{"id":"eaf44c64-2e2b-4528-b7ef-a724f9644570","entityType":"agent","slug":"clawhub-zkeviny-mgc-database-security","name":"Mgc Database Security","canonicalUrl":"https://www.xpersona.co/agent/clawhub-zkeviny-mgc-database-security","canonicalPath":"/agent/clawhub-zkeviny-mgc-database-security","generatedAt":"2026-10-11T20:57:16.524Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T16:39:11.403Z","emptyReason":null},"description":"Secure database credential management using MGC Blackbox 1.5.2. Supports MySQL, PostgreSQL, SQLite, MariaDB and other databases. Credentials are stored encrypted; local scripts retrieve them via HTTP API at runtime, while AI agents never touch plaintext.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1K downloads reported by the source. Last updated 10/11/2026.","installCommand":"clawhub skill install s173fckt3bzxxvt9dfp0rrdeg1894z72:mgc-database-security","sourceUrl":"https://clawhub.ai/zkeviny/mgc-database-security","homepage":"https://clawhub.ai/zkeviny/skills/mgc-database-security","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/zkeviny/mgc-database-security","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/zkeviny/skills/mgc-database-security","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":60,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Mgc Database Security technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-11T16:39:11.403Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T16:39:11.403Z","emptyReason":null},"stars":null,"forks":null,"downloads":1026,"packageName":null,"latestVersion":"1.3.0","tractionLabel":"1K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T16:39:11.331Z","emptyReason":null},"lastUpdatedAt":"2026-10-11T16:39:11.403Z","lastCrawledAt":"2026-10-11T16:39:11.331Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-12T16:39:11.331Z","lastVerifiedAt":null,"highlights":[{"version":"1.3.0","createdAt":"2026-09-29T03:41:25.591Z","changelog":"Version 1.3.0 introduces major upgrades for secure, zero-exposure workflow management and collaboration. - Upgraded to MGC Blackbox 1.5.2+; added mgc_save_file (workflow folder storage), mgc_seal_package (workflow sealing), mgc_package (plaintext packaging). - Migrated script management from single-script to workflow-folder mode with import, from-import, relative-path, and subprocess auto-recognition. - Credential management unified 'info_type' naming from 'credential' to 'token' for skill_spec consistency. - Added dedicated documentation for workflow/skill-package sealed-collaboration. - Enhanced agent prompt: workflow examples upgraded from multi-step chain to find → save_file → run pattern. - Expanded tooling: now documents 10 MCP tools including mgc_save_file, mgc_seal_package, mgc_package.","fileCount":10,"zipByteSize":25972},{"version":"1.2.1","createdAt":"2026-08-18T06:35:09.436Z","changelog":"\"version\": \"1.2.0\", \"changes\": [ \"Upgraded to adapt to MGC 1.4.10\", \"Refactored zero-exposure flow: AI calls mgc_run, local script reads config via HTTP API; credentials never enter AI context\", \"Replaced mgc_get with mgc_run for executing sealed scripts (1.4.7+ blackbox)\", \"Added mgc_find (1.4.10 fuzzy search) and mgc_open_webui to mcp_tools; removed mgc_get\", \"Documented mgc_seal ext02/ext03 packaging (1.4.10 auto-parse) and multi-line PEM requirement for ext04\", \"Added update_if_exists=true for credential rotation\", \"Added 1.4.9 sandbox mode note\", \"Updated MGC main skill doc reference to WebUI MGC Skills button (1.4.7+)\", \"Templates updated with parse_known_args and JSON array ext02 contract\"","fileCount":5,"zipByteSize":12468},{"version":"1.2.0","createdAt":"2026-07-30T07:17:35.992Z","changelog":"changes: - Requires MGC 1.4.7+ for mgc_run support - Use mgc_run instead of mgc_get action=\"run\"","fileCount":5,"zipByteSize":10411},{"version":"1.1.0","createdAt":"2026-07-13T03:20:35.502Z","changelog":"**Major update: Expanded documentation and practical guidance for secure database credential workflows.** - Added complete example section with workflow templates for MySQL, PostgreSQL, and SQL Server - Introduced comprehensive troubleshooting and FAQ sections - Added anti-patterns with recommended correct practices - Clarified capability boundaries and when/when not to use this skill - Included advanced scenarios and multi‑node workflow guidance - Provided templates for SKILL.md and local scripts - Removed redundant skill-card.md file","fileCount":5,"zipByteSize":10265},{"version":"1.0.1","createdAt":"2026-06-22T15:20:15.043Z","changelog":"- Updated documentation to emphasize using MCP tools over CLI for credential management. - Guides secure management of database credentials with MGC Blackbox, supporting multiple database types. - Reinforces zero-exposure: AI models never see database passwords or connection strings. - Provides step-by-step instructions, API reference, and best practices for storing and retrieving credentials securely. - No code included; documentation only.","fileCount":5,"zipByteSize":5188}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s173fckt3bzxxvt9dfp0rrdeg1894z72:mgc-database-security","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s173fckt3bzxxvt9dfp0rrdeg1894z72:mgc-database-security` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/zkeviny/mgc-database-security before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zkeviny-mgc-database-security/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zkeviny-mgc-database-security/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zkeviny-mgc-database-security/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-zkeviny-mgc-database-security/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-zkeviny-mgc-database-security/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-zkeviny-mgc-database-security/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-11T20:57:16.521Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zkeviny-mgc-database-security/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zkeviny-mgc-database-security/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zkeviny-mgc-database-security/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-zkeviny-mgc-database-security/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-11T16:39:11.403Z","emptyReason":null},"readme":"Skill: Mgc Database Security\n\nOwner: zkeviny\n\nSummary: Secure database credential management using MGC Blackbox 1.5.2. Supports MySQL, PostgreSQL, SQLite, MariaDB and other databases. Credentials are stored encrypted; local scripts retrieve them via HTTP API at runtime, while AI agents never touch plaintext.\n\nTags: latest:1.3.0\n\nVersion history:\n\nv1.3.0 | 2026-09-29T03:41:25.591Z | user\n\nVersion 1.3.0 introduces major upgrades for secure, zero-exposure workflow management and collaboration.\n\n- Upgraded to MGC Blackbox 1.5.2+; added mgc_save_file (workflow folder storage), mgc_seal_package (workflow sealing), mgc_package (plaintext packaging).\n- Migrated script management from single-script to workflow-folder mode with import, from-import, relative-path, and subprocess auto-recognition.\n- Credential management unified 'info_type' naming from 'credential' to 'token' for skill_spec consistency.\n- Added dedicated documentation for workflow/skill-package sealed-collaboration.\n- Enhanced agent prompt: workflow examples upgraded from multi-step chain to find → save_file → run pattern.\n- Expanded tooling: now documents 10 MCP tools including mgc_save_file, mgc_seal_package, mgc_package.\n\nv1.2.1 | 2026-08-18T06:35:09.436Z | user\n\n\"version\": \"1.2.0\",\n      \"changes\": [\n        \"Upgraded to adapt to MGC 1.4.10\",\n        \"Refactored zero-exposure flow: AI calls mgc_run, local script reads config via HTTP API; credentials never enter AI context\",\n        \"Replaced mgc_get with mgc_run for executing sealed scripts (1.4.7+ blackbox)\",\n        \"Added mgc_find (1.4.10 fuzzy search) and mgc_open_webui to mcp_tools; removed mgc_get\",\n        \"Documented mgc_seal ext02/ext03 packaging (1.4.10 auto-parse) and multi-line PEM requirement for ext04\",\n        \"Added update_if_exists=true for credential rotation\",\n        \"Added 1.4.9 sandbox mode note\",\n        \"Updated MGC main skill doc reference to WebUI MGC Skills button (1.4.7+)\",\n        \"Templates updated with parse_known_args and JSON array ext02 contract\"\n\nv1.2.0 | 2026-07-30T07:17:35.992Z | user\n\nchanges:\n      - Requires MGC 1.4.7+ for mgc_run support\n      - Use mgc_run instead of mgc_get action=\"run\"\n\nv1.1.0 | 2026-07-13T03:20:35.502Z | user\n\n**Major update: Expanded documentation and practical guidance for secure database credential workflows.**\n\n- Added complete example section with workflow templates for MySQL, PostgreSQL, and SQL Server\n- Introduced comprehensive troubleshooting and FAQ sections\n- Added anti-patterns with recommended correct practices\n- Clarified capability boundaries and when/when not to use this skill\n- Included advanced scenarios and multi‑node workflow guidance\n- Provided templates for SKILL.md and local scripts\n- Removed redundant skill-card.md file\n\nv1.0.1 | 2026-06-22T15:20:15.043Z | auto\n\n- Updated documentation to emphasize using MCP tools over CLI for credential management.\n- Guides secure management of database credentials with MGC Blackbox, supporting multiple database types.\n- Reinforces zero-exposure: AI models never see database passwords or connection strings.\n- Provides step-by-step instructions, API reference, and best practices for storing and retrieving credentials securely.\n- No code included; documentation only.\n\nArchive index:\n\nArchive v1.3.0: 10 files, 25972 bytes\n\nFiles: agent_system_prompt.md (4538b), manifest.json (3819b), prompts/collaboration_management.md (11527b), prompts/credential_management.md (6507b), prompts/knowledge_management.md (5047b), prompts/script_management.md (10641b), README.md (9186b), skill-card.md (1864b), SKILL.md (12179b), _meta.json (140b)\n\nFile v1.3.0:SKILL.md\n\nspec: usk/3.0\nid: data-analyst-secure-suite\nversion: 1.3.0\nname: Secure Data Analyst Skill Suite\ndescription: A secure data analysis workflow suite based on MGC Blackbox 1.5.2+, providing credential protection, zero-exposure script & workflow application, sealed-package collaboration, and knowledge management. Supports MGC 1.5.2 workflow auto-recognition (import / from-import / relative paths / subprocess runtime routing). Includes a Data Analyst Agent system prompt template.\nauthor: MirginCipher Team\nlicense: MIT\ntags: security, data analysis, mgc, zero-exposure, local sandbox, credential management, workflow management, sealed collaboration, knowledge management, agent template, fuzzy search, auto-recognized workflow, sealed cross-script\nplatform_compatibility: windows, macos, linux\nrequires:\n  mgc_blackbox: \">=1.5.2\"\nchangelog:\n  - version: 1.3.0\n    changes:\n      - Upgraded to MGC 1.5.2+: added mgc_save_file (workflow folder storage), mgc_seal_package (workflow sealing), mgc_package (plaintext packaging).\n      - Script management refactor: upgraded from single-script to workflow-folder mode, with import / from-import / relative-path / subprocess auto-recognition.\n      - Credential management: unified info_type from 'credential' to 'token' to align with skill_spec.\n      - Added prompts/collaboration_management.md: dedicated workflow / skill-package sealed-authorization guide.\n      - Agent template: workflow examples upgraded from 5-step manual chain to find -> save_file -> run pattern.\n      - Added sealed-collaboration chapter (mgc_seal_package one-click seal of an entire workflow).\n      - Added recognizable cross-script patterns table (from-import / import / Path / subprocess).\n      - MCP tools list expanded to 10 (added mgc_save_file, mgc_seal_package, mgc_package).\n  - version: 1.2.0\n    changes:\n      - Synced with MGC Blackbox 1.4.10: added mgc_find (fuzzy search) and mgc_run (preferred over mgc_get action=run).\n      - Script management: replaced mgc_get(action='run') with dedicated mgc_run tool.\n      - Script management: added mgc_find workflow for locating scripts by name.\n      - Script sealing: clarified ext04 must be a multi-line PEM public key.\n      - Credential management: added mgc_find workflow.\n      - Knowledge management: added mgc_find workflow.\n      - Agent system prompt: documented the find -> get/run workflow pattern.\n  - version: 1.1.1\n    changes:\n      - Optimized documentation structure per review report\n      - Added 'Anti-patterns and pitfalls' chapter\n      - Added 'Complete use cases' chapter\n      - Unified prompt file-name references\n  - version: 1.1.0\n    changes:\n      - Consolidated prompts into three core modules: credential, script, knowledge management\n      - Added agent_system_prompt.md as a Data Analyst Agent system-prompt template\n      - Strengthened document structure and clarified each module's scenario and invocation\n  - version: 1.0.0\n    changes:\n      - Initial release\n---\n\n# Overview\n\n**Secure Data Analyst Skill Suite** is a documentation skill suite built on **MGC Blackbox 1.5.2+** that helps data analysts securely manage, on the local machine:\n\n- Sensitive credentials\n- User-owned scripts and workflows\n- Workflow / skill-package sealed authorization collaboration\n- Analysis frameworks and knowledge\n\nThis suite uses a **hybrid design**:\n\n- **Skill prompts (under `prompts/`)**: four core capabilities — credential management, workflow management, sealed-collaboration, knowledge management\n- **Agent system-prompt template (`agent_system_prompt.md`)**: builds a Data Analyst Agent that obeys strict security boundaries\n\nAll sensitive operations require explicit user authorization. This suite provides no automated data-access capability.\n\n---\n\n# Scenarios\n\nThis suite is suitable for:\n\n- In-house enterprise data analysis\n- Scenarios requiring sensitive-data protection\n- Secure sharing of scripts / workflows in team collaboration\n- Safe use of vendor scripts\n- Building a secure Data Analyst Agent\n- Building a knowledge accumulation system (can pair with a Self-Improving Agent)\n\n---\n\n# Prerequisites\n\n1. Install MGC Blackbox (≥ 1.5.2):\n   ```\n   pip install mgc-blackbox\n   ```\n2. Start the MGC service:\n   ```\n   mgc\n   ```\n3. Available MCP tools: mgc_save, mgc_save_file, mgc_get, mgc_run, mgc_seal, mgc_seal_package, mgc_package, mgc_list, mgc_find, mgc_open_webui\n4. Token file: `~/.mgc/database/mgc_black_box/.mgc_token`\n\n---\n\n# Core capabilities\n\n## 1. Credential management (`credential_management.md`)\n\nSecurely manage sensitive credentials such as database keys and API tokens.\n\n### Scenarios\n- Need to connect to databases or external services\n- Scripts need safe access to credentials\n- Team members share database/service **access rights** (not the data itself)\n- Team members share **analysis methods and scripts** across the team and outside (via workflow sealed authorization)\n\n### What it provides\n- Local encrypted storage\n- AI never sees credential content\n- Scripts can call credentials with zero exposure\n- All accesses require user authorization\n\n### How the agent uses it\nAfter user authorization, the agent reads credentials but never sees plaintext.\n\n---\n\n## 2. Workflow management (`script_management.md`)\n\nManage user-owned query / clean / analyze scripts — both single-script and workflow-folder modes.\n\n### Scenarios\n- User wants to apply their own scripts or workflows\n- Scripts need safe access to credentials\n- Multi-script workflows need auto-recognition of import / subprocess call relationships (1.5.2+)\n- Workflows need cross-team collaboration (sealed)\n- Need to build a complete data-analysis chain (query → clean → analyze)\n\n### What it provides\n- Single-script encrypted storage (`mgc_save`)\n- Workflow-folder encrypted storage with auto-recognition of import / subprocess (`mgc_save_file`, 1.5.2+)\n- AI never sees script content\n- Scripts call credentials with zero exposure\n- Supports single-script sealing (`mgc_seal`) and workflow sealing (`mgc_seal_package`)\n- All applications require user authorization\n\n### How the agent uses it\nAfter user authorization, the agent runs scripts or workflows through MGC. In workflow mode, MGC auto-recognizes the import chain — no manual parameter chaining needed.\n\n---\n\n## 3. Sealed-authorization collaboration (`collaboration_management.md`)\n\nSeal-authorize workflows and skill packages to other nodes, enabling \"usable but not readable, runnable but not resellable\" cross-team / cross-organization collaboration.\n\n### Scenarios\n- Data team seals an analysis workflow to a business team (run only, no source access)\n- Vendor analyst seals an analysis solution to a client\n- Cross-department sharing of analysis methodologies while protecting core logic\n- Independent license per client\n\n### What it provides\n- Workflow sealing (`mgc_seal_package`): seal the entire workflow in one call, AES-256 encryption\n- Skill-package sealing: seal a complete skill package (with SKILL.md); receiving AI can read the instructions but cannot see source code\n- Node binding: AES key bound to the target node's RSA public key; cannot be re-sealed\n- One-key-per-node: each client receives an independent key\n- No cloud: all encryption / decryption / execution happens locally\n\n### How the agent uses it\nAfter user authorization, the agent performs the sealing operation. The sealed package is delivered by the user manually — the agent does not participate in transport.\n\n---\n\n## 4. Knowledge management (`knowledge_management.md`)\n\nManage knowledge assets: analysis frameworks, prompt templates, methodologies, business rules, and more.\n\n### Scenarios\n- Build standardized analysis frameworks\n- Reuse prompt templates\n- Share analysis methods across the team\n- Build a knowledge accumulation system\n- Pair with a Self-Improving Agent for automatic knowledge capture\n\n### What it provides\n- Encrypted storage of knowledge content\n- Agent reads knowledge with explicit user authorization\n- Knowledge sealed collaboration supported\n- Used to build analysis-report structure\n\n### How the agent uses it\nAfter user authorization, the agent reads knowledge and uses it to guide analysis structure or generate prompts.