0\",\n  \"publishedAt\": 1779130756604\n}"},{"path":"references/SETUP.md","content":"# tandoor-cli Setup Guide\n\nA command-line interface for [Tandoor Recipe Manager](https://tandoor.dev).\n\n---\n\n## Prerequisites\n\n- Node.js 18+\n- npm 8+\n- A running Tandoor instance (local or remote)\n\n---\n\n## Installation\n\n### Option 1: Install globally via npm\n\n```bash\nnpm install -g tandoor-cli\n```\n\nAfter the global install, the `tandoor` command becomes available system-wide.\n\n### Option 2: Run without installing\n\n```bash\nnpx tandoor-cli <command>\n```\n\nNo global install is required. `npx` downloads and runs the CLI on demand.\n\n**Note:** The rest of this documentation assumes a global install.\n\n---\n\n## Configuration\n\n`TANDOOR_URL` and at least one authentication method are required.\n\nThe CLI supports three configuration sources, applied in this order (highest priority first):\n\n1. Environment variables\n2. Persistent config file\n3. `.env` file\n\n### Option 1: Environment variables\n\n```bash\nexport TANDOOR_URL=http://localhost:8080\nexport TANDOOR_API_TOKEN=your_token_here\n```\n\nEnvironment variables take precedence over stored config and `.env` settings.\n\n### Option 2: `tandoor configure`\n\nRun the interactive setup command to save credentials to `~/.config/tandoor-cli/config.json`:\n\n```bash\n# without install\nnpx tandoor-cli configure\n\n# with global install\ntandoor configure\n```\n\nYou will be prompted for:\n- `TANDOOR_URL`\n- `TANDOOR_API_TOKEN`\n\nThe file is written with restricted permissions (0600) to protect your credentials.\n\n### Option 3: `.env` file\n\nCreate a `.env` file in your working directory:\n\n```dotenv\nTANDOOR_URL=http://localhost:8080\nTANDOOR_API_TOKEN=your_token_here\nTANDOOR_USERNAME=\nTANDOOR_PASSWORD=\n```\n\nThe CLI loads `.env` automatically when present.\n\n---\n\n## Authentication\n\n### API token (preferred)\n\nUse an OAuth2 access token with Bearer authentication. \n\n**Important:** The regular DRF token shown in Tandoor's Settings → API does **not** work for this CLI. You need an OAuth2 access token.\n\n**⚠️ Security Note:** Use the shortest token lifetime appropriate for your use case. For AI agent use, consider tokens that expire in days or weeks, not years.\n\n#### Generating an OAuth2 token\n\nIf you're running Tandoor in Docker, you can generate an OAuth2 token using the Django shell. Choose the appropriate example based on your needs:\n\n##### Read-Only Token (Safest)\n\nFor querying recipes only:\n\n```bash\ndocker exec <your-container-name> /opt/recipes/venv/bin/python /opt/recipes/manage.py shell -c \"\nfrom oauth2_provider.models import Application, AccessToken\nfrom django.contrib.auth.models import User\nfrom django.utils import timezone\nfrom datetime import timedelta\nimport secrets\n\nuser = User.objects.get(username='YOUR_USERNAME')\n\napp, _ = Application.objects.get_or_create(\n    name='tandoor-cli',\n    defaults=dict(\n        user=user,\n        client_type=Application.CLIENT_CONFIDENTIAL,\n        authorization_grant_type=Application.GRANT_PASSWORD,\n    )\n)\n\ntoken = AccessToken.objects.create(\n    user=user,\n    application=app,\n    token=secrets.token_"},{"path":"SECURITY_REVIEW_RESPONSE.md","content":"# Response to OlawHub Security Review\n\nThis document summarizes the changes made to address security concerns raised in the OlawHub skill review.\n\n## Review Date\nMay 4, 2026\n\n## Summary of Changes\n\nAll security concerns have been addressed through documentation updates, explicit approval gates, and security best practices guidance.\n\n---\n\n## 1. Tool Misuse and Exploitation (HIGH SEVERITY)\n\n### Original Concern\n> The skill exposes destructive, bulk, and account-administration operations to the agent, but the instructions do not add explicit approval gates or limits for these high-impact actions.\n\n### Resolution\n\n**Files Modified:**\n- `SKILL.md`\n- `references/SETUP.md`\n\n**Changes Made:**\n\n1. **Command Classification System**\n   - All commands now categorized by risk level:\n     - Read operations (safe, no approval)\n     - Write operations (require user confirmation)\n     - Destructive operations (require explicit confirmation)\n     - Administrative operations (require privileged token + explicit confirmation)\n\n2. **Explicit Approval Gates**\n   - Added \"Approval Required\" column to command tables\n   - Documented specific confirmation messages for each destructive operation\n   - Examples:\n     - `delete <id>`: \"This will permanently delete recipe X. Cannot be undone. Confirm?\"\n     - `shopping check --all`: \"This will mark ALL shopping items as checked. Confirm?\"\n     - `household users assign`: \"This will move user X to household Y. Confirm?