\n\n---\n\n# Security boundary\n\n## This suite provides\n\n- Local encrypted credential storage\n- Zero-exposure application of user-owned scripts\n- Workflow auto-recognition and sealed routing (1.5.2+, including subprocess literal-list runtime routing)\n- Sealed-authorization collaboration for workflows / skill packages (1.5.2+)\n- Knowledge encryption management\n\n## This suite does NOT provide\n\n- Automated data access\n- Automated cleaning or analysis\n- Automated transport\n- Script generation or modification\n\nAll scripts must be user-provided and comply with organizational policy.\n\n---\n\n# File structure\n\n```\ndata-analyst-secure-suite/\n├── SKILL.md                    # main document (this file)\n├── README.md                   # detailed usage guide\n├── manifest.json               # skill metadata\n├── agent_system_prompt.md      # Agent system-prompt template\n└── prompts/\n    ├── credential_management.md    # credential management\n    ├── script_management.md        # workflow & script management\n    ├── collaboration_management.md # sealed collaboration\n    └── knowledge_management.md     # knowledge management\n```\n\n---\n\n# Usage modes\n\n## Mode 1 — Skill mode\n\nThe AI can read the four core prompts under `prompts/`:\n\n| Document | When to use | Triggered by |\n|----------|-------------|--------------|\n| `credential_management.md` | Need to store or access credentials | user or agent |\n| `script_management.md` | Need to store or run a script/workflow | user or agent |\n| `collaboration_management.md` | Need to seal a workflow / skill package to another node | user or agent |\n| `knowledge_management.md` | Need to store or read knowledge | user or agent |\n\nThe AI cites the matching document on user request and asks for authorization before every sensitive operation.\n\n---\n\n## Mode 2 — Agent template mode\n\nSet `agent_system_prompt.md` as the system prompt for an AI Agent.\n\nThe agent will automatically enforce:\n\n- Request user authorization before every sensitive operation\n- Only apply scripts or workflows through MGC Blackbox\n- Never view script content or credentials\n- Never automate workflow execution\n- Never auto-select a script name (`info_owner` must be supplied by the user)\n\nAfter authorization, the agent may cite documents under `prompts/` as workflow guidance.\n\n---\n\n# MCP tools reference\n\n| Tool | Description | Authorization required |\n|------|-------------|------------------------|\n| `mgc_save` | Store credentials, single scripts, prompts | yes |\n| `mgc_save_file` | Store workflow folders (auto-recognize import / subprocess) | yes |\n| `mgc_get` | Retrieve a value / fetch node_pub | yes |\n| `mgc_run` | Run a script or workflow (black-box) | yes |\n| `mgc_seal` | Seal a single script for collaboration | yes |\n| `mgc_seal_package` | Seal an entire workflow folder | yes |\n| `mgc_package` | Plaintext packaging within the same trust zone | yes |\n| `mgc_list` | List stored entries (exact match) | optional |\n| `mgc_find` | Fuzzy-search entries by name | optional |\n| `mgc_open_webui` | Open MGC WebUI | no |\n\n---\n\n# Security notes\n\n1. **Zero exposure**: scripts and credentials execute locally; the AI receives only run status\n2. **Encrypted storage**: all content encrypted at rest\n3. **No plaintext leak**: the AI never sees script or credential content\n4. **Auto-recognized workflows**: import / from-import / relative-path / subprocess call chains auto-routed; nothing lands on disk (1.5.2+)\n5. **Sealed workflows / skill packages**: entire workflow or skill package sealed to the target node in one call; node-bound; cannot be resold (1.5.2+)\n\n---\n\n# Contact\n\n- Issues: https://github.com/zkeviny/MGC-Blackbox/issues\n- Email: mirgincipher@outlook.com\n\n---\n\n> **Reminder**: This suite is for secure workflow management. All sensitive operations must have explicit user authorization. All scripts are user-owned; all execution happens locally through MGC Blackbox.\n\nFile v1.3.0:README.md\n\n# Secure Data Analyst Skill Suite\n\n# Secure Data Analyst Skill Suite\n\n> **Version**: 1.3.0 · **Requires**: MGC Blackbox ≥ 1.5.2\n\nA secure data-analysis workflow suite built on **MGC Blackbox**, providing a hybrid mix of **skill prompts + Agent system-prompt template**, helping data analysts securely manage scripts, workflows, credentials, sealed collaboration, and knowledge on the local machine.\n\n---\n\n## What this suite is\n\nThis suite helps data analysts complete data-analysis workflows locally and securely:\n\n- **Database credential security** (zero exposure)\n- **Application of user-owned scripts & workflows** (query / clean / analyze)\n- **Auto-recognized workflows** (import / from-import / relative-path / subprocess runtime routing, 1.5.2+)\n- **Sealed-collaboration on workflows / skill packages** (one-key-per-node, node-bound, no resell, 1.5.2+)\n- **Knowledge management for analysis methods & prompts** (local encrypted storage)\n- **Optional Data Analyst Agent template** (auto-enforces the security boundary)\n\nAll sensitive operations require explicit user authorization. This suite does not provide any automated data-access capability.\n\n---\n\n## Prerequisites\n\n- Python 3.10+\n- Install MGC Blackbox:\n  ```\n  pip install mgc-blackbox>=1.5.2\n  ```\n- Start MGC:\n  ```\n  mgc\n  ```\n- Available MCP tools: mgc_save, mgc_save_file, mgc_get, mgc_run, mgc_seal, mgc_seal_package, mgc_package, mgc_list, mgc_find, mgc_open_webui\n- Token file: `~/.mgc/database/mgc_black_box/.mgc_token`\n\n---\n\n## Core capabilities\n\n### 1. Credential management (`credential_management.md`)\n\nSecurely store and use database keys, API tokens, and other secrets.\n\n**Scenarios**\n- Need to connect to databases or external services\n- Scripts need safe access to credentials\n- Team members share database/service **access rights** (not the data itself)\n- Team members share **analysis methods and scripts** across the team and outside (via workflow sealed authorization)\n\n**What it provides**\n- Local encrypted storage\n- AI never sees the plaintext credentials\n- Scripts can call credentials with zero exposure\n- All accesses require user authorization\n\n**How the agent uses it**\nThe agent, after user authorization, reads credentials but never sees plaintext.\n\n---\n\n### 2. Workflow management (`script_management.md`)\n\nManage user-owned query / clean / analyze scripts — both as single scripts and as workflow folders.\n\n**Scenarios**\n- User wants to apply their own scripts or workflows\n- Scripts need safe access to credentials\n- Multi-script workflows need auto-recognition of import / subprocess call relationships (1.5.2+)\n- Workflows need cross-team collaboration (sealed)\n- Need to build a complete data-analysis chain (query → clean → analyze)\n\n**What it provides**\n- Single-script encrypted storage (`mgc_save`)\n- Workflow-folder encrypted storage with auto-recognition of import / subprocess (`mgc_save_file`, 1.5.2+)\n- AI never sees the script content\n- Scripts call credentials with zero exposure\n- Single-script sealing (`mgc_seal`) and workflow sealing (`mgc_seal_package`) supported\n- All applications require user authorization\n\n**How the agent uses it**\nThe agent, after user authorization, runs scripts or workflows through MGC. In workflow mode, MGC auto-recognizes the import chain — no manual parameter chaining needed.\n\n---\n\n### 3. Sealed-collaboration (`collaboration_management.md`)\n\nSeal-authorize workflows and skill packages to other nodes, enabling \"usable but not readable, runnable but not resellable\" cross-team / cross-organization collaboration.\n\n**Scenarios**\n- Data team seals an analysis workflow to a business team (run only, no source access)\n- Vendor analyst seals an analysis solution to a client\n- Cross-department method sharing while protecting core logic\n- Independent license per client\n\n**What it provides**\n- Workflow sealing (`mgc_seal_package`): seal the entire workflow in one call, AES-256 encryption\n- Skill-package sealing: seal a complete skill package (with SKILL.md); receiving AI can read the instructions but cannot see source code\n- Node binding: AES key bound to the target node's RSA public key; cannot be re-sealed\n- One-key-per-node: each client receives an independent key\n- No cloud: all encryption / decryption / execution happens locally\n\n**How the agent uses it**\nThe agent performs the sealing operation after user authorization. The sealed package is delivered by the user manually — the agent does not participate in transport.\n\n---\n\n### 4. Knowledge management (`knowledge_management.md`)\n\nManage knowledge assets such as analysis frameworks, prompt templates, methodologies, and business rules.\n\n**Scenarios**\n- Build standardized analysis frameworks\n- Reuse prompt templates\n- Share analysis methods across the team\n- Build a knowledge accumulation system\n- Pair with a Self-Improving Agent for automatic knowledge capture\n\n**What it provides**\n- Encrypted storage of knowledge content\n- Agent reads knowledge with explicit user authorization\n- Knowledge sealed collaboration supported\n- Used to build analysis-report structure\n\n**How the agent uses it**\nThe agent, after user authorization, reads knowledge and uses it to guide analysis structure or generate prompts.\n\n---\n\n## Security boundary\n\n### This suite provides\n- Local encrypted credential storage\n- Zero-exposure application of user-owned scripts\n- Workflow auto-recognition and sealed routing (1.5.2+, including subprocess literal-list runtime routing)\n- Sealed-collaboration for workflows / skill packages (1.5.2+)\n- Knowledge encryption management\n\n### This suite does NOT provide\n- Automated data access\n- Automated cleaning or analysis\n- Automated transport\n- Script generation or modification\n\nAll scripts must be user-owned and comply with organizational policy.\n\n---\n\n## File structure\n\n```\ndata-analyst-secure-suite/\n├── SKILL.md                    # main document (this file)\n├── README.md                   # detailed usage guide\n├── manifest.json               # skill metadata\n├── agent_system_prompt.md      # Agent system-prompt template\n└── prompts/\n    ├── credential_management.md    # credential management\n    ├── script_management.md        # workflow & script management\n    ├── collaboration_management.md # sealed collaboration\n    └── knowledge_management.md     # knowledge management\n```\n\n---\n\n## Usage modes\n\n### Mode 1 — Skill mode\n\nThe AI can read the four core prompts under `prompts/`:\n\n| Document | When to use | Triggered by |\n|----------|-------------|--------------|\n| `credential_management.md` | Need to store or access credentials | user or agent |\n| `script_management.md` | Need to store or run a script/workflow | user or agent |\n| `collaboration_management.md` | Need to seal a workflow / skill package to another node | user or agent |\n| `knowledge_management.md` | Need to store or read knowledge | user or agent |\n\nThe AI cites the matching document on user request and asks for authorization before each sensitive operation.\n\n---\n\n### Mode 2 — Agent template mode\n\nSet `agent_system_prompt.md` as the system prompt for an AI Agent.\n\nThe agent will automatically enforce:\n\n- Request user authorization before every sensitive operation\n- Only apply scripts or workflows through MGC Blackbox\n- Never view script content or credentials\n- Never automate workflow execution\n- Never auto-select a script name (`info_owner` must be supplied by the user)\n\nAfter authorization, the agent may cite documents under `prompts/` as workflow guidance.\n\n---\n\n## MCP tools reference\n\n| Tool | Description | Authorization required |\n|------|-------------|------------------------|\n| `mgc_save` | Store credentials, single scripts, prompts | yes |\n| `mgc_save_file` | Store workflow folders (auto-recognize import / subprocess) | yes |\n| `mgc_get` | Retrieve a value / fetch node_pub | yes |\n| `mgc_run` | Run a script or workflow (black-box) | yes |\n| `mgc_seal` | Seal a single script for collaboration | yes |\n| `mgc_seal_package` | Seal an entire workflow folder | yes |\n| `mgc_package` | Plaintext packaging within the same trust zone | yes |\n| `mgc_list` | List stored entries (exact match) | optional |\n| `mgc_find` | Fuzzy-search entries by name | optional |\n| `mgc_open_webui` | Open MGC WebUI | no |\n\n---\n\n## Security notes\n\n1. **Zero exposure**: scripts and credentials execute locally; the AI receives only run status\n2. **Encrypted storage**: all content encrypted at rest\n3. **No plaintext leak**: the AI never sees script or credential content\n4. **Auto-recognized workflows**: import / from-import / relative-path / subprocess call chains auto-routed; nothing lands on disk (1.5.2+)\n5. **Sealed workflows / skill packages**: entire workflow or skill package sealed to the target node in one call; node-bound; cannot be resold (1.5.2+)\n\n---\n\n## Contact\n\n- Issues: https://github.com/zkeviny/MGC-Blackbox/issues\n- Email: mirgincipher@outlook.com\n\n---\n\n> **Reminder**: This suite is for secure workflow management. All sensitive operations must have explicit user authorization. All scripts are user-owned; all execution happens locally through MGC Blackbox.\n\nFile v1.3.0:_meta.json\n\n{\n  \"ownerId\": \"kn7dbqpp9139vnzrg035qhwfk18947vg\",\n  \"slug\": \"mgc-database-security\",\n  \"version\": \"1.3.0\",\n  \"publishedAt\": 1790653285591\n}\n\nFile v1.3.0:agent_system_prompt.md\n\n# Secure Data Analyst Agent — System Prompt Template (Safety Version)\n\nYou are a **Secure Data Analyst Workflow Assistant** that helps data analysts use MGC Blackbox (≥ 1.5.2) to securely manage and apply their own scripts and workflows on the local machine.\nYou are NOT an automated execution engine. You must strictly obey the security boundary and obtain explicit user authorization before any sensitive operation.\n\n---\n\n## Your role\n\nYou are a **workflow assistant**, not an automation engine.\nYour goal is, after the user authorizes it, to safely apply the user's scripts and workflows via MGC Blackbox and to assist in managing the full workflow.\n\nYou must not make decisions on behalf of the user, and you must not execute anything without authorization.\n\n---\n\n## Security boundary you must obey\n\n### You must NEVER:\n\n- Access any credential without user authorization\n- Access or view script content without user authorization\n- Generate, modify, or infer user scripts\n- Apply scripts or workflows without user authorization\n- Transmit any data to an external system\n- Chain multiple workflow steps without explicit confirmation\n- Auto-select a script name (`info_owner` must be explicitly supplied by the user)\n- Automate data access, cleaning, analysis, or transport\n\n### You MUST:\n\n- Request user authorization before any sensitive operation\n- Only apply scripts and workflows through MGC Blackbox\n- Return results without exposing script logic\n- Only use user-owned scripts\n- Ensure all operations happen on the user's local machine\n- Refer to the prompts in this skill suite when the user asks about workflows\n\n---\n\n## How to use this skill suite\n\n### 1. Credential management\n\nWhen the user wants to store credentials:\n\n```\nAsk: \"Do you authorize storing these credentials in MGC?\"\n- If yes: direct the user to the MGC WebUI\n- You NEVER handle credential content directly\n```\n\n---\n\n### 2. Workflow application (find → save_file → run, 1.5.2+)\n\nWhen the user requests running a data-analysis workflow, use the **find → run** self-describing workflow:\n\n```\nStep 1 — Locate the workflow (mgc_find, fuzzy-search by name):\nmatches = mgc_find(\n    info_owner=\"<partial name>\",  # e.g. \"monthly_sales\" matches \"monthly_sales_analysis\"\n)\n# matches returns a metadata list — NEVER plaintext.\n# If multiple matches, ask the user to disambiguate; if exactly one, proceed.\n\nStep 2 — Request authorization:\n\"Do you authorize running the workflow <info_owner from matches>?\"\n\nStep 3 — If authorized, run the workflow through MGC:\nresult = mgc_run(\n    info_owner=\"<info_owner>\",\n    diff_2=\"<info_owner>\",\n)\n# MGC auto-recognizes the package's import / subprocess relationships and routes through sealed execution.\n# Returns {\"pid\": 12345, \"status\": \"started\"}\n\nStep 4 — Return the run status without exposing script logic\n```\n\n> **Note**: Workflow output must be written to an explicit file path, or into a database / MGC itself. MGC never returns plaintext script content.\n\n---\n\n### 3. Single-script application\n\nWhen the user only needs to run a single standalone script (no cross-script calls):\n\n```\nStep 1 — Locate the script (mgc_find):\nmatches = mgc_find(\n    info_owner=\"<partial name>\",\n    info_type=\"script\",\n)\n\nStep 2 — Request authorization\n\nStep 3 — If authorized, run the script:\nresult = mgc_run(\n    info_type=\"script\",\n    info_owner=\"<info_owner>\",\n    diff_1=\"<info_owner>\",\n)\n\nStep 4 — Return the run status without exposing script logic\n```\n\n---\n\n### 4. Sealed-authorization collaboration\n\nWhen the user wants to deliver a workflow or skill package to another node, refer to `prompts/collaboration_management.md`.\n\nThe agent never transmits the sealed package itself — that is the user's responsibility.\n\n---\n\n### 5. Knowledge application\n\nWhen the user wants to consult or write analysis methods, prompts, or business rules:\n\n```\nStep 1 — Locate knowledge (mgc_find):\nmatches = mgc_find(\n    info_owner=\"<partial name>\",\n)\n\nStep 2 — Request authorization\n\nStep 3 — If authorized, read knowledge:\nresult = mgc_get(\n    info_type=\"text\",\n    info_owner=\"<info_owner>\",\n)\n\nStep 4 — Use the knowledge to guide analysis or generate prompts\n```\n\n---\n\n## Reminders\n\n- Always request user authorization before any sensitive step.\n- Never view script or credential plaintext.\n- `info_owner` is supplied by the user; the agent never auto-selects.\n- All execution happens through MGC Blackbox, locally.\n- The agent never automates transport of sealed packages.\n\nIf in doubt, ask the user.\n\nFile v1.3.0:prompts/collaboration_management.md\n\n# Workflow & Skill Package Sealed Collaboration\n\nThis document guides data analysts on how to securely seal and deliver workflows or skill packages to other nodes in **MGC Blackbox ≥ 1.5.2**, enabling \"usable but unreadable, runnable but unresellable\" cross-team / cross-organization collaboration.\n\nAll sensitive operations must be explicitly authorized by the user before proceeding.\n\n---\n\n# 1. Why Sealed Collaboration Is Needed\n\nCommon collaboration pain points in data analysis workflows:\n\n| Scenario | Pain Point | MGC Solution |\n|----------|-----------|--------------|\n| Data team delivers analysis workflow to business team | Don't want business team to see source code or modify logic | After workflow sealing, recipient can only run, never read |\n| External analyst delivers analysis package to customer | Customer resells source to peers after delivery | AES key bound to customer node, cannot re-seal |\n| Cross-department sharing of analysis methodology | Worry about core algorithm leakage | Seal the entire workflow at once, core algorithms locked inside scripts |\n| Delivering to multiple customers | Each customer needs independent authorization | One key per customer, each customer has independent key |\n\n> **Core principle**: Delivery equals authorization. After sealing, the recipient can only run — cannot read, modify, or resell.\n\n---\n\n# 2. Workflow Sealing vs Skill Package Sealing\n\nMGC supports two sealed collaboration modes:\n\n| Dimension | Workflow Sealing | Skill Package Sealing |\n|-----------|------------------|------------------------|\n| **Sealing Target** | Analysis script folder (run.py + helpers/) | Complete skill package with SKILL.md |\n| **Sealing Tool** | `mgc_seal_package` | `mgc_seal_package` |\n| **Recipient Usage** | `mgc_run` directly invokes entry script | AI reads SKILL.md instructions and calls corresponding scripts |\n| **Use Case** | Deliver a \"one-click run\" analysis tool to business team | Deliver a complete \"AI-understandable usage guide\" package to client |\n| **SKILL.md Included?** | Not required | Required (recipient AI's usage manual) |\n| **Recipient AI Visibility** | Sees only run status | Can read SKILL.md (plaintext), but cannot see script source code |\n\n> **Selection guidance**:\n> - If the recipient only needs to \"execute your analysis\", use **Workflow Sealing**\n> - If the recipient needs AI to autonomously call different scripts per your package, use **Skill Package Sealing**\n\n---\n\n# 3. End-to-End Collaboration Flow\n\n## 3.1 Complete Flow\n\n```\nAuthor Node                                         Recipient Node (Client / Team)\n───────────                                        ──────────────────────\n\n1. Save workflow / skill package\n   mgc_save_file(path=\"./my_workflow\")\n   → MGC auto-recognizes import / subprocess relationships\n\n2. Recipient fetches their own public key            mgc_get(info_type=\"__NODE_PUB__\",\n   (Public key is not secret; any channel OK)         info_owner=\"__NODE_PUB__\")\n                                                    → Send PEM public key to author\n\n3. Seal with recipient's public key\n   mgc_seal_package(\n       info_owner=\"my_workflow\",\n       diff_2=\"my_workflow\",\n       ext04=recipient_PEM_pubkey,\n       output_dir=\"./delivery\",          # REQUIRED in 1.5.2+\n   )\n   → Generates .mgc_file encrypted package\n\n4. Deliver by any channel                            5. Import sealed package\n   (email / USB / IM / cloud drive)                     mgc_save_file(\n                                                          path=\"./received.mgc_file\",\n                                                          info_owner=\"my_workflow\",\n                                                          diff_2=\"my_workflow\",\n                                                       )\n\n                                                   6. Run\n                                                      mgc_run(info_owner=\"my_workflow\",\n                                                              diff_2=\"my_workflow\")\n                                                      → Sealed execution, no plaintext on disk\n```\n\n## 3.2 Security Features\n\n- **AES-256 encryption**: Each script file encrypted independently\n- **RSA-2048 key exchange**: AES key encrypted with recipient node's public key, only recipient can decrypt\n- **Node binding**: Key bound to target node, recipient cannot re-seal to a third party\n- **No cloud**: All encryption / decryption / execution happens locally, MGC connects to no cloud\n- **Any delivery channel**: Encrypted package can be sent via email, USB, IM, cloud drive — even if intercepted, cannot decrypt\n\n---\n\n# 4. Workflow Sealing Walkthrough\n\n## 4.1 Prepare the Workflow Folder\n\n```\nmy_analysis/\n├── manifest.json\n├── run.py              # Entry script\n├── helpers/\n│   ├── query.py        # Query module\n│   ├── clean.py        # Cleaning module\n│   └── analyze.py      # Analysis module\n└── config/\n    └── settings.json\n```\n\n## 4.2 Save to MGC\n\n```python\nmgc_save_file(\n    path=\"./my_analysis\",\n    info_owner=\"monthly_sales_analysis\",\n    diff_2=\"monthly_sales_analysis\",\n)\n# MGC auto-recognizes import / subprocess call relationships\n```\n\n## 4.3 Seal to Target Node\n\n```python\n# Target node's public key (recipient fetches via mgc_get and sends to you)\nrecipient_pub = \"\"\"-----BEGIN PUBLIC KEY-----\nMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA...\n-----END PUBLIC KEY-----\"\"\"\n\nmgc_seal_package(\n    info_owner=\"monthly_sales_analysis\",\n    diff_2=\"monthly_sales_analysis\",\n    ext04=recipient_pub,\n    output_dir=\"./delivery\",  # REQUIRED in 1.5.2+\n)\n# → Generates .mgc_file encrypted package\n```\n\n> **Note**: `ext04` MUST contain real newline characters `\\n`. Do NOT pass PEM as a single concatenated line.\n\n## 4.4 Recipient Imports and Runs\n\n```python\n# Recipient imports the sealed package\nmgc_save_file(\n    path=\"./received.mgc_file\",\n    info_owner=\"monthly_sales_analysis\",\n    diff_2=\"monthly_sales_analysis\",\n)\n\n# Recipient runs (sealed execution, no plaintext on disk)\nmgc_run(\n    info_owner=\"monthly_sales_analysis\",\n    diff_2=\"monthly_sales_analysis\",\n)\n# → {\"pid\": 12345, \"status\": \"started\"}\n```\n\n---\n\n# 5. Skill Package Sealing Walkthrough\n\nThe difference between a skill package and a workflow: it includes `SKILL.md` as the recipient AI's usage manual.\n\n## 5.1 Prepare Skill Package Folder\n\n```\nmy_skill_package/\n├── manifest.json\n├── SKILL.md             # ← Required for skill packages; recipient AI's usage manual (plaintext)\n├── run_query.py          # Query script\n├── run_clean.py          # Cleaning script\n├── run_analyze.py        # Analysis script\n└── helpers/\n    ├── db_connect.py\n    └── stats.py\n```\n\n## 5.2 Role of SKILL.md\n\n`SKILL.md` is **plaintext** — the recipient AI needs to read it to understand:\n- Which scripts are available\n- Which script to call in which scenario\n- What parameters to pass\n- In what order\n\n> **Key rule**: `SKILL.md` describes \"how to use\"; core algorithms live in scripts. Recipient AI can read SKILL.md but cannot read script source.\n\n## 5.3 Save and Seal\n\n```python\n# Save skill package\nmgc_save_file(\n    path=\"./my_skill_package\",\n    info_owner=\"sales_analysis_suite\",\n    diff_2=\"sales_analysis_suite\",\n)\n\n# Seal to target node\nmgc_seal_package(\n    info_owner=\"sales_analysis_suite\",\n    diff_2=\"sales_analysis_suite\",\n    ext04=recipient_pub,\n    output_dir=\"./delivery\",  # REQUIRED in 1.5.2+\n)\n# → Generates .mgc_file encrypted package\n```\n\n## 5.4 Recipient Imports and Uses\n\n```python\n# Recipient imports\nmgc_save_file(\n    path=\"./received.mgc_file\",\n    info_owner=\"sales_analysis_suite\",\n    diff_2=\"sales_analysis_suite\",\n)\n\n# Recipient AI reads SKILL.md (plaintext, learns how to use)\nmgc_get(\n    info_type=\"file\",\n    info_owner=\"sales_analysis_suite\",\n    diff_2=\"sales_analysis_suite\",\n    diff_3=\"SKILL.md\",\n)\n\n# Recipient AI follows SKILL.md instructions to invoke corresponding scripts\nmgc_run(\n    info_owner=\"sales_analysis_suite\",\n    diff_2=\"sales_analysis_suite\",\n)\n```\n\n---\n\n# 6. Independent Authorization per Customer\n\nEach customer needs to be sealed independently — one key binds to one node:\n\n```python\n# Seal for customer A\nmgc_seal_package(\n    info_owner=\"monthly_sales_analysis\",\n    diff_2=\"monthly_sales_analysis\",\n    ext04=client_a_pub,\n    output_dir=\"./delivery_a\",\n)\n# → Generates .mgc_file for customer A\n\n# Seal for customer B (same workflow, different key)\nmgc_seal_package(\n    info_owner=\"monthly_sales_analysis\",\n    diff_2=\"monthly_sales_analysis\",\n    ext04=client_b_pub,\n    output_dir=\"./delivery_b\",\n)\n# → Generates .mgc_file for customer B\n```\n\n**Security features**:\n- Customer A's package cannot run on Customer B's machine (key mismatch)\n- Customer A cannot re-seal their package to Customer C (AES key bound to A's node)\n- Each customer's sealed package is independent, no cross-impact\n\n---\n\n# 7. Authorization Template (AI Must Ask)\n\n### Before sealing a workflow:\n\n```\nWorkflow Name: monthly_sales_analysis\nTarget Node Public Key: {first 16 chars of node_pub}...\nOperation: Seal Workflow\nAuthorization Required: YES\n\nDo you authorize sealing this workflow? Reply \"yes\" to proceed, or \"no\" to cancel.\n```\n\n### Before sealing a skill package:\n\n```\nSkill Package Name: sales_analysis_suite\nTarget Node Public Key: {first 16 chars of node_pub}...\nOperation: Seal Skill Package\nAuthorization Required: YES\n\nDo you authorize sealing this skill package? Reply \"yes\" to proceed, or \"no\" to cancel.\n```\n\n---\n\n# 8. Best Practices\n\n### ✔ 1. Put Core Algorithms in Scripts, Not in SKILL.md\nSKILL.md is plaintext; the recipient can read it. The algorithm is your \"product\" — it must be locked inside scripts.\n\n### ✔ 2. SKILL.md Only Describes Routing\nSpecify \"which scenario calls which script, with what parameters\"; do not write business logic details.\n\n### ✔ 3. Seal Independently for Each Customer\nDo not try to deliver one sealed package to multiple customers — each customer's key binds to their own node.\n\n### ✔ 4. Write Results to Specified Files\nAfter a sealed package runs, MGC will not return plaintext. Workflow output must explicitly target a file path, or be written to a database or MGC itself.\n\n### ✔ 5. Delivery Channel Is Unrestricted\nEncrypted packages can be sent via email, USB, IM, or cloud drive. Even if intercepted, without the corresponding node's private key it cannot be decrypted.\n\n---\n\n# 9. FAQ\n\n| Issue | Solution |\n|-------|----------|\n| Sealing failed | Check whether `ext04` is a multi-line PEM public key (preserving `\\n`) |\n| Recipient run fails | Check whether dependencies in `ext05` are installed on recipient side |\n| Recipient import fails | Ensure all scripts are within the same `mgc_save_file` package |\n| Platform incompatible | Check whether `ext06` contains the recipient's OS |\n| Customer says \"it doesn't work on another machine\" | This is by design — node binding prevents resale |\n\n---\n\n# 10. Summary\n\nThis sealed collaboration document provides:\n\n- Workflow sealing (`mgc_seal_package`) and skill package sealing\n- End-to-end authorized collaboration flow (node_pub → seal → import → run)\n- Multi-customer independent authorization (one key per seal, one node per key)\n- IP protection: \"usable but unreadable, runnable but unresellable\"\n\nThis is the core capability of secure data analyst collaboration workflows.\n\nFile v1.3.0:prompts/credential_management.md\n\n# Credential Management Workflow\n\nThis document guides data analysts on how to securely manage database keys, API tokens, and other sensitive credentials in **MGC Blackbox**, and implement **zero-exposure calls** in scripts.\n\nAll sensitive operations must be explicitly authorized by the user before proceeding.\n\n---\n\n# Overview\n\nMGC Blackbox provides local encrypted storage and zero-exposure access capabilities:\n\n- Credentials never exposed to AI in plaintext\n- Credentials decrypted only on user's local machine\n- Scripts can safely call credentials, but AI cannot see content\n- All access requires user authorization\n\n---\n\n# How to Securely Store Credentials\n\nCredential storage is recommended via **MGC WebUI** or **mgc_save** tool.\n\n## Method 1: Via WebUI (Recommended)\n\n1. Start MGC:\n   ```\n   mgc\n   ```\n2. Open WebUI:\n   ```\n   http://127.0.0.1:57218\n   ```\n3. Navigate to **Save page**\n4. Fill in fields:\n\n```\ninfo_type: \"token\"                 # 1.5.x unified to 'token'\ninfo_owner: \"db_warehouse_prod\"   # Custom name\ncontent: <your database credentials>  # Encrypted locally\n```\n\n## Method 2: Via mgc_save\n\n```python\nmgc_save(\n    info_type=\"token\",               # 1.5.x unified to 'token'\n    info_owner=\"db_warehouse_prod\",\n    content=\"postgres://user:password@host:5432/dbname\"\n)\n```\n\n## Security Notes\n\n- Credentials stored encrypted locally\n- AI cannot see credential content\n- All access requires user authorization\n- Credentials never leave user's machine\n\n---\n\n# How to Call Credentials with Zero Exposure (Core)\n\nScripts can safely access credentials, but AI can never see credential content.\n\nBelow is the **standard zero-exposure credential call pattern** (pseudocode):\n\n## Standard Example: Script Internally Accesses Credentials Safely\n\nScripts access credentials via MGC local API:\n\n```python\nimport requests\nimport os\nimport json\n\nBASE_URL = \"http://127.0.0.1:57219\"\nTOKEN_PATH = os.path.expanduser(\"~/.mgc/database/mgc_black_box/.mgc_token\")\n\ndef get_token():\n    \"\"\"Read local Token\"\"\"\n    if os.path.exists(TOKEN_PATH):\n        with open(TOKEN_PATH) as f:\n            return f.read().strip()\n    return \"\"\n\ndef get_credential():\n    \"\"\"Get credential from MGC\"\"\"\n    token = get_token()\n    if not token:\n        print(\"Token not found!\")\n        return None\n\n    resp = requests.post(\n        f\"{BASE_URL}/api/mgc/sensitive/get\",\n        headers={\"X-MGC-Token\": token, \"Content-Type\": \"application/json\"},\n        json={\n            \"info_type\": \"token\",   # 1.5.x unified to 'token'\n            \"info_owner\": \"db_warehouse_prod\"  # Credential name\n        }\n    )\n\n    if resp.status_code == 200:\n        data = resp.json()\n        if data.get(\"code\") == 200:\n            data_field = data.get(\"data\")\n            # data_field may be string or dict\n            if isinstance(data_field, str):\n                return json.loads(data_field)\n            elif isinstance(data_field, dict):\n                content = data_field.get(\"content\")\n                if content:\n                    return json.loads(content)\n    return None\n\n# Using credential\ndef query_monthly_orders():\n    credential = get_credential()\n    # ... Use credential to connect and query\n```\n\nNote:\n- This call is local only (127.0.0.1), AI cannot see credentials\n- Token file path: `~/.mgc/database/mgc_black_box/.mgc_token`\n\n### Locating Credentials by Name (Recommended Workflow, v1.4.10+)\n\nBefore fetching a credential, locate it with **mgc_find** (fuzzy search by name):\n\n```python\n# Fuzzy search for a credential by name\nmatches = mgc_find(\n    info_owner=\"db_warehouse\",   # partial name; substring match by default\n    info_type=\"token\",\n)\n# Returns metadata list — never the credential plain_text.\n# After locating the exact (info_type, info_owner), the script internally\n# calls mgc_get to retrieve and decrypt.\n```\n\n**Security features**:\n- `mgc_find` never returns credential plain_text — only metadata\n- After locating, the script still goes through `mgc_get` (local decryption)\n- All access still requires user authorization\n\n## Security Features\n\n- Credentials decrypted locally\n- AI cannot see credential content\n- Internal script calls do not expose credentials\n- Authorization required before access\n\n---\n\n## Using Credentials in Scripts (Example)\n\n```python\ndef query_monthly_orders():\n    credential = get_db_credential()\n\n    # Use credential to establish connection (example)\n    conn = connect_to_database(credential)\n\n    # Execute user's own query logic\n    result = conn.execute(\"SELECT * FROM orders WHERE month = '2024-06'\")\n    return result\n```\n\n---\n\n# How to Authorize Credential Access (User Must Confirm)\n\nWhen AI needs to access credentials, it must ask the user:\n\n```\nCredential Name: db_warehouse_prod\nOperation: Access Credential\nAuthorization Required: YES\n\nDo you authorize accessing this credential? Reply \"yes\" to proceed or \"no\" to cancel.\n```\n\nAI must not access any credentials without user authorization.\n\n---\n\n# Best Practices\n\n## 1. Use Descriptive info_owner\nFor example:\n- `db_warehouse_prod`\n- `api_salesforce_token`\n- `redis_cache_credential`\n\n## 2. Do Not Hardcode Credentials in Scripts\nAll credentials must be obtained via MGC.\n\n## 3. Do Not Paste Credentials in AI Conversations\nAI cannot protect plaintext credentials.\n\n## 4. All Access Requires Authorization\nAI must not automatically access credentials.\n\n---\n\n# FAQ\n\n| Issue | Solution |\n|-------|----------|\n| Script cannot access credentials | Check if info_owner matches |\n| Credentials empty | Check if WebUI stored correctly |\n| Execution failed | Check if script dependencies are available locally |\n\n---\n\n## Collaboration extension (1.5.2+)\n\n### Sharing access rights (not the data)\n\nMultiple team members can each call the same credential (e.g. `db_warehouse_prod`) from their own machines through MGC, without sharing any data externally. Each member stores the credential on their own node via `mgc_save` and reads it via `mgc_get`.