\"\n\n3. **Agent Behavior Rules Section**\n   - Clear instructions on when to proceed vs. when to ask\n   - Explicit prohibition on using `--force` without user instruction\n   - Requirement to explain impact before destructive operations\n\n4. **Security Warning Banner**\n   - Added prominent warning at top of SKILL.md\n   - States: \"This skill provides mutation authority over your Tandoor instance\"\n   - Directs users to only install if they want agent mutation authority\n\n**User Impact:** Agents can no longer execute destructive operations without explicit user approval. Users maintain full control over high-impact actions.\n\n---\n\n## 2. Agentic Supply Chain Vulnerabilities (LOW SEVERITY)\n\n### Original Concern\n> The skill relies on an external npm package that is not included in the reviewed artifact set; npx may download and run package code on demand.\n\n### Resolution\n\n**Files Modified:**\n- `SKILL.md`\n- `SECURITY.md`\n\n**Changes Made:**\n\n1. **Version Awareness**\n   - Documentation acknowledges the npm package dependency\n   - Recommends version pinning for production use\n\n2. **Verification Links**\n   - Added direct links to npm package: https://www.npmjs.com/package/tandoor-cli\n   - Added direct link to source repository: https://github.com/dcenatiempo/tandoor-cli\n   - Included in \"Before first use\" checklist\n\n3. **Pre-Installation Checklist**\n   - Verify the npm package\n   - Review the source code\n   - Consider using a test instance first\n\n4. **Supply Chain Security Section**\n   - Added to SKILL.md under \"Security & Permissi"},{"path":"SECURITY.md","content":"# Security Guidelines for Tandoor CLI Skill\n\nThis document addresses security concerns and best practices for using the tandoor-cli skill with AI agents.\n\n## Overview\n\nThe tandoor-cli skill provides programmatic access to your Tandoor Recipe Manager instance. Like any tool with write access to your data, it requires careful configuration and usage to maintain security.\n\n## Addressed Security Concerns\n\n### 1. Tool Misuse and Exploitation (HIGH SEVERITY)\n\n**Concern:** The skill exposes destructive, bulk, and account-administration operations without explicit approval gates.\n\n**Mitigation:**\n- **Command Classification:** All commands are now classified by risk level (read, write, destructive, administrative)\n- **Approval Gates:** The SKILL.md explicitly requires user confirmation before:\n  - Any write operation (add, update, import)\n  - Any destructive operation (delete, clear, bulk operations)\n  - Any administrative operation (household management, user assignment)\n- **Agent Behavior Rules:** Clear instructions prevent agents from executing high-risk commands without explicit user approval\n- **No Automatic --force:** Agents are forbidden from using `--force` flags without explicit user instruction\n\n**User Action Required:**\n- Review the command classification table in SKILL.md\n- Only install this skill if you want the agent to have mutation authority\n- Monitor agent behavior and revoke access if misuse is detected\n\n### 2. Agentic Supply Chain Vulnerabilities (LOW SEVERITY)\n\n**Concern:** The skill relies on an external npm package that could be compromised.\n\n**Mitigation:**\n- **Version Pinning:** The skill explicitly uses `npx tandoor-cli@0.3.1` to pin to a known version\n- **Verification Links:** SKILL.md provides direct links to:\n  - npm package: https://www.npmjs.com/package/tandoor-cli\n  - Source repository: https://github.com/dcenatiempo/tandoor-cli\n- **Pre-Installation Checklist:** Users are instructed to verify the package before first use\n- **No Auto-Updates:** Using `@version` syntax prevents automatic updates to potentially compromised versions\n\n**User Action Required:**\n- Verify the npm package and repository before first installation\n- Review the package source code if using privileged credentials\n- Monitor npm security advisories for the tandoor-cli package\n- Update to newer versions only after reviewing changelogs\n\n### 3. Identity and Privilege Abuse - Space Owner Token (HIGH SEVERITY)\n\n**Concern:** The skill directs use of a highly privileged space-owner token for household invite management.\n\n**Mitigation:**\n- **Least Privilege Principle:** SKILL.md now emphasizes using the least-privileged token possible\n- **Token Scoping Guidance:**\n  - Read-only tokens for query operations\n  - Standard user tokens for recipe management\n  - Admin tokens only when household management is required\n  - Space-owner tokens only for invite link creation\n- **Explicit Warnings:** Administrative commands clearly state they require privileged tokens\n- **Permi"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":2240,"uniquenessScore":36,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-10T18:06:37.122Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-10T18:06:37.122Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T21:51:05.612Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}