\n\n### Sharing analysis methods and scripts across the team\n\nWhen the team wants to share **analysis methods and scripts** (not just credentials), use `mgc_seal_package` to seal a workflow folder to a target node (one-key-per-node). See `prompts/collaboration_management.md` for the full flow.\n\n---\n\n# Summary\n\nThis credential management document provides:\n\n- Local encrypted storage\n- Zero-exposure calls\n- User authorization mechanism\n- Secure script writing guidelines\n\nThis is the foundational capability for secure data analyst workflows.\n\n---\n\nFile v1.3.0:prompts/knowledge_management.md\n\n# Knowledge Management\n\nThis document guides data analysts on how to securely manage knowledge assets — analysis frameworks, prompt templates, business rules, methodologies — in **MGC Blackbox ≥ 1.5.1**, implementing local encrypted storage and zero-exposure access.\n\nAll sensitive operations must be explicitly authorized by the user before proceeding.\n\n---\n\n# 1. Overview\n\nMGC Blackbox provides local encrypted storage and zero-exposure access for knowledge content:\n\n- Knowledge content never exposed to AI\n- Knowledge decrypted only on the user's local machine\n- AI can read knowledge after user authorization, but cannot see plaintext\n- All access must be authorized by the user\n\nKnowledge management is the core capability for building reusable analysis systems.\n\n---\n\n# 2. Storable Knowledge Types\n\n| Type | Description | Example |\n|------|-------------|---------|\n| Analysis Frameworks | Standardized analysis structures | \"Monthly Sales Analysis Framework\" |\n| Prompt Templates | Reusable prompts | \"Data Quality Check Prompt\" |\n| Methodologies | Analysis methods | \"Cohort Analysis Methodology\" |\n| Business Rules | Domain rules | \"Customer Segmentation Rules\" |\n| Best Practices | Experience summaries | \"Data Validation Best Practices\" |\n\nAll knowledge content must be provided by the user; this suite does not generate knowledge content.\n\n---\n\n# 3. How to Securely Store Knowledge Content\n\nKnowledge storage is recommended via **MGC WebUI** or **mgc_save** tool.\n\n---\n\n## Method 1: Via WebUI (Recommended)\n\n1. Start MGC:\n   ```\n   mgc\n   ```\n2. Open WebUI:\n   ```\n   http://127.0.0.1:57218\n   ```\n3. Navigate to **Save page**\n4. Fill in fields:\n\n```\ninfo_type: \"prompt\" or \"knowledge\"\ninfo_owner: \"framework_monthly_sales\"   # Custom name\ncontent: <your knowledge content>\n```\n\n---\n\n## Method 2: Via mgc_save\n\n```python\nmgc_save(\n    info_type=\"prompt\",\n    info_owner=\"framework_monthly_sales\",\n    content=\"\"\"\n# Monthly Sales Analysis Framework\n## Step 1: Data Validation\n- Check data completeness\n- Verify date range\n\n## Step 2: Key Metrics\n- Total revenue\n- Growth rate\n- Customer count\n\"\"\"\n)\n```\n\n---\n\n# 4. How to Securely Read Knowledge Content (Zero-Exposure)\n\nAI can read knowledge after user authorization, but cannot see plaintext content.\n\n---\n\n## Standard Reading Method (Requires User Authorization)\n\n```python\nknowledge = mgc_get(\n    info_type=\"prompt\",\n    info_owner=\"framework_monthly_sales\"\n)\n```\n\n### Locating Knowledge Entries (Recommended Workflow, v1.4.10+)\n\nBefore reading knowledge, locate it with **mgc_find** (fuzzy search by name):\n\n```python\n# Fuzzy search for knowledge by name\nmatches = mgc_find(\n    info_owner=\"framework\",  # partial name; substring match by default\n    info_type=\"prompt\",\n)\n# Returns metadata list — never the knowledge plain_text.\n# After locating the exact (info_type, info_owner), call mgc_get to read.\n```\n\n**Security features**:\n- `mgc_find` never returns knowledge plain_text — only metadata\n- After locating, `mgc_get` decrypts locally\n- All access still requires user authorization\n\n---\n\n## Security Features\n\n- AI cannot see knowledge plaintext\n- All access completed locally\n- All access must be authorized by the user\n\n---\n\n# 5. How to Use Knowledge Content in Analysis\n\nKnowledge content can be used for:\n\n- Building analysis report structures\n- Guiding analysis steps\n- Generating prompts\n- Reusing business rules\n- Reusing methodologies\n\nExample (AI uses knowledge after user authorization):\n\n```\nUser: \"Use the monthly sales analysis framework to analyze this data.\"\n\n→ AI requests authorization to read knowledge\n→ User authorizes\n→ AI uses knowledge content to build analysis structure\n```\n\n---\n\n# 6. Authorization Template (AI Must Ask)\n\nWhen AI needs to read knowledge, it must ask the user:\n\n```\nKnowledge Name: framework_monthly_sales\nOperation: Read Knowledge Content\nAuthorization Required: YES\n\nDo you authorize reading this knowledge? Reply \"yes\" to proceed, or \"no\" to cancel.\n```\n\nAI must not read any knowledge without user authorization.\n\n---\n\n# 7. Best Practices\n\n### ✔ 1. Use Descriptive Knowledge Names\nFor example:\n- `framework_monthly_sales`\n- `prompt_data_quality_check`\n- `rule_customer_segmentation`\n\n### ✔ 2. Knowledge Content Should Be Structured\nFor example:\n- Markdown\n- JSON\n- Step-by-step structure\n\n### ✔ 3. Do Not Paste Knowledge Plaintext in AI Conversations\nAI cannot protect sensitive content.\n\n### ✔ 4. All Reading Requires Authorization\nAI must not automatically read knowledge.\n\n---\n\n# 8. FAQ\n\n| Issue | Solution |\n|-------|----------|\n| Cannot read knowledge | Check whether `info_owner` matches |\n| Knowledge is empty | Check whether WebUI stored correctly |\n| Sealing failed | Check whether the target node has MGC 1.4.6+ installed |\n\n---\n\n# 9. Summary\n\nThis knowledge management document provides:\n\n- Encrypted knowledge storage\n- Zero-exposure reading\n- User authorization mechanism\n- Analysis framework and prompt reuse capabilities\n\nThis is the core capability for building reusable analysis systems.\n\nFile v1.3.0:prompts/script_management.md\n\n# Script & Workflow Management\n\nThis document guides data analysts on how to securely manage query scripts, cleaning scripts, analysis scripts, and other **user-owned scripts** in **MGC Blackbox ≥ 1.5.2**, and implement **zero-exposure application** locally.\n\nAll sensitive operations must be explicitly authorized by the user before proceeding.\n\n---\n\n# 1. Overview\n\nMGC Blackbox 1.5.2+ provides local encrypted storage, automatic cross-script recognition, and zero-exposure application:\n\n- Script content never exposed to AI\n- Scripts decrypted only on the user's local machine\n- Scripts can safely call credentials (zero-exposure)\n- All applications must be authorized by the user\n- AI can only see execution results, never script logic\n- **Workflow folders are automatically scanned for `import` / relative-path / `subprocess` call relationships** (1.5.1+)\n\n---\n\n# 2. Two Management Modes\n\n| Mode | Scenario | Storage Tool | Run Tool |\n|------|---------|-------------|---------|\n| **Workflow Mode (recommended)** | Multi-script pipelines (query → clean → analyze) | `mgc_save_file` | `mgc_run` (specify entry script) |\n| **Single-Script Mode** | Single independent script | `mgc_save` | `mgc_run` |\n\n> **Recommendation**: If your analysis chain has 2+ scripts, use Workflow Mode. MGC will automatically recognize `import` / `from-import` / relative-path / `subprocess` relationships between scripts and route execution under sealing — no manual parameter passing needed.\n\n---\n\n# 3. Workflow Mode (Recommended, 1.5.2+)\n\n## 3.1 Workflow Folder Structure\n\nA typical data analysis workflow:\n\n```\nmy_analysis/\n├── manifest.json\n├── run.py              # Entry script: invokes modules under helpers\n├── helpers/\n│   ├── query.py        # Query module\n│   ├── clean.py        # Cleaning module\n│   └── analyze.py      # Analysis module\n└── config/\n    └── settings.json   # Configuration file\n```\n\n`run.py` can directly `import` modules from the same package:\n\n```python\n# run.py\nfrom helpers.query import query_data\nfrom helpers.clean import clean_data\nfrom helpers.analyze import analyze_data\n\ndef main():\n    raw = query_data()\n    cleaned = clean_data(raw)\n    result = analyze_data(cleaned)\n    # Write result to file or MGC; never return it\n    with open(\"output/report.xlsx\", \"wb\") as f:\n        f.write(result)\n\nif __name__ == \"__main__\":\n    main()\n```\n\n## 3.2 Save the Workflow\n\n```python\nmgc_save_file(\n    path=\"./my_analysis\",\n    info_owner=\"monthly_sales_analysis\",\n    diff_2=\"monthly_sales_analysis\",\n)\n```\n\n**MGC will automatically**:\n- Parse each script's `argparse` and write it to `ext02` (parameter list)\n- Scan imports and write them to `ext05` (dependency list)\n- Infer `ext06` (platform list)\n- Build `ext08` (cross-script call graph) — recognizing `import` / `from-import` / `Path` relative-path / `subprocess` relationships\n\n> **Note**: MGC will **use the last segment of the path as `diff_2`** (e.g. `path=\"./my_analysis\"` actually writes `diff_2=\"my_analysis\"`). After saving, please use `mgc_find` to confirm the actual `diff_2` before passing it to sealing.\n\n## 3.3 Run the Workflow\n\n```python\nmgc_run(\n    info_owner=\"monthly_sales_analysis\",\n    diff_2=\"monthly_sales_analysis\",\n)\n# → {\"pid\": 12345, \"status\": \"started\"}\n```\n\nMGC will automatically:\n- Decrypt all scripts into memory (never written to disk)\n- Intercept `import` / `subprocess` calls and route through sealed execution\n- Return run status, never script content\n\n## 3.4 Locate Workflow by Name\n\n```python\n# Fuzzy search for a workflow\nmatches = mgc_find(\n    info_owner=\"monthly\",      # partial name; substring match by default\n    match_mode=\"substring\",\n)\n# Returns metadata list (info_type, info_owner, ext01..ext03) — never plain text.\n# After locating the exact info_owner, pass it to mgc_run.\n```\n\n## 3.5 Workflow Sealed Collaboration (1.5.2+)\n\nSeal the entire workflow to another node (team member / client) in one shot:\n\n```python\n# 1. The recipient first fetches their own node_pub\n# Recipient runs: mgc_get(info_type=\"__NODE_PUB__\", info_owner=\"__NODE_PUB__\")\n\n# 2. You seal the entire workflow with the recipient's public key\nmgc_seal_package(\n    info_owner=\"monthly_sales_analysis\",\n    diff_2=\"monthly_sales_analysis\",\n    ext04=recipient_node_pub,          # Recipient's PEM public key\n    output_dir=\"./delivery\",            # REQUIRED in 1.5.2+: output directory for sealed package\n)\n# → Generates .mgc_file encrypted package\n```\n\nAfter the recipient receives the `.mgc_file`:\n\n```python\n# Recipient imports the sealed package (info_owner / diff_2 must match sealing-time values)\nmgc_save_file(\n    path=\"./received.mgc_file\",\n    info_owner=\"monthly_sales_analysis\",\n    diff_2=\"monthly_sales_analysis\",\n)\n\n# Recipient runs in blackbox mode\nmgc_run(info_owner=\"monthly_sales_analysis\", diff_2=\"monthly_sales_analysis\")\n```\n\n**Security features**:\n- Whole workflow sealed in one shot, no need to seal each script individually\n- AES key bound to recipient's RSA public key, recipient cannot re-seal to a third party\n- Recipient can only run, never read source\n\n> **Note**: `ext04` MUST contain real newline characters `\\n`. Do NOT pass PEM as a single concatenated line.\n\n---\n\n# 4. Single-Script Mode (Simple Scenarios)\n\nWhen you only need to manage a single independent script (no cross-script calls), use `mgc_save`.\n\n## 4.1 Save a Single Script\n\n```python\nmgc_save(\n    info_type=\"script\",\n    info_owner=\"quick_query\",\n    ext01=\"python\",\n    content=\"<your script content>\"\n)\n```\n\n## 4.2 Run a Single Script\n\n```python\nmgc_run(\n    info_type=\"script\",\n    info_owner=\"quick_query\",\n    diff_1=\"quick_query\",\n)\n```\n\n## 4.3 Seal a Single Script\n\n```python\nsealed = mgc_seal(\n    info_owner=\"quick_query\",\n    ext04=recipient_node_pub,\n)\n```\n\n---\n\n# 5. How Scripts Zero-Exposure Call Credentials Internally\n\n**MGC implementation**: Scripts are stored in MGC; at runtime MGC decrypts and executes the script locally. If the script needs to access credentials, it calls a local API to fetch them internally.\n\n## Standard Example: Script Safely Accesses Credentials Internally\n\n```python\nimport os, requests, json\n\n# Read MGC access token (fixed path, do not change)\nwith open(os.path.expanduser(\"~/.mgc/database/mgc_black_box/.mgc_token\")) as f:\n    MGC_TOKEN = f.read().strip()\n\ndef get_credential(info_owner=\"db_warehouse_prod\"):\n    \"\"\"Fetch credential from MGC\"\"\"\n    resp = requests.post(\n        \"http://127.0.0.1:57219/api/mgc/sensitive/get\",\n        headers={\"X-MGC-Token\": MGC_TOKEN},\n        json={\n            \"info_type\": \"token\",\n            \"info_owner\": info_owner,\n        },\n    )\n    if resp.status_code == 200:\n        data = resp.json()\n        if data.get(\"code\") == 200:\n            data_field = data.get(\"data\")\n            if isinstance(data_field, str):\n                return json.loads(data_field)\n            elif isinstance(data_field, dict):\n                content = data_field.get(\"content\")\n                if content:\n                    return json.loads(content)\n    return None\n\n# Using credential\ndef query_monthly_orders():\n    credential = get_credential(\"db_warehouse_prod\")\n    # ... use credential to connect and query\n```\n\n**Notes**:\n- This call is local-only (127.0.0.1), AI cannot see credentials\n- Token file path: `~/.mgc/database/mgc_black_box/.mgc_token`\n\n---\n\n# 6. Recognizable Cross-Script Patterns (Required for Workflow Mode)\n\nWhen saving a workflow folder with `mgc_save_file`, MGC automatically recognizes the following patterns:\n\n| Pattern | Code Example | Recognizable? |\n|---------|--------------|--------------|\n| `from` import | `from config import DEFAULT_CITY` | ✅ |\n| `from` import with alias | `from helpers.fetch import get_weather as gw` | ✅ |\n| Plain `import` | `import helpers.parse` | ✅ |\n| `Path` relative path | `Path(__file__).parent / \"config.py\"` | ✅ |\n| `open()` relative path | `open(\"config.json\")` referencing a sibling file | ✅ |\n| `subprocess` + relative path | `subprocess.run([sys.executable, str(Path(__file__).parent / \"config.py\"), ...])` | ✅ — only within the same package |\n| `subprocess` + literal list (1.5.2+) | `subprocess.run([sys.executable, \"helper.py\", \"--arg\"])` | ✅ — runtime routing support since 1.5.2 |\n| Dynamic import | `importlib.import_module(module_name)` | ❌ only static parsing supported |\n| Absolute path | `open(\"/Users/alice/config.py\")` | ❌ not portable |\n\n**Scope**: Cross-script calls are only recognized within the same folder package. Please keep helpers and driver in the same directory.\n\n---\n\n# 7. Authorization Template (AI Must Ask)\n\nWhen AI needs to apply scripts or workflows, it must ask the user:\n\n```\nWorkflow Name: monthly_sales_analysis\nOperation: Run Workflow\nAuthorization Required: YES\n\nDo you authorize this operation? Reply \"yes\" to proceed, or \"no\" to cancel.\n```\n\nAI must not apply any script or workflow without user authorization.\n\n---\n\n# 8. Best Practices\n\n### ✔ 1. Prefer Workflow Mode\nFor multi-script analysis chains, save with `mgc_save_file` — MGC auto-recognizes import relationships, no manual parameter passing needed.\n\n### ✔ 2. Entry Script Only Handles Orchestration\n`run.py` should only call modules under `helpers`; put core algorithms in their own modules.\n\n### ✔ 3. Write Results to File or MGC\nFor blackbox execution, MGC will not return any plaintext. Workflow output must explicitly target a file path, or be written to a database or MGC itself.\n\n### ✔ 4. Use Descriptive `info_owner`\nFor example: `monthly_sales_analysis`, `customer_churn_prediction`, `daily_report_gen`\n\n### ✔ 5. Never Hardcode Secrets in Scripts\nAll secrets must be obtained through MGC.\n\n### ✔ 6. All Applications Require Authorization\nAI must not automatically apply scripts or workflows.\n\n---\n\n# 9. FAQ\n\n| Issue | Solution |\n|-------|----------|\n| Workflow run fails | Check whether dependencies in `ext05` are installed locally |\n| Import cannot find module | Ensure all scripts are within the same `mgc_save_file` package |\n| Sealing failed | Check whether `ext04` is a multi-line PEM public key (preserving `\\n`) |\n| Platform incompatible | Check whether `ext06` contains the current OS |\n| Credential fetch failed | Check whether `info_owner` matches |\n\n---\n\n# 10. Summary\n\nThis workflow management document provides:\n\n- Encrypted workflow folder storage and automatic recognition\n- Zero-exposure credential calls\n- Zero-exposure workflow execution\n- User authorization mechanism\n- Workflow sealing and collaboration authorization\n\nThis is the core capability of secure data analyst workflows.\n\nFile v1.3.0:skill-card.md\n\n## Description:\n\nGuides data analysts in using MGC Blackbox to manage local credentials, scripts, workflows, knowledge, and sealed collaboration with explicit approval.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[zkeviny](https://clawhub.ai/user/zkeviny)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nData analysts and developers use this skill to manage local credentials, user-owned analysis workflows, knowledge, and authorized sharing through MGC Blackbox.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Agent-triggered credential access or workflow execution can perform sensitive operations.\n\nMitigation: Require explicit user approval for each sensitive operation.\n\nRisk: The MGC token or retrieved credentials can be exposed.\n\nMitigation: Treat the token and any retrieved credential content as secrets.\n\nRisk: Broad zero-exposure claims may overstate protection for knowledge or script internals.\n\nMitigation: Do not assume those contents are invisible to the agent; review what each operation reveals.\n\n## Reference(s):\n\n- [ClawHub skill release](https://clawhub.ai/zkeviny/skills/mgc-database-security)\n- [MGC Blackbox project](https://github.com/zkeviny/MGC-Blackbox)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Code, Shell commands]\n\n**Output Format:** [Markdown with code examples and tool-call guidance]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Requires MGC Blackbox 1.5.2+ for the documented workflows.]\n\n## Skill Version(s):\n\n1.3.0 (source: ClawHub release and bundled skill)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v1.3.0:manifest.json\n\n{\n  \"id\": \"data-analyst-secure-suite\",\n  \"version\": \"1.3.0\",\n  \"name\": \"Secure Data Analyst Skill Suite\",\n  \"description\": \"A secure data analysis workflow suite based on MGC Blackbox 1.5.2+, providing credential protection, zero-exposure script & workflow application, sealed-package collaboration, and knowledge management. Supports MGC 1.5.2 workflow auto-recognition (import / from-import / relative paths / subprocess runtime routing). Includes a Data Analyst Agent system prompt template.\",\n  \"author\": \"MirginCipher Team\",\n  \"license\": \"MIT\",\n  \"tags\": [\n    \"security\",\n    \"data analysis\",\n    \"mgc\",\n    \"zero-exposure\",\n    \"local sandbox\",\n    \"credential management\",\n    \"workflow management\",\n    \"sealed collaboration\",\n    \"knowledge management\",\n    \"agent template\",\n    \"fuzzy search\",\n    \"auto-recognized workflow\",\n    \"sealed cross-script\"\n  ],\n  \"platform_compatibility\": [\"windows\", \"macos\", \"linux\"],\n  \"mcp_tools\": [\"mgc_save\", \"mgc_save_file\", \"mgc_get\", \"mgc_run\", \"mgc_seal\", \"mgc_seal_package\", \"mgc_package\", \"mgc_list\", \"mgc_find\", \"mgc_open_webui\"],\n  \"install\": \"pip install mgc-blackbox>=1.5.2\",\n  \"runtime\": \"mgc\",\n  \"port\": 57219,\n  \"links\": {\n    \"homepage\": \"https://github.com/zkeviny/MGC-Blackbox\",\n    \"issues\": \"https://github.com/zkeviny/MGC-Blackbox/issues\",\n    \"contact\": \"mirgincipher@outlook.com\"\n  },\n  \"keywords\": [\n    \"data analyst\",\n    \"secure workflow\",\n    \"credential protection\",\n    \"workflow management\",\n    \"sealed collaboration\",\n    \"knowledge management\",\n    \"local sandbox\",\n    \"agent template\",\n    \"fuzzy search\",\n    \"workflow sealing\"\n  ],\n  \"agent_template\": {\n    \"name\": \"Secure Data Analyst Agent\",\n    \"file\": \"agent_system_prompt.md\",\n    \"description\": \"A system prompt template for building a secure Data Analyst Agent. All sensitive operations require explicit user authorization.\"\n  },\n  \"disclaimers\": [\n    \"This skill suite does not provide automated data access; all scripts must be user-owned.\",\n    \"All sensitive operations require explicit user authorization.\",\n    \"Scripts must comply with organizational security and compliance policies.\"\n  ],\n  \"changelog\": [\n    {\n      \"version\": \"1.3.0\",\n      \"changes\": [\n        \"Upgraded to MGC 1.5.2+: added mgc_save_file (workflow folder storage), mgc_seal_package (workflow sealing), mgc_package (plaintext packaging).\",\n        \"Script management refactor: upgraded from single-script to workflow-folder mode, with import/from-import/relative-path/subprocess auto-recognition.\",\n        \"Added prompts/collaboration_management.md: dedicated workflow / skill-package sealed-authorization guide.\",\n        \"Credential management: unified info_type from 'credential' to 'token' to align with skill_spec.\",\n        \"Agent template: workflow examples upgraded from 5-step manual chain to find -> save_file -> run pattern.\",\n        \"Added sealed-collaboration chapter (mgc_seal_package one-click seal of an entire workflow).\",\n        \"Added recognizable cross-script patterns table (from-import / import / Path / subprocess).\",\n        \"MCP tools list expanded to 10 (added mgc_save_file, mgc_seal_package, mgc_package).\"\n      ]\n    },\n    {\n      \"version\": \"1.2.0\",\n      \"changes\": [\n        \"Synced with MGC Blackbox 1.4.10: added mgc_find (fuzzy search) and mgc_run (preferred over mgc_get action=run).\",\n        \"Script management: replaced mgc_get(action='run') with dedicated mgc_run tool.\",\n        \"Script management: added mgc_find workflow for locating scripts by name.\",\n        \"Script sealing: clarified ext04 must be a multi-line PEM public key.\",\n        \"Credential management: added mgc_find workflow.\",\n        \"Knowledge management: added mgc_find workflow.\",\n        \"Agent system prompt: documented the find -> get/run workflow pattern.\"\n      ]\n    }\n  ]\n}\n\nArchive v1.2.1: 5 files, 12468 bytes\n\nFiles: manifest.json (2970b), README.md (3007b), skill-card.md (2248b), SKILL.md (23083b), _meta.json (140b)\n\nFile v1.2.1:SKILL.md\n\n---\n\nspec: usk/3.0\nid: mgc_database_security\nversion: 1.2.0\nname: Database Credential Security (Zero‑Exposure Edition)\ndescription: Secure database credential management using MGC Blackbox 1.4.10. Supports MySQL, PostgreSQL, SQLite, MariaDB and other databases. Credentials are stored encrypted; local scripts retrieve them via HTTP API at runtime, while AI agents never touch plaintext.\nauthor: MirginCipher Team\nlicense: MIT\ntags: database, mysql, postgresql, sqlite, mariadb, security, credential-management, zero-exposure, mgc, mgc_run, mgc_find\nplatform_compatibility: windows, macos, linux\nchangelog:\n  - version: 1.2.0\n    changes:\n      - Upgraded to adapt to MGC 1.4.10\n      - Refactored zero-exposure flow (mgc_run + HTTP API; credentials never enter AI context)\n      - Replaced mgc_get with mgc_run for sealed-script execution (1.4.7+ blackbox)\n      - Added mgc_find (1.4.10 fuzzy search) and mgc_open_webui; removed mgc_get\n      - Documented mgc_seal ext02/ext03 packaging (1.4.10 auto-parse) and multi-line PEM for ext04\n      - Added update_if_exists=true for credential rotation\n      - Added 1.4.9 sandbox mode note\n      - Updated MGC main skill doc reference to WebUI MGC Skills button (1.4.7+)\n      - Templates updated with parse_known_args and JSON array ext02 contract\n  - version: 1.1.0\n    changes:\n      - Added complete example section with workflow templates\n      - Added troubleshooting section, FAQ, anti-patterns, capability boundary, advanced scenarios\n  - version: 1.0.1\n    changes:\n      - Updated to emphasize MCP tools over CLI\n  - version: 1.0.0\n    changes:\n      - Initial release with MySQL zero-exposure pattern\n\n---\n\n# Overview\n\nDatabase Credential Security is a documentation skill that teaches how to manage database credentials securely using MGC Blackbox 1.4.10. Supports MySQL, PostgreSQL, SQLite, MariaDB, SQL Server and other databases. Credentials are encrypted at rest; local scripts retrieve them via HTTP API at runtime; **AI agents never touch credential plaintext** (true zero‑exposure via `mgc_run` blackbox execution).\n\nThis skill contains **no executable code** and is safe for automatic approval.\n\n---\n\n# ⚠️ Critical: True Zero‑Exposure Means AI Never Sees Credentials\n\nThe wrong way (breaks zero‑exposure):\n\n```\nAI → mgc_get(config) → returns plaintext JSON (incl. password) → AI uses password\n```\n\nThe right way (1.4.10 true zero‑exposure):\n\n```\nUser → mgc_save(config with credentials)\nUser / Script Agent → mgc_save(script that reads config via HTTP API)\nExecutor Agent → mgc_run(script) → MGC blackbox executes\n                              └─ script reads credentials via HTTP API\n                              └─ script connects to DB and runs SQL\n                              └─ script writes result to file\n                              └─ MGC returns only {pid, status}\nAI → reads result file → only sees SQL output, NEVER password\n```\n\n> **Never call `mgc_get` from AI**. `mgc_get` returns plaintext and breaks zero‑exposure. Use `mgc_run` for blackbox execution instead.\n\n---\n\n# What This Skill Enables\n\nAfter reading this documentation, an AI agent will understand how to:\n\n- Store database credentials encrypted in MGC Blackbox (via WebUI or `mgc_save`)\n- Write local database scripts that retrieve credentials via HTTP API at runtime\n- Execute database scripts via `mgc_run` (1.4.7+ blackbox); AI never sees credentials\n- Manage multiple database connections safely\n- Rotate credentials without code changes (`update_if_exists=true`)\n- Seal database scripts for multi‑node execution with `mgc_seal`\n\n---\n\n# When to Use This Skill\n\n## Must Use Cases\n\n1. **Production environments** — any database access in production requires secure credential management\n2. **Automation tasks** — scheduled scripts that need database access (CI/CD, cron jobs)\n3. **Multi‑node collaboration** — Node A creates a database script, Node B executes it via `mgc_seal`\n4. **AI needs database access but must not see passwords** — AI provides SQL only; scripts handle the rest\n\n## Example Triggers\n\n- \"Connect to MySQL database securely\"\n- \"Execute a SQL query without exposing the password\"\n- \"Create a scheduled backup script for PostgreSQL\"\n- \"Run database migrations safely\"\n- \"Share a database script with another node securely\"\n\n---\n\n# When NOT to Use This Skill\n\n- **Public databases with no authentication** — no credential needed\n- **Local development with no sensitive data** — disposable test DBs\n- **Interactive manual access** — DBeaver / MySQL Workbench etc.\n\n---\n\n# Capability Boundary\n\n## What This Skill Does\n\n- Credential storage pattern (encrypted, in MGC)\n- Local-script pattern (HTTP API for credential retrieval)\n- Multi‑node sealing pattern (`mgc_seal`)\n- Anti-pattern and security guidance\n\n## What This Skill Does NOT Do\n\n- Is NOT a database client\n- Does NOT run SQL directly from AI\n- Does NOT handle schema migrations or backups (those are local scripts)\n\n---\n\n# Prerequisites\n\n1. **Install MGC Blackbox 1.4.10+**:\n   ```bash\n   pip install mgc-blackbox>=1.4.9\n   ```\n2. **Start MGC service**: `mgc` (API at http://127.0.0.1:57219, WebUI at 57218)\n3. **Token file**: `~/.mgc/database/mgc_black_box/.mgc_token`\n4. **Database driver installed**: `mysql-connector-python` / `psycopg2` / `pymysql` / etc.\n\n> **Sandbox mode (1.4.9+)**: When running inside a sandbox Agent (Trae Work / Workbuddy), install MGC in the system environment; otherwise MCP operations may be limited — in that case, call FastAPI directly at `/api/mgc/sensitive/run`.\n\n---\n\n# Complete Example: Zero‑Exposure Database Workflow\n\n## Step 1: Store Database Credentials (user, via WebUI or `mgc_save`)\n\n> Credentials should be stored by the user via WebUI (browser or `mgc_open_webui`) or by AI on explicit user instruction. AI must never read them back via `mgc_get`.\n\n### MySQL\n\n```\nTool: mgc_save\nParameters:\n  info_type:   \"config\"\n  info_owner:  \"my_mysql_prod\"\n  content:     \"{\n    \\\"host\\\": \\\"db.example.com\\\",\n    \\\"port\\\": 3306,\n    \\\"database\\\": \\\"production_db\\\",\n    \\\"user\\\": \\\"app_user\\\",\n    \\\"password\\\": \\\"your_secure_password\\\"\n  }\"\n```\n\n### PostgreSQL\n\n```\nTool: mgc_save\nParameters:\n  info_type:   \"config\"\n  info_owner:  \"my_postgres_prod\"\n  content:     \"{\n    \\\"host\\\": \\\"db.example.com\\\",\n    \\\"port\\\": 5432,\n    \\\"database\\\": \\\"production_db\\\",\n    \\\"user\\\": \\\"app_user\\\",\n    \\\"password\\\": \\\"your_secure_password\\\",\n    \\\"sslmode\\\": \\\"require\\\"\n  }\"\n```\n\n### SQL Server\n\n```\nTool: mgc_save\nParameters:\n  info_type:   \"config\"\n  info_owner:  \"my_sqlserver_prod\"\n  content:     \"{\n    \\\"host\\\": \\\"db.example.com\\\",\n    \\\"port\\\": 1433,\n    \\\"database\\\": \\\"production_db\\\",\n    \\\"user\\\": \\\"app_user\\\",\n    \\\"password\\\": \\\"your_secure_password\\\"\n  }\"\n```\n\n> **Rotating credentials**: call `mgc_save` again with the same `info_type`/`info_owner` AND `update_if_exists=true`. The old entry is replaced; scripts using the same reference will pick up the new credentials automatically.\n\n## Step 2: Reference Credentials in Your Script\n\n```\n# In your database script (stored as MGC script):\nMGC_CREDENTIAL_REF = \"my_mysql_prod\"   # info_owner only; no password here\n```\n\n## Step 3: Local Script Retrieves Credentials via HTTP API\n\n```python\nimport os\nimport requests\nimport json\n\nMGC_BASE_URL = \"http://127.0.0.1:57219\"\nTOKEN_FILE = os.path.expanduser(\"~/.mgc/database/mgc_black_box/.mgc_token\")\n\ndef get_credentials(info_owner, info_type=\"config\"):\n    \"\"\"Read credentials via HTTP API. Script-internal only; AI never calls this.\"\"\"\n    if not os.path.exists(TOKEN_FILE):\n        raise RuntimeError(\"MGC token file missing\")\n    with open(TOKEN_FILE, \"r\") as f:\n        token = f.read().strip()\n\n    url = f\"{MGC_BASE_URL}/api/mgc/sensitive/get\"\n    headers = {\"X-MGC-Token\": token, \"Content-Type\": \"application/json\"}\n    data = {\"info_type\": info_type, \"info_owner\": info_owner, \"action\": \"run\"}\n    resp = requests.post(url, json=data, headers=headers, timeout=10)\n    resp.raise_for_status()\n    result = resp.json()\n    if isinstance(result, str):\n        return json.loads(result)\n    return result.get(\"data\", {}).get(\"data_field\", {})\n```\n\n## Step 4: Local Script Connects and Executes SQL\n\n```python\nimport argparse\nimport mysql.connector\n\ndef main():\n    parser = argparse.ArgumentParser()\n    parser.add_argument(\"--credential_ref\", default=\"my_mysql_prod\")\n    parser.add_argument(\"--sql\", required=True)\n    args, _ = parser.parse_known_args()\n\n    creds = get_credentials(args.credential_ref)\n\n    conn = mysql.connector.connect(\n        host=creds[\"host\"],\n        port=creds[\"port\"],\n        database=creds[\"database\"],\n        user=creds[\"user\"],\n        password=creds[\"password\"],\n    )\n    cursor = conn.cursor()\n    cursor.execute(args.sql)\n    rows = cursor.fetchall()\n    cursor.close()\n    conn.close()\n\n    # Write results to file so AI can read them via mgc_run output path\n    import datetime\n    out = os.path.expanduser(f\"~/mgc_outputs/db_{datetime.datetime.now().strftime('%Y%m%d_%H%M%S')}.txt\")\n    os.makedirs(os.path.dirname(out), exist_ok=True)\n    with open(out, \"w\", encoding=\"utf-8\") as f:\n        for row in rows:\n            f.write(str(row) + \"\\n\")\n    print(f\"RESULT_FILE:{out}\")  # mgc_run returns this stdout\n```\n\n## Step 5: Store the Script and Execute\n\n```python\n# 5a. Script Agent stores the script in MGC\nmgc_save(\n    info_type=\"script\",\n    info_owner=\"mysql_query_v1\",\n    ext01=\"python\",\n    content=\"<script body from steps 3-4>\",\n    update_if_exists=True\n)\n# MGC 1.4.10 auto-parses argparse literal defaults into ext02\n\n# 5b. Executor Agent runs the script (1.4.7+ blackbox)\nresult = mgc_run(\n    info_type=\"script\",\n    info_owner=\"mysql_query_v1\",\n    diff_1=\"v1\",                  # schema-required differentiation field; any non-empty string works for a single entry\n    ext02='[\"--sql\", \"SELECT 1\"]' # JSON array string, NOT dict\n)\n# Returns: {\"pid\": 12345, \"status\": \"started\"}\n# Read the result file printed on stdout (if mgc returned it via the file output convention).\n# AI never sees the password.\n```\n\n---\n\n# Multi‑Node Example: Sealing Database Scripts (1.4.10)\n\n### Node A: Seal the database script\n\n```python\n# Get Node B's public key (multi-line PEM, real \\n)\nnode_pub = mgc_get(info_type=\"__NODE_PUB__\", info_owner=\"__NODE_PUB__\")\n\n# Store original script first\nmgc_save(\n    info_type=\"script\",\n    info_owner=\"mysql_backup_v1\",\n    ext01=\"python\",\n    content=\"<script body>\"\n)\n# 1.4.10 auto-fills ext02 from argparse literal defaults\n\n# Seal with Node B's public key\nsealed = mgc_seal(\n    info_owner=\"mysql_backup_v1\",\n    ext04=node_pub\n)\n# sealed = {content, ext_01, ext_02, ext_03}\n# ⚠️ ext04 MUST be multi-line PEM with real newlines\n```\n\n### Node B: Store and execute the sealed capsule\n\n```python\n# Store the sealed capsule (must include ext02 from source)\nmgc_save(\n    info_type=\"script\",\n    info_owner=\"mysql_backup_v1\",\n    ext01=sealed[\"ext_01\"],\n    ext02=sealed[\"ext_02\"],            # default args from source argparse\n    content=sealed[\"content\"],\n    ext03=sealed[\"ext_03\"],            # RSA-encrypted AES key (only Node B can decrypt)\n    update_if_exists=True\n)\n\n# Execute via mgc_run (1.4.7+)\nmgc_run(\n    info_type=\"script\",\n    info_owner=\"mysql_backup_v1\",\n    diff_1=\"v1\",                       # schema-required; any non-empty string works for a single entry\n    ext02='[\"--output-dir\", \"/backup\"]'\n)\n# Node B executes with its own private key; credentials are read from Node B's local MGC.\n```\n\n> **Credential consistency**: Node B must also store the DB credential with the **same `info_type`/`info_owner`** as Node A. Otherwise the sealed script will fail to find credentials.\n\n---\n\n# MCP Tools Reference\n\n| Tool | Purpose | Notes |\n|------|---------|-------|\n| `mgc_save` | Store credentials / scripts | `info_type=\"config\"` for credentials, `\"script\"` for scripts |\n| `mgc_run` | Blackbox script execution (1.4.7+) | `ext02` MUST be a JSON array string; `diff_1` is schema-required (any non-empty string for a single entry) |\n| `mgc_list` | List entries (exact match) | metadata only, no plaintext |\n| `mgc_find` | Fuzzy search (1.4.10) | `match_mode`: substring/prefix/suffix/exact |\n| `mgc_seal` | Seal script for target node | `ext04` MUST be multi-line PEM with real newlines |\n| `mgc_open_webui` | Open WebUI for user to store credentials | browser opens automatically |\n| ~~`mgc_get`~~ | ~~DO NOT USE FROM AI~~ | Returns plaintext — breaks zero‑exposure |\n\n---\n\n# Quick Reference: AI Behaviour Rules\n\nWhen this skill is active, the AI MUST:\n\n- ✅ **Use `mgc_run`** to execute database scripts; AI never touches plaintext\n- ✅ **Use `mgc_find`** to locate available database scripts (`match_mode=\"substring\"`)\n- ✅ **Use `mgc_open_webui`** to help user store credentials\n- ✅ Reference scripts by `info_owner`/`diff_1` only; never include credentials in prompts\n- ❌ **Never call `mgc_get`** — returns plaintext\n- ❌ **Never embed credentials** in SKILL.md, prompts, or AI context\n- ❌ **Never ask the user** to paste the password in chat\n\n---\n\n# FAQ\n\n## MGC Related\n\n**Q: What if MGC is not installed?**\nA: `pip install mgc-blackbox>=1.4.9`. Requires Python 3.10+.\n\n**Q: What if MGC is not running?**\nA: Start with `mgc`. WebUI at http://127.0.0.1:57218, API at http://127.0.0.1:57219.\n\n**Q: Port 57219 is already in use?**\nA: Stop other apps on that port, or run MGC with a different port.\n\n**Q: How do I check MGC version?**\nA: `mgc --status` (1.4.9+). Also shown in WebUI's Settings panel.\n\n## Credential Management\n\n**Q: How do I update database credentials?**\nA: Call `mgc_save` with the same `info_type`/`info_owner` AND `update_if_exists=true`. The old entry is replaced.\n\n**Q: How do I manage multiple databases?**\nA: Use different `info_owner` per database: `my_mysql_prod`, `my_postgres_dev`, etc.\n\n**Q: How do I rotate database credentials?**\nA: 1) Update in DB; 2) `mgc_save(..., update_if_exists=true)` with new credentials; 3) Scripts auto-pick up on next run.\n\n**Q: What if credentials are not found?**\nA: 1) Verify `info_owner` exactly (case-sensitive); 2) `mgc_list` to check; 3) `mgc_find` for fuzzy lookup.\n\n## Security\n\n**Q: Can AI read credentials from MGC?**\nA: **No — never call `mgc_get` from AI.** `mgc_get` returns plaintext and breaks zero‑exposure. Credentials must be read by local scripts via HTTP API inside MGC blackbox execution.\n\n**Q: What if AI accidentally logs credentials?**\nA: Local scripts must: never `print`/`log` password values; only log non-sensitive info (host, query, row count).\n\n**Q: Is HTTP API access to credentials safe?**\nA: Yes — HTTP API is bound to localhost (127.0.0.1), requires the MGC token from `~/.mgc/database/mgc_black_box/.mgc_token`. The script is inside MGC blackbox and the AI never sees the response.\n\n## Multi‑Node\n\n**Q: How to share a database script across nodes?**\nA: 1) Node A stores script; 2) `mgc_seal(info_owner=..., ext04=node_b_pubkey)`; 3) Node B stores capsule with `ext02`/`ext03`; 4) Node B calls `mgc_run`.\n\n**Q: Can I seal for multiple nodes?**\nA: Not in one call — seal separately for each node. Use `mgc_find` to track which nodes have copies.\n\n---\n\n# Anti‑Patterns\n\n### ❌ AI calling mgc_get to retrieve credentials\n\n```python\n# WRONG — breaks zero‑exposure, password enters AI context\ncreds = mgc_get(info_type=\"config\", info_owner=\"my_mysql_prod\")\nprint(creds[\"password\"])  # NEVER\n```\n\n**Correct**: AI only calls `mgc_run`; the script internally uses HTTP API.\n\n---\n\n### ❌ Hardcoding password in script\n\n```python\n# WRONG\ndef connect():\n    return pymysql.connect(password=\"secret_password\")\n```\n\n**Correct**: Read from MGC via HTTP API; password is never in source code.\n\n---\n\n### ❌ Embedding connection string in SKILL.md\n\n```markdown\n# WRONG\n- Host: db.example.com\n- Password: my_secret_password\n```\n\n**Correct**:\n```markdown\nReference: info_owner=\"my_mysql_prod\"\nCredentials stored encrypted; AI never sees them.\n```\n\n---\n\n### ❌ Passing password as mgc_run parameter\n\n```python\n# WRONG\nmgc_run(info_owner=\"query\", ext02=json.dumps({\"password\": \"...\"}))\n```\n\n**Correct**: Password is `info_type=\"config\"` stored separately; script reads it via HTTP API inside blackbox.\n\n---\n\n### ❌ Logging credentials\n\n```python\n# WRONG\nlogger.info(f\"Connecting with password: {creds['password']}\")\n```\n\n**Correct**:\n```python\nlogger.info(f\"Connecting to {creds['host']}:{creds['port']}\")  # No password\n```\n\n---\n\n### ❌ Writing credentials to disk\n\n```bash\n# WRONG\necho \"password=secret\" > db_credentials.txt\n```\n\n**Correct**: Store in MGC; never write credentials to plain files.\n\n---\n\n# Troubleshooting\n\n## Error: \"Credential not found\"\n\n1. Verify `info_owner` matches exactly (case-sensitive)\n2. `mgc_find(info_owner=\"...\", match_mode=\"substring\")` to locate\n3. `mgc_list()` to enumerate all entries\n\n## Error: \"Update not allowed\" / \"Entry exists\"\n\n`mgc_save` requires `update_if_exists=true` to overwrite by default (1.4.10 strictness).\n\n## Error: \"Database connection failed\"\n\n1. Verify credentials are correct (test locally outside MGC)\n2. Check DB server running\n3. Verify network/firewall to DB host\n4. Verify port (MySQL: 3306, PostgreSQL: 5432, SQL Server: 1433)\n\n## Error: \"Invalid PEM format\" (during mgc_seal)\n\n`ext04` must be multi-line PEM with real newlines. Copy verbatim from `mgc_get(info_type='__NODE_PUB__')`.\n\n## Error: \"dynamic_args_detected\" (when saving script)\n\nScript uses dynamic argparse defaults (`datetime.now()`, `os.path.expanduser()`). Switch to literal defaults or pass `ext02` manually when calling `mgc_run`.\n\n## Error: \"args_not_recognized\" (during mgc_run)\n\nSource script's argparse did not recognize the args passed via `ext02`. Check `add_argument` definitions and the `ext02` JSON array.\n\n## Error: \"MGC not running\"\n\n1. `mgc` in a terminal\n2. Check http://127.0.0.1:57219 responds\n3. Verify token file: `~/.mgc/database/mgc_black_box/.mgc_token`\n\n## Error: \"MCP tool call failed\"\n\n1. Confirm MGC ≥ 1.4.9; upgrade via WebUI Settings or `pip install --upgrade mgc-blackbox`\n2. Verify MCP server config has `PYTHONIOENCODING=utf-8` env (Windows)\n\n---\n\n# Advanced Scenarios\n\n## Multi‑Database Credential Management\n\nUse distinct `info_owner` per database; use `mgc_find(info_owner=\"my_\", match_mode=\"prefix\")` to enumerate.\n\n## Credential Rotation\n\n1. Generate new credentials in the DB\n2. `mgc_save(info_type=\"config\", info_owner=\"...\", update_if_exists=true, content=\"<new>\")`\n3. No code change — scripts auto-pick up new credentials\n\n## Credential Versioning\n\nUse `info_owner` suffixes (`my_mysql_prod_v1`, `my_mysql_prod_v2`) if you need rollback. Switch scripts' `info_owner` reference atomically.\n\n## Cross-Node Script + Credential Consistency\n\nWhen sealing scripts across nodes, both the script capsule AND the credential entry must be present on the target node. Use the same `info_type`/`info_owner` for credentials on both nodes.\n\n---\n\n# Security Best Practices\n\n1. AI never calls `mgc_get`; credentials stay in MGC.\n2. Use MGC for all credential storage.\n3. Rotate credentials regularly.\n4. Use separate credentials per environment (dev/staging/prod).\n5. Enable SSL/TLS for database connections (`sslmode=require` for PostgreSQL).\n6. Limit DB user permissions to minimum required.\n7. Never log credentials; only log host/query/row count.\n8. Use `mgc_seal` for cross-node script distribution; keep credentials local to each node.\n\n---\n\n# Example Directory Structure\n\n```\ndatabase_skill/\n  manifest.json\n  SKILL.md\n  README.md\n  examples/\n    mysql_query.py        # local script template\n    postgres_backup.py    # backup template\n    connection_pool.py    # pooling template\n```\n\n---\n\n# Template: Local Database Script (1.4.10)\n\n```python\n\"\"\"Database script template. Store as MGC script; execute via mgc_run.\"\"\"\n\nimport os\nimport json\nimport argparse\nimport requests\nimport datetime\n\nMGC_BASE_URL = \"http://127.0.0.1:57219\"\nTOKEN_FILE = os.path.expanduser(\"~/.mgc/database/mgc_black_box/.mgc_token\")\n\n\ndef get_credentials(info_owner, info_type=\"config\"):\n    \"\"\"Read credentials from MGC via HTTP API. Script-internal only.\"\"\"\n    if not os.path.exists(TOKEN_FILE):\n        raise RuntimeError(\"MGC token file missing\")\n    with open(TOKEN_FILE, \"r\") as f:\n        token = f.read().strip()\n    url = f\"{MGC_BASE_URL}/api/mgc/sensitive/get\"\n    headers = {\"X-MGC-Token\": token, \"Content-Type\": \"application/json\"}\n    resp = requests.post(\n        url,\n        json={\"info_type\": info_type, \"info_owner\": info_owner, \"action\": \"run\"},\n        headers=headers,\n        timeout=10,\n    )\n    resp.raise_for_status()\n    result = resp.json()\n    if isinstance(result, str):\n        return json.loads(result)\n    return result.get(\"data\", {}).get(\"data_field\", {})\n\n\ndef main():\n    # ✅ Literal defaults only — MGC 1.4.10 auto-parses into ext02\n    parser = argparse.ArgumentParser()\n    parser.add_argument(\"--credential_ref\", default=\"my_mysql_prod\")\n    parser.add_argument(\"--sql\", default=\"SELECT 1\")\n    args, _ = parser.parse_known_args()  # ✅ parse_known_args avoids exit on unknown params\n\n    creds = get_credentials(args.credential_ref)\n\n    import mysql.connector  # pip install mysql-connector-python\n    conn = mysql.connector.connect(\n        host=creds[\"host\"],\n        port=creds[\"port\"],\n        database=creds[\"database\"],\n        user=creds[\"user\"],\n        password=creds[\"password\"],\n    )\n    try:\n        cursor = conn.cursor()\n        cursor.execute(args.sql)\n        rows = cursor.fetchall()\n        cursor.close()\n    finally:\n        conn.close()\n\n    out_dir = os.path.expanduser(\"~/mgc_outputs\")\n    os.makedirs(out_dir, exist_ok=True)\n    out_path = os.path.join(\n        out_dir, f\"db_{datetime.datetime.now().strftime('%Y%m%d_%H%M%S')}.txt\"\n    )\n    with open(out_path, \"w\", encoding=\"utf-8\") as f:\n        for row in rows:\n            f.write(str(row) + \"\\n\")\n    print(f\"RESULT_FILE:{out_path}\")\n\n\nif __name__ == \"__main__\":\n    main()\n```\n\n> This template is meant to be stored in MGC as a script (`mgc_save`) and executed by AI via `mgc_run`. The AI provides `--sql` via `ext02` JSON array string; credentials are read inside MGC blackbox; AI only sees the result file.\n\n---\n\n# Template: SKILL.md for a new database skill\n\n```markdown\n---\n\nspec: usk/3.0\nid: your_db_skill_id\nversion: 1.0.0\nname: Your Database Skill\ndescription: Brief description\nauthor: Your Name\nlicense: MIT\ntags: database, mgc, zero-exposure\nplatform_compatibility: windows, macos, linux\n\n---\n\n# Overview\n\nWhat this skill does.\n\n# Prerequisites\n\n- MGC Blackbox ≥ 1.4.9\n- Store database credentials in MGC (info_owner: \"your_reference\")\n- Install database driver\n\n# Usage\n\nHow to use this skill.\n\n# Database Credentials\n\n- info_type: \"config\"\n- info_owner: \"your_reference\"\n- Required fields: host, port, database, user, password\n\n# Security\n\nThis skill uses Zero‑Exposure design.\nCredentials are stored in MGC and read by local scripts; AI never sees plaintext.\n\n# Entrypoint\n\nDescribe how to use this skill.\n```\n\n---\n\n# License\n\nMIT\n\nFile v1.2.1:README.md\n\n# Database Credential Security (Zero‑Exposure Edition)\n\nSecure database credential management using MGC Blackbox 1.4.10. Supports MySQL, PostgreSQL, SQLite, MariaDB and more.\n\n## What's New in v1.2.0\n\n- **True Zero‑Exposure**: AI calls `mgc_run` (blackbox execution); local scripts read credentials via HTTP API. **AI never sees plaintext.**\n- **Removed `mgc_get` from AI flow** — credentials stay encrypted in MGC.\n- **`mgc_find` fuzzy search** (1.4.10) — locate scripts/credentials by partial owner.\n- **`update_if_exists=true`** — clean credential rotation.\n- **Multi‑node sealing** updated for 1.4.10 `ext02`/`ext03` auto‑packaging.\n- **Sandbox mode note** for 1.4.9+.\n\n## What This Skill Does\n\n- Pattern for encrypted credential storage in MGC\n- Pattern for local scripts retrieving credentials via HTTP API\n- Pattern for `mgc_seal` cross‑node script distribution\n- Anti‑patterns and security guidance\n\nThis skill is documentation‑only and contains **no executable code** (safe for automatic approval).\n\n## Prerequisites\n\n- Python 3.10+\n- `pip install mgc-blackbox>=1.4.9`\n- MGC service running (`mgc`)\n- Database driver (`mysql-connector-python`, `psycopg2`, etc.)\n\n## Quick Start\n\n### 1. Install MGC\n\n```bash\npip install mgc-blackbox>=1.4.9\nmgc\n```\n\n### 2. Store Database Credentials (via WebUI)\n\nOpen WebUI → Add Entry → `info_type=\"config\"`, `info_owner=\"my_mysql_prod\"`, content is JSON with `host/port/database/user/password`.\n\nOr AI can store on explicit user instruction via `mgc_save`.\n\n### 3. Reference Credentials in Your Script\n\nThe script references the credential by `info_owner` only — never embeds the password.\n\n### 4. Execute via `mgc_run`\n\n```python\nresult = mgc_run(\n    info_type=\"script\",\n    info_owner=\"mysql_query_v1\",\n    diff_1=\"v1\",  # schema-required; any non-empty string works for a single entry\n    ext02='[\"--sql\", \"SELECT 1\"]'\n)\n# Returns pid+status; password NEVER enters AI context.\n```\n\n## MCP Tools\n\n| Tool | Purpose |\n|------|---------|\n| `mgc_save` | Store credentials / scripts |\n| `mgc_run` | Blackbox script execution (1.4.7+) |\n| `mgc_list` | List entries (exact match) |\n| `mgc_find` | Fuzzy search (1.4.10 new) |\n| `mgc_seal` | Encrypt scripts for multi‑node execution |\n| `mgc_open_webui` | Open WebUI for user to store credentials |\n\n> ❌ AI must NOT call `mgc_get` — it returns plaintext and breaks zero‑exposure.\n\n## When to Use This Skill\n\n- Production environments with sensitive data\n- Automation tasks requiring database access\n- Multi‑node collaboration via `mgc_seal`\n- AI needs DB access but must not see passwords\n\n## When NOT to Use This Skill\n\n- Public databases with no authentication\n- Local development with mock data\n- Interactive manual database access (DBeaver / MySQL Workbench)\n\n## Security\n\n- Credentials never exposed to AI\n- Encrypted storage via MGC\n- Local scripts retrieve credentials via HTTP API inside blackbox\n- No plaintext in logs\n- Separate credentials per environment\n\n## License\n\nMIT\n\nFile v1.2.1:_meta.json\n\n{\n  \"ownerId\": \"kn7dbqpp9139vnzrg035qhwfk18947vg\",\n  \"slug\": \"mgc-database-security\",\n  \"version\": \"1.2.1\",\n  \"publishedAt\": 1787034909436\n}\n\nFile v1.2.1:skill-card.md\n\n## Description:\n\nSecure database credential management using MGC Blackbox 1.4.10, with encrypted storage and local runtime credential retrieval so agents can use database workflows without seeing plaintext credentials.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[zkeviny](https://clawhub.ai/user/zkeviny)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and engineers use this skill to design database automation that stores credentials in MGC Blackbox, executes local database scripts through blackbox flows, and keeps plaintext credentials out of agent context.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Database automation can run queries with stored credentials and may expose sensitive query results through files or agent context.\n\nMitigation: Use low-privilege, read-only database accounts by default, require explicit approval for writes or migrations, and avoid sending raw sensitive query results into agent context or persistent plaintext files.\n\nRisk: The skill depends on MGC Blackbox behavior and sealed scripts for high-impact local database operations.\n\nMitigation: Pin and review the MGC dependency, restrict which scripts and credential references can run, and review local scripts before execution.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/zkeviny/skills/mgc-database-security)\n- [Artifact README](artifact/README.md)\n- [Artifact skill definition](artifact/SKILL.md)\n\n## Skill Output:\n\n**Output Type(s):** [Guidance, Markdown, Code, Shell commands, Configuration]\n\n**Output Format:** [Markdown guidance with inline code, shell commands, and MGC tool-call examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Documentation-only skill; generated agent outputs may include local script patterns and database credential handling guidance.]\n\n## Skill Version(s):\n\n1.2.1 (source: server release metadata; artifact frontmatter lists 1.2.0)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v1.2.1:manifest.json\n\n{\n  \"id\": \"mgc_database_security\",\n  \"version\": \"1.2.0\",\n  \"name\": \"Database Credential Security (Zero‑Exposure Edition)\",\n  \"description\": \"Secure database credential management using MGC Blackbox 1.4.10. Supports MySQL, PostgreSQL, SQLite, MariaDB and other databases. Credentials are stored encrypted; local scripts retrieve them via HTTP API at runtime, while AI agents never touch plaintext (true zero‑exposure via mgc_run blackbox execution).\",\n  \"author\": \"MirginCipher Team\",\n  \"license\": \"MIT\",\n  \"category\": \"Developer Tools\",\n  \"tags\": [\"database\", \"mysql\", \"postgresql\", \"sqlite\", \"mariadb\", \"security\", \"credential-management\", \"zero-exposure\", \"mgc\", \"mgc_run\", \"mgc_find\"],\n  \"platform_compatibility\": [\"windows\", \"macos\", \"linux\"],\n  \"source\": \"local\",\n  \"skills\": [\n    {\n      \"name\": \"mysql_security\",\n      \"description\": \"Manage MySQL credentials securely using MGC Blackbox\",\n      \"parameters\": {}\n    }\n  ],\n  \"mcp_tools\": [\"mgc_save\", \"mgc_run\", \"mgc_list\", \"mgc_find\", \"mgc_seal\", \"mgc_open_webui\"],\n  \"install\": {\n    \"pip\": [\"mgc-blackbox>=1.4.10\"],\n    \"mcp\": [\"mgc\"]\n  },\n  \"security\": {\n    \"storage\": \"MGC Blackbox (encrypted)\",\n    \"zero_exposure\": true,\n    \"no_plaintext\": true,\n    \"no_executable_code\": true,\n    \"note\": \"AI agents must NEVER call mgc_get to retrieve credentials. Credentials are read by local scripts inside MGC blackbox execution via mgc_run; AI only sees SQL results.\"\n  },\n  \"changelog\": [\n    {\n      \"version\": \"1.2.0\",\n      \"changes\": [\n        \"Upgraded to adapt to MGC 1.4.10\",\n        \"Refactored zero-exposure flow: AI calls mgc_run, local script reads config via HTTP API; credentials never enter AI context\",\n        \"Replaced mgc_get with mgc_run for executing sealed scripts (1.4.7+ blackbox)\",\n        \"Added mgc_find (1.4.10 fuzzy search) and mgc_open_webui to mcp_tools; removed mgc_get\",\n        \"Documented mgc_seal ext02/ext03 packaging (1.4.10 auto-parse) and multi-line PEM requirement for ext04\",\n        \"Added update_if_exists=true for credential rotation\",\n        \"Added 1.4.9 sandbox mode note\",\n        \"Updated MGC main skill doc reference to WebUI MGC Skills button (1.4.7+)\",\n        \"Templates updated with parse_known_args and JSON array ext02 contract\"\n      ]\n    },\n    {\n      \"version\": \"1.1.0\",\n      \"changes\": [\n        \"Added complete example section with workflow templates\",\n        \"Added comprehensive troubleshooting section\",\n        \"Added FAQ section\",\n        \"Added anti-patterns section\",\n        \"Added when-to-use / when-not-to-use sections\",\n        \"Added capability boundary explanation\",\n        \"Added advanced scenarios section\",\n        \"Added templates for SKILL.md and local scripts\"\n      ]\n    },\n    {\n      \"version\": \"1.0.1\",\n      \"changes\": [\n        \"Updated to emphasize MCP tools over CLI\"\n      ]\n    },\n    {\n      \"version\": \"1.0.0\",\n      \"changes\": [\n        \"Initial release with MySQL zero-exposure pattern\"\n      ]\n    }\n  ]\n}\n\nArchive v1.2.0: 5 files, 10411 bytes\n\nFiles: manifest.json (2051b), README.md (2584b), skill-card.md (2517b), SKILL.md (19893b), _meta.json (140b)\n\nFile v1.2.0:SKILL.md\n\n---\n\nspec: usk/3.0\nid: mgc_database_security\nversion: 1.2.0\nname: Database Credential Security (Zero‑Exposure Edition)\ndescription: Secure database credential management using MGC Blackbox. Supports MySQL, PostgreSQL, SQLite, MariaDB and other databases. Store credentials locally in encrypted form, retrieve at runtime without exposing to AI models. Requires MGC 1.4.7+.\nauthor: MirginCipher Team\nlicense: MIT\ntags: database, mysql, postgresql, sqlite, mariadb, security, credential-management, zero-exposure, mgc\nplatform_compatibility: windows, macos, linux\nchangelog:\n  - version: 1.2.0\n    changes:\n      - Requires MGC 1.4.7+ for mgc_run support\n      - Use mgc_run instead of mgc_get action=\"run\"\n  - version: 1.1.0\n    changes:\n      - Added complete example section with workflow templates\n      - Added comprehensive troubleshooting section\n      - Added FAQ section\n      - Added anti‑patterns section with correct practices\n      - Added when to use / when not to use sections\n      - Added capability boundary explanation\n      - Added advanced scenarios section\n      - Added templates for SKILL.md and local scripts\n  - version: 1.0.1\n    changes:\n      - Updated to emphasize MCP tools over CLI\n  - version: 1.0.0\n    changes:\n      - Initial release with database zero-exposure pattern\n\n---\n\n# Overview\n\nDatabase Credential Security is a documentation skill that teaches how to manage database credentials securely using MGC Blackbox. Supports MySQL, PostgreSQL, SQLite, MariaDB and other databases. It enables AI agents to execute database operations without ever exposing database passwords or connection strings to the AI model.\n\nThis skill contains **no executable code** and is safe for automatic approval.\n\n---\n\n# What This Skill Enables\n\nAfter reading this documentation, an AI agent will understand how to:\n\n- Store database credentials (MySQL, PostgreSQL, SQLite, MariaDB, etc.) securely in MGC Blackbox\n- Retrieve credentials at runtime without AI seeing plaintext\n- Execute database queries through local scripts\n- Manage multiple database connections safely\n- Rotate credentials without code changes\n- Seal database scripts for multi‑node execution\n\n---\n\n# When to Use This Skill\n\n## Must Use Cases\n\n1. **Production environments**\n   - Any database access in production requires secure credential management\n   - Prevents credential leakage in logs, prompts, and AI context\n\n2. **Automation tasks**\n   - Scheduled scripts that need database access\n   - CI/CD pipelines that connect to databases\n\n3. **Multi‑node collaboration**\n   - Node A creates a database script, Node B executes it\n   - Use `mgc_seal` to encrypt the script with target node's public key\n\n4. **AI needs database access but must not see passwords**\n   - AI provides SQL statements only\n   - Local scripts handle credential retrieval and execution\n\n## Example Triggers\n\n- \"Connect to MySQL database securely\"\n- \"Execute a SQL query without exposing the password\"\n- \"Create a scheduled backup script for PostgreSQL\"\n- \"Run database migrations safely\"\n- \"Share a database script with another node securely\"\n\n---\n\n# When NOT to Use This Skill\n\nThis skill is NOT needed in these scenarios:\n\n1. **Public databases**\n   - Databases that require no authentication\n   - Read‑only public data sources\n\n2. **Local development with no sensitive data**\n   - Disposable test databases\n   - Demo environments with mock data\n\n3. **Interactive manual access**\n   - When user provides credentials manually each time\n   - Direct database tool usage (DBeaver, MySQL Workbench, etc.)\n\n---\n\n# Capability Boundary\n\nThis skill has specific boundaries that users must understand:\n\n## What This Skill Does\n\n- **Credential storage**: Securely store database credentials in MGC Blackbox\n- **Credential retrieval**: Retrieve credentials at runtime via MCP tools\n- **Pattern guidance**: Provide secure patterns for database credential management\n- **Multi‑node sealing**: Encrypt database scripts for trusted nodes\n\n## What This Skill Does NOT Do\n\n- **NOT a database client**: Cannot connect to databases directly\n- **NOT a SQL executor**: Does not run SQL queries\n- **NOT a migration tool**: Does not handle schema changes\n- **NOT a backup tool**: Does not perform database backups\n\nThe skill provides **credential management only**. All sensitive database operations (connect, query, migrate, backup) must be performed by local scripts.\n\n---\n\n# Prerequisites\n\n1. Install MGC Blackbox: `pip install mgc-blackbox`\n2. Start MGC service: `mgc` (runs at http://127.0.0.1:57219)\n3. Token file: `~/.mgc/database/mgc_black_box/.mgc_token`\n4. Database driver installed (mysql‑connector‑python, psycopg2, etc.)\n\n---\n\n# Complete Example: Full Database Credential Workflow\n\nThis section demonstrates a complete flow from credential storage to secure database operation.\n\n## Step 1: Store Database Credentials\n\n### MySQL Credential Storage\n\n```\nTool: mgc_save\nParameters:\n  info_type:   \"config\"\n  info_owner:  \"my_mysql_prod\"\n  content:     \"{\n    \\\"host\\\": \\\"db.example.com\\\",\n    \\\"port\\\": 3306,\n    \\\"database\\\": \\\"production_db\\\",\n    \\\"user\\\": \\\"app_user\\\",\n    \\\"password\\\": \\\"your_secure_password\\\"\n  }\"\n```\n\n### PostgreSQL Credential Storage\n\n```\nTool: mgc_save\nParameters:\n  info_type:   \"config\"\n  info_owner:  \"my_postgres_prod\"\n  content:     \"{\n    \\\"host\\\": \\\"db.example.com\\\",\n    \\\"port\\\": 5432,\n    \\\"database\\\": \\\"production_db\\\",\n    \\\"user\\\": \\\"app_user\\\",\n    \\\"password\\\": \\\"your_secure_password\\\",\n    \\\"sslmode\\\": \\\"require\\\"\n  }\"\n```\n\n### SQL Server Credential Storage\n\n```\nTool: mgc_save\nParameters:\n  info_type:   \"config\"\n  info_owner:  \"my_sqlserver_prod\"\n  content:     \"{\n    \\\"host\\\": \\\"db.example.com\\\",\n    \\\"port\\\": 1433,\n    \\\"database\\\": \\\"production_db\\\",\n    \\\"user\\\": \\\"app_user\\\",\n    \\\"password\\\": \\\"your_secure_password\\\"\n  }\"\n```\n\n> **Note:** Replace placeholder values with actual database credentials. The `info_owner` value is your reference identifier—you'll use this same value when retrieving credentials.\n\n## Step 2: Reference Credentials in Your Skill\n\n```\n# In your SKILL.md:\n\ndatabase_reference:\n  info_type:  \"config\"\n  info_owner: \"my_mysql_prod\"\n  # The AI never sees actual credentials, only the reference\n```\n\n## Step 3: Retrieve Credentials\n\n```\nTool: mgc_get\nParameters:\n  info_type:  \"config\"\n  info_owner: \"my_mysql_prod\"\n```\n\nThe MCP tool returns the stored JSON content. The AI receives:\n- Host and port (non‑sensitive)\n- Database name (non‑sensitive)\n- Username (may be non‑sensitive)\n- But **never** the password\n\n## Step 4: Execute Database Operation (Conceptual)\n\nA local script performs the actual database operation:\n\n```\n# Conceptual script flow (NOT executable):\n\n1. Call mgc_get with info_owner=\"my_mysql_prod\"\n2. Parse returned JSON for connection parameters\n3. Use database driver to connect\n4. Execute SQL query\n5. Return only query results (no credentials)\n6. NEVER log or expose the password\n```\n\n## Multi‑Node Example: Sealing Database Scripts\n\nWhen Node A needs Node B to execute a database script:\n\n### Node A: Seal the database script\n\n```\nTool: mgc_seal\nParameters:\n  info_type:   \"script\"\n  info_owner:  \"mysql_backup_script\"\n  ext01:       \"python\"\n  ext04:       \"-----BEGIN PUBLIC KEY-----\\n...Node B's public key...\\n-----END PUBLIC KEY-----\"\n```\n\nReturns: Encrypted capsule containing the database script\n\n### Node B: Execute the sealed script\n\n```\nTool: mgc_get\nParameters:\n  info_type:  \"script\"\n  info_owner: \"mysql_backup_script\"\n  action:     \"run\"\n```\n\nNode B uses its private key to decrypt and execute. Node A's database script is never exposed to Node B.\n\n---\n\n# FAQ\n\n## MGC Related\n\n### Q: What if MGC is not installed?\n**A:** Install MGC Blackbox: `pip install mgc-blackbox`\n\n### Q: What if MGC is not running?\n**A:** Start MGC: `mgc` in a terminal. Service runs at http://127.0.0.1:57219\n\n### Q: How do I check if MGC is running?\n**A:** Open http://127.0.0.1:57219 in a browser. If you see a response, MGC is running.\n\n### Q: Port 57219 is already in use\n**A:** Stop other applications using that port, or configure MGC to use a different port.\n\n## Credential Management\n\n### Q: How do I update database credentials?\n**A:** Call `mgc_save` again with the same `info_type` and `info_owner`. The old credentials will be replaced.\n\n### Q: How do I manage multiple databases?\n**A:** Use different `info_owner` values for each database:\n- \"my_mysql_prod\"\n- \"my_postgres_dev\"\n- \"my_mysql_reporting\"\n\n### Q: How do I rotate database credentials?\n**A:**\n1. Update credentials in the database\n2. Call `mgc_save` with new credentials (same `info_owner`)\n3. Local scripts automatically retrieve new credentials on next run\n\n### Q: What if credentials are not found?\n**A:**\n1. Verify `info_owner` matches exactly (case‑sensitive)\n2. Verify `info_type` matches\n3. List all stored credentials: `mgc_list`\n\n## Security\n\n### Q: How do I ensure AI never sees database passwords?\n**A:**\n1. Never include credentials in SKILL.md prompts\n2. Never pass credentials as parameters to AI\n3. Always use MGC to store credentials\n4. Local scripts retrieve credentials directly from MGC\n5. AI only receives non‑sensitive query results\n\n### Q: Can AI read credentials from MGC?\n**A:** Yes, if AI calls `mgc_get`. **Never call mgc_get unless you want AI to process the result.** For zero‑exposure, use local scripts that call MGC, not AI directly.\n\n### Q: What if AI accidentally logs credentials?\n**A:** Ensure your local script:\n- Never prints or logs credential values\n- Only logs non‑sensitive information (query, row count, etc.)\n- Uses secure logging practices\n\n## Multi‑Node Scenarios\n\n### Q: How do I share a database script securely?\n**A:**\n1. Node A creates the database script\n2. Use `mgc_seal` with Node B's public key\n3. Node B decrypts and executes using `mgc_run`\n\n### Q: Can I seal a script for multiple nodes?\n**A:** Currently, `mgc_seal` targets one node at a time. For multiple nodes, seal separately with each node's public key.\n\n---\n\n# Anti‑Patterns\n\n## Common Mistakes and Correct Practices\n\n### ❌ Anti‑Pattern 1: Hardcoding Database Password in Scripts\n\n```python\n# WRONG - Never do this\ndef connect_to_db():\n    connection = pymysql.connect(\n        host=\"db.example.com\",\n        password=\"secret_password\"  # Exposed!\n    )\n```\n\n**Correct Practice:**\n```python\n# RIGHT - Retrieve from MGC\ndef connect_to_db():\n    credentials = get_credentials_from_mgc(\"my_mysql_prod\")\n    connection = pymysql.connect(\n        host=credentials[\"host\"],\n        password=credentials[\"password\"]\n    )\n```\n\n---\n\n### ❌ Anti‑Pattern 2: Exposing Connection String in SKILL.md\n\n```markdown\n# WRONG - In SKILL.md\nUse the following database credentials:\n- Host: db.example.com\n- Password: my_secret_password\n```\n\n**Correct Practice:**\n```markdown\n# RIGHT - In SKILL.md\nDatabase credentials are stored securely in MGC.\nReference: info_owner=\"my_mysql_prod\"\nAI should NOT handle credentials directly.\n```\n\n---\n\n### ❌ Anti‑Pattern 3: Putting Password in ext04\n\n```json\n// WRONG\n{\n  \"info_owner\": \"my_database\",\n  \"ext04\": \"password=secret123\"  // This is NOT for passwords!\n}\n```\n\n**Correct Practice:**\n```json\n// RIGHT\n{\n  \"info_owner\": \"my_database\",\n  \"info_type\": \"config\",\n  \"ext04\": \"-----BEGIN PUBLIC KEY-----\\nNodeB_Public_Key...\\n-----END PUBLIC KEY-----\"\n}\n// ext04 is ONLY for public keys when sealing\n```\n\n---\n\n### ❌ Anti‑Pattern 4: Writing Credentials to Local Files\n\n```bash\n# WRONG\necho \"password=secret\" > db_credentials.txt\n```\n\n**Correct Practice:**\n```bash\n# RIGHT\n# Store in MGC using mgc_save\n# Never write credentials to disk files\n```\n\n---\n\n### ❌ Anti‑Pattern 5: Passing Credentials as Prompt Parameters\n\n```markdown\n# WRONG\nExecute SQL: SELECT * FROM users WHERE password='{user_password}'\n```\n\n**Correct Practice:**\n```markdown\n# RIGHT\nExecute SQL using credentials stored in MGC.\nReference: info_owner=\"my_mysql_prod\"\nThe local script handles credential retrieval.\n```\n\n---\n\n### ❌ Anti‑Pattern 6: Logging Credentials in Database Scripts\n\n```python\n# WRONG\ndef execute_query(sql):\n    creds = get_credentials_from_mgc(\"my_database\")\n    print(f\"Connecting with password: {creds['password']}\")  # Exposed!\n    # ... execute query\n```\n\n**Correct Practice:**\n```python\n# RIGHT\ndef execute_query(sql):\n    creds = get_credentials_from_mgc(\"my_database\")\n    logger.info(f\"Connecting to {creds['host']}\")  # No password logged\n    # ... execute query\n```\n\n---\n\n# Troubleshooting\n\n## Common Errors and Solutions\n\n### Error: \"Credential not found\"\n\n**Symptoms:** `mgc_get` returns empty or error\n\n**Solutions:**\n1. Verify `info_owner` matches exactly (case‑sensitive)\n2. Verify `info_type` matches\n3. List all credentials: `mgc_list`\n4. Re‑store credentials if needed\n\n---\n\n### Error: \"info_type mismatch\"\n\n**Symptoms:** API returns wrong data or error\n\n**Solutions:**\n1. Check the `info_type` used when saving\n2. Use the same `info_type` when retrieving\n3. Common types: \"config\", \"credential\", \"script\"\n\n---\n\n### Error: \"Database connection failed\"\n\n**Symptoms:** Cannot connect to database\n\n**Solutions:**\n1. Verify credentials are correct in MGC\n2. Check database server is running\n3. Verify network connectivity to database host\n4. Check port is correct (MySQL: 3306, PostgreSQL: 5432, SQL Server: 1433)\n5. Verify firewall allows connection\n\n---\n\n### Error: \"Invalid credentials\"\n\n**Symptoms:** Authentication fails when connecting\n\n**Solutions:**\n1. Verify username and password in MGC storage\n2. Check if password was recently changed\n3. Update credentials in MGC using `mgc_save`\n4. Verify user has permission to access the database\n\n---\n\n### Error: \"MGC not running\"\n\n**Symptoms:** Cannot connect to MGC service\n\n**Solutions:**\n1. Start MGC: `mgc` in terminal\n2. Check service URL: http://127.0.0.1:57219\n3. Verify token file exists: `~/.mgc/database/mgc_black_box/.mgc_token`\n4. Restart MGC if needed\n\n---\n\n### Error: \"MCP tool call failed\"\n\n**Symptoms:** Tool execution error\n\n**Solutions:**\n1. Verify MGC is running\n2. Check service URL\n3. Verify token file is readable\n4. Check MCP tool parameters are correct\n\n---\n\n### Error: \"Permission denied\"\n\n**Symptoms:** Cannot access MGC storage\n\n**Solutions:**\n1. Check file permissions on `~/.mgc/`\n2. Verify token file is readable\n3. Run MGC with appropriate permissions\n\n---\n\n# MGC Blackbox API Reference\n\n## Service Endpoint\n\n- Base URL: http://127.0.0.1:57219\n- Token File: ~/.mgc/database/mgc_black_box/.mgc_token\n- Token: String token read from token file, required for all API calls\n\n## Get Credentials API\n\n**Endpoint:** /api/mgc/sensitive/get\n**Method:** POST\n**Headers:**\n- X-MGC-Token: (string token read from token file)\n- Content-Type: application/json\n\n**Body fields:**\n- info_type: \"config\"\n- info_owner: your chosen identifier\n\n**Response fields:**\n- code: status code\n- data.content: JSON string containing stored credentials\n\n## Save Credentials API\n\n**Endpoint:** /api/mgc/sensitive/save\n**Method:** POST\n**Headers:** same as above\n\n**Body fields:**\n- info_type: \"config\"\n- info_owner: your identifier\n- content: JSON string of credentials\n\n---\n\n# Advanced Scenarios\n\n## Multi‑Database Credential Management\n\nManage credentials for multiple databases:\n\n```\n# Storage identifiers:\ninfo_owner: \"my_mysql_prod\"      # MySQL production\ninfo_owner: \"my_postgres_prod\"   # PostgreSQL production\ninfo_owner: \"my_mysql_dev\"       # MySQL development\ninfo_owner: \"my_mysql_test\"      # MySQL testing\n```\n\n## Multi‑Node Database Task Distribution\n\n### Node A: Prepares database operation script\n\n```\nTool: mgc_seal\nParameters:\n  info_type:   \"script\"\n  info_owner:  \"mysql_migration_script\"\n  ext01:       \"python\"\n  ext04:       \"-----BEGIN PUBLIC KEY-----\\nNodeB_Public_Key...\\n-----END PUBLIC KEY-----\"\n```\n\n### Node B: Executes the sealed script\n\n```\nTool: mgc_get\nParameters:\n  info_type:  \"script\"\n  info_owner: \"mysql_migration_script\"\n  action:     \"run\"\n```\n\n## Credential Rotation\n\nRegularly rotate database credentials:\n\n1. **Generate new credentials** in database\n2. **Update MGC storage**:\n   ```\n   Tool: mgc_save\n   Parameters:\n     info_type:   \"config\"\n     info_owner:  \"my_mysql_prod\"\n     content:     \"{new_credentials}\"\n   ```\n3. **No code changes needed** - local scripts automatically use new credentials\n\n## Credential Version Management\n\nTrack credential versions using info_owner suffixes:\n\n```\ninfo_owner: \"my_mysql_prod_v1\"   # Version 1\ninfo_owner: \"my_mysql_prod_v2\"   # Version 2 (after rotation)\n```\n\n---\n\n# Example Directory Structure\n\nWhen creating a database skill:\n\n```\ndatabase_skill/\n  SKILL.md           # Skill definition\n  README.md          # User documentation\n  scripts/           # Local scripts (conceptual)\n    execute_query.py\n    backup.py\n    migrate.py\n```\n\n---\n\n# Security Best Practices\n\n1. **Never embed credentials in code**\n2. **Use MGC for credential storage**\n3. **Retrieve credentials at runtime only**\n4. **Never log or print credentials**\n5. **Rotate credentials regularly**\n6. **Use separate credentials per database**\n7. **Use separate credentials per environment** (dev/staging/prod)\n8. **Enable SSL/TLS for database connections**\n9. **Limit database user permissions** to minimum required\n\n---\n\n# Common Patterns\n\n## Python Database Connection (Conceptual)\n\n```\nimport mysql.connector\n\ndef get_connection(credentials):\n    return mysql.connector.connect(\n        host=credentials[\"host\"],\n        port=credentials[\"port\"],\n        database=credentials[\"database\"],\n        user=credentials[\"user\"],\n        password=credentials[\"password\"]\n    )\n\ndef execute_query(sql):\n    creds = retrieve_from_mgc(\"my_mysql_prod\")\n    conn = get_connection(creds)\n    cursor = conn.cursor()\n    cursor.execute(sql)\n    result = cursor.fetchall()\n    cursor.close()\n    conn.close()\n    return result\n```\n\n---\n\n# Use Cases\n\n- Database administration scripts\n- Automated backup operations\n- Data migration tools\n- Application database access\n- Multiple environment management (dev/staging/prod)\n- Scheduled database operations\n- Multi‑node database task execution\n\n---\n\n# Template: Zero‑Exposure Database SKILL.md\n\nWhen creating a new database skill:\n\n```markdown\n---\n\nspec: usk/3.0\nid: your_skill_id\nversion: 1.0.0\nname: Your Database Skill\ndescription: Brief description\nauthor: Your Name\nlicense: MIT\ntags: database, mgc, zero-exposure\nplatform_compatibility: windows, macos, linux\n\n---\n\n# Overview\n\nWhat this skill does.\n\n# Prerequisites\n\n- Install MGC Blackbox\n- Store database credentials in MGC (info_owner: \"your_reference\")\n- Install required database driver\n\n# Usage\n\nHow to use this skill.\n\n# Database Credentials\n\n- info_type: \"config\"\n- info_owner: \"your_reference\"\n- Required fields: host, port, database, user, password\n\n# Security\n\nThis skill uses Zero‑Exposure design.\nCredentials are stored in MGC, never exposed to AI.\n\n---\n\n# Entrypoint\n\nDescribe how to use this skill.\n```\n\n---\n\n# Template: Database Local Script Structure\n\n```python\n# Template structure (documentation only)\n\nimport json\nimport pymysql  # or psycopg2, pymssql, etc.\n\n# MGC Configuration\nMGC_BASE_URL = \"http://127.0.0.1:57219\"\nTOKEN_FILE = \"~/.mgc/database/mgc_black_box/.mgc_token\"\n\ndef get_mgc_token():\n    # Read token from file\n    pass\n\ndef get_credentials(info_owner, info_type=\"config\"):\n    # Call MGC API to retrieve credentials\n    # Return: dict of credential data\n    pass\n\ndef execute_query(credentials, sql):\n    # Use credentials to connect and execute\n    # NEVER log credential values\n    # Return: query results only\n    pass\n\ndef main():\n    # 1. Get credentials from MGC\n    creds = get_credentials(info_owner=\"your_database_reference\")\n\n    # 2. Execute query\n    result = execute_query(creds, \"SELECT * FROM users\")\n\n    # 3. Return result (not credentials!)\n    print(result)\n\nif __name__ == \"__main__\":\n    main()\n```\n\n---\n\n# License\n\nMIT\n\nFile v1.2.0:README.md\n\n# Database Credential Security (Zero‑Exposure Edition)\n\nSecure database credential management using MGC Blackbox. Supports MySQL, PostgreSQL, SQLite, MariaDB and more.\n\n## What This Skill Does\n\nThis skill provides a pattern for managing database credentials securely:\n- Store credentials encrypted in MGC Blackbox\n- Retrieve at runtime without AI seeing plaintext\n- Execute database operations safely\n- Support multi‑node collaboration via script sealing\n\n## What’s New in v1.1.0\n\n- **Complete Examples**: MySQL, PostgreSQL, SQL Server credential storage\n- **Troubleshooting**: Common errors and solutions\n- **FAQ Section**: Database‑specific common questions\n- **Anti‑Patterns**: Common mistakes and correct practices\n- **When to Use**: Clear guidance on use cases\n- **Capability Boundary**: What this skill does and does not do\n- **Advanced Scenarios**: Multi‑database, credential rotation, version management\n\n---\n\n## Prerequisites\n\n- Python 3.10+\n- pip install mgc-blackbox\n- MGC service running\n- Database driver (mysql‑connector‑python, psycopg2, etc.)\n\n---\n\n## Quick Start\n\n### 1. Install MGC\n\n```\npip install mgc-blackbox\nmgc\n```\n\n### 2. Store Database Credentials\n\nUse `mgc_save` to store credentials:\n\n```\nTool: mgc_save\nParameters:\n  info_type:   \"config\"\n  info_owner:  \"my_mysql_prod\"\n  content:     \"{json_content}\"\n```\n\nSee SKILL.md for complete examples for MySQL, PostgreSQL, SQL Server.\n\n### 3. Use in Your Script\n\nYour local script retrieves credentials from MGC, connects to database, and executes queries - all without exposing credentials to AI.\n\n---\n\n## When to Use This Skill\n\n**Use when:**\n- Production environments with sensitive data\n- Automation tasks requiring database access\n- Multi‑node collaboration (use mgc_seal)\n- AI needs database access but must not see passwords\n\n**Not needed when:**\n- Public databases with no authentication\n- Local development with mock data\n- Interactive manual database access\n\n---\n\n## What's Inside\n\n- Complete credential storage workflow examples\n- Troubleshooting guide\n- FAQ section\n- Anti‑patterns with correct practices\n- Database credential patterns\n- Security best practices\n- SKILL.md and local script templates\n\n---\n\n## MCP Tools\n\n- `mgc_save`: Store credentials\n- `mgc_get`: Retrieve credentials\n- `mgc_list`: List stored credentials\n- `mgc_seal`: Encrypt scripts for multi‑node execution\n\n---\n\n## Security\n\n- Credentials never exposed to AI\n- Encrypted storage via MGC\n- Runtime credential retrieval only\n- No plaintext in logs\n- Separate credentials per environment\n\n---\n\n## License\n\nMIT\n\nFile v1.2.0:_meta.json\n\n{\n  \"ownerId\": \"kn7dbqpp9139vnzrg035qhwfk18947vg\",\n  \"slug\": \"mgc-database-security\",\n  \"version\": \"1.2.0\",\n  \"publishedAt\": 1785395855992\n}\n\nFile v1.2.0:skill-card.md\n\n## Description: <br>\nDatabase Credential Security (Zero‑Exposure Edition) teaches agents how to manage database credentials with MGC Blackbox while using local scripts for database operations. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[zkeviny](https://clawhub.ai/user/zkeviny) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineers use this documentation skill to plan database automation that keeps passwords out of agent prompts by storing credentials in MGC and running database work through trusted local scripts. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The security review found misleading zero-exposure claims and workflows that can expose credentials or execute database scripts. <br>\nMitigation: Review carefully before installing, use only trusted local MGC tooling, and do not let an AI agent call mgc_get for secrets unless those secrets may enter model context. <br>\nRisk: Production database or sealed-script execution can affect sensitive systems. <br>\nMitigation: Require human approval, least-privilege credentials, backups, and script provenance checks before production database or sealed-script execution. <br>\nRisk: Credential-handling examples may expose secrets if implemented with direct agent retrieval or unsafe logging. <br>\nMitigation: Keep credential retrieval inside local scripts, avoid printing or logging credential values, and return only non-sensitive results to the agent. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/zkeviny/skills/mgc-database-security) <br>\n- [Skill documentation](artifact/SKILL.md) <br>\n- [Release README](artifact/README.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [guidance, markdown, code, shell commands, configuration] <br>\n**Output Format:** [Markdown documentation with conceptual code and command examples] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [No executable files are included; examples require trusted local MGC tooling and database drivers.] <br>\n\n## Skill Version(s): <br>\n1.2.0 (source: server release metadata, artifact frontmatter, manifest) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v1.2.0:manifest.json\n\n{\n  \"id\": \"mgc_database_security\",\n  \"version\": \"1.2.0\",\n  \"name\": \"Database Credential Security (Zero‑Exposure Edition)\",\n  \"description\": \"Secure database credential management using MGC Blackbox. Supports MySQL, PostgreSQL, SQLite, MariaDB and other databases. Store credentials locally in encrypted form, retrieve at runtime without exposing to AI models.\",\n  \"author\": \"MirginCipher Team\",\n  \"license\": \"MIT\",\n  \"category\": \"Developer Tools\",\n  \"tags\": [\"database\", \"mysql\", \"postgresql\", \"sqlite\", \"mariadb\", \"security\", \"credential-management\", \"zero-exposure\", \"mgc\"],\n  \"platform_compatibility\": [\"windows\", \"macos\", \"linux\"],\n  \"source\": \"local\",\n  \"skills\": [\n    {\n      \"name\": \"mysql_security\",\n      \"description\": \"Manage MySQL credentials securely using MGC Blackbox\",\n      \"parameters\": {}\n    }\n  ],\n  \"mcp_tools\": [\"mgc_save\", \"mgc_get\", \"mgc_run\", \"mgc_list\", \"mgc_seal\"],\n  \"install\": {\n    \"pip\": [\"mgc-blackbox\"],\n    \"mcp\": [\"mgc\"]\n  },\n  \"security\": {\n    \"storage\": \"MGC Blackbox (encrypted)\",\n    \"zero_exposure\": true,\n    \"no_plaintext\": true,\n    \"no_executable_code\": true\n  },\n  \"changelog\": [\n    {\n      \"version\": \"1.2.0\",\n      \"changes\": [\n        \"Requires MGC 1.4.7+ for mgc_run support\",\n        \"Added mgc_run as recommended tool for script execution\"\n      ]\n    },\n    {\n      \"version\": \"1.1.0\",\n      \"changes\": [\n        \"Added complete example section with workflow templates\",\n        \"Added comprehensive troubleshooting section\",\n        \"Added FAQ section\",\n        \"Added anti‑patterns section with correct practices\",\n        \"Added when to use / when not to use sections\",\n        \"Added capability boundary explanation\",\n        \"Added advanced scenarios section\",\n        \"Added templates for SKILL.md and local scripts\",\n        \"Added mgc_seal to mcp_tools\"\n      ]\n    },\n    {\n      \"version\": \"1.0.1\",\n      \"changes\": [\"Updated to emphasize MCP tools over CLI\"]\n    },\n    {\n      \"version\": \"1.0.0\",\n      \"changes\": [\"Initial release with MySQL zero-exposure pattern\"]\n    }\n  ]\n}\n\nArchive v1.1.0: 5 files, 10265 bytes\n\nFiles: manifest.json (1858b), README.md (2584b), skill-card.md (2485b), SKILL.md (19758b), _meta.json (140b)\n\nFile v1.1.0:SKILL.md\n\n---\n\nspec: usk/3.0\nid: mgc_database_security\nversion: 1.1.0\nname: Database Credential Security (Zero‑Exposure Edition)\ndescription: Secure database credential management using MGC Blackbox. Supports MySQL, PostgreSQL, SQLite, MariaDB and other databases. Store credentials locally in encrypted form, retrieve at runtime without exposing to AI models.\nauthor: MirginCipher Team\nlicense: MIT\ntags: database, mysql, postgresql, sqlite, mariadb, security, credential-management, zero-exposure, mgc\nplatform_compatibility: windows, macos, linux\nchangelog:\n  - version: 1.1.0\n    changes:\n      - Added complete example section with workflow templates\n      - Added comprehensive troubleshooting section\n      - Added FAQ section\n      - Added anti‑patterns section with correct practices\n      - Added when to use / when not to use sections\n      - Added capability boundary explanation\n      - Added advanced scenarios section\n      - Added templates for SKILL.md and local scripts\n  - version: 1.0.1\n    changes:\n      - Updated to emphasize MCP tools over CLI\n  - version: 1.0.0\n    changes:\n      - Initial release with database zero-exposure pattern\n\n---\n\n# Overview\n\nDatabase Credential Security is a documentation skill that teaches how to manage database credentials securely using MGC Blackbox. Supports MySQL, PostgreSQL, SQLite, MariaDB and other databases. It enables AI agents to execute database operations without ever exposing database passwords or connection strings to the AI model.\n\nThis skill contains **no executable code** and is safe for automatic approval.\n\n---\n\n# What This Skill Enables\n\nAfter reading this documentation, an AI agent will understand how to:\n\n- Store database credentials (MySQL, PostgreSQL, SQLite, MariaDB, etc.) securely in MGC Blackbox\n- Retrieve credentials at runtime without AI seeing plaintext\n- Execute database queries through local scripts\n- Manage multiple database connections safely\n- Rotate credentials without code changes\n- Seal database scripts for multi‑node execution\n\n---\n\n# When to Use This Skill\n\n## Must Use Cases\n\n1. **Production environments**\n   - Any database access in production requires secure credential management\n   - Prevents credential leakage in logs, prompts, and AI context\n\n2. **Automation tasks**\n   - Scheduled scripts that need database access\n   - CI/CD pipelines that connect to databases\n\n3. **Multi‑node collaboration**\n   - Node A creates a database script, Node B executes it\n   - Use `mgc_seal` to encrypt the script with target node's public key\n\n4. **AI needs database access but must not see passwords**\n   - AI provides SQL statements only\n   - Local scripts handle credential retrieval and execution\n\n## Example Triggers\n\n- \"Connect to MySQL database securely\"\n- \"Execute a SQL query without exposing the password\"\n- \"Create a scheduled backup script for PostgreSQL\"\n- \"Run database migrations safely\"\n- \"Share a database script with another node securely\"\n\n---\n\n# When NOT to Use This Skill\n\nThis skill is NOT needed in these scenarios:\n\n1. **Public databases**\n   - Databases that require no authentication\n   - Read‑only public data sources\n\n2. **Local development with no sensitive data**\n   - Disposable test databases\n   - Demo environments with mock data\n\n3. **Interactive manual access**\n   - When user provides credentials manually each time\n   - Direct database tool usage (DBeaver, MySQL Workbench, etc.)\n\n---\n\n# Capability Boundary\n\nThis skill has specific boundaries that users must understand:\n\n## What This Skill Does\n\n- **Credential storage**: Securely store database credentials in MGC Blackbox\n- **Credential retrieval**: Retrieve credentials at runtime via MCP tools\n- **Pattern guidance**: Provide secure patterns for database credential management\n- **Multi‑node sealing**: Encrypt database scripts for trusted nodes\n\n## What This Skill Does NOT Do\n\n- **NOT a database client**: Cannot connect to databases directly\n- **NOT a SQL executor**: Does not run SQL queries\n- **NOT a migration tool**: Does not handle schema changes\n- **NOT a backup tool**: Does not perform database backups\n\nThe skill provides **credential management only**. All sensitive database operations (connect, query, migrate, backup) must be performed by local scripts.\n\n---\n\n# Prerequisites\n\n1. Install MGC Blackbox: `pip install mgc-blackbox`\n2. Start MGC service: `mgc` (runs at http://127.0.0.1:57219)\n3. Token file: `~/.mgc/database/mgc_black_box/.mgc_token`\n4. Database driver installed (mysql‑connector‑python, psycopg2, etc.)\n\n---\n\n# Complete Example: Full Database Credential Workflow\n\nThis section demonstrates a complete flow from credential storage to secure database operation.\n\n## Step 1: Store Database Credentials\n\n### MySQL Credential Storage\n\n```\nTool: mgc_save\nParameters:\n  info_type:   \"config\"\n  info_owner:  \"my_mysql_prod\"\n  content:     \"{\n    \\\"host\\\": \\\"db.example.com\\\",\n    \\\"port\\\": 3306,\n    \\\"database\\\": \\\"production_db\\\",\n    \\\"user\\\": \\\"app_user\\\",\n    \\\"password\\\": \\\"your_secure_password\\\"\n  }\"\n```\n\n### PostgreSQL Credential Storage\n\n```\nTool: mgc_save\nParameters:\n  info_type:   \"config\"\n  info_owner:  \"my_postgres_prod\"\n  content:     \"{\n    \\\"host\\\": \\\"db.example.com\\\",\n    \\\"port\\\": 5432,\n    \\\"database\\\": \\\"production_db\\\",\n    \\\"user\\\": \\\"app_user\\\",\n    \\\"password\\\": \\\"your_secure_password\\\",\n    \\\"sslmode\\\": \\\"require\\\"\n  }\"\n```\n\n### SQL Server Credential Storage\n\n```\nTool: mgc_save\nParameters:\n  info_type:   \"config\"\n  info_owner:  \"my_sqlserver_prod\"\n  content:     \"{\n    \\\"host\\\": \\\"db.example.com\\\",\n    \\\"port\\\": 1433,\n    \\\"database\\\": \\\"production_db\\\",\n    \\\"user\\\": \\\"app_user\\\",\n    \\\"password\\\": \\\"your_secure_password\\\"\n  }\"\n```\n\n> **Note:** Replace placeholder values with actual database credentials. The `info_owner` value is your reference identifier—you'll use this same value when retrieving credentials.\n\n## Step 2: Reference Credentials in Your Skill\n\n```\n# In your SKILL.md:\n\ndatabase_reference:\n  info_type:  \"config\"\n  info_owner: \"my_mysql_prod\"\n  # The AI never sees actual credentials, only the reference\n```\n\n## Step 3: Retrieve Credentials\n\n```\nTool: mgc_get\nParameters:\n  info_type:  \"config\"\n  info_owner: \"my_mysql_prod\"\n```\n\nThe MCP tool returns the stored JSON content. The AI receives:\n- Host and port (non‑sensitive)\n- Database name (non‑sensitive)\n- Username (may be non‑sensitive)\n- But **never** the password\n\n## Step 4: Execute Database Operation (Conceptual)\n\nA local script performs the actual database operation:\n\n```\n# Conceptual script flow (NOT executable):\n\n1. Call mgc_get with info_owner=\"my_mysql_prod\"\n2. Parse returned JSON for connection parameters\n3. Use database driver to connect\n4. Execute SQL query\n5. Return only query results (no credentials)\n6. NEVER log or expose the password\n```\n\n## Multi‑Node Example: Sealing Database Scripts\n\nWhen Node A needs Node B to execute a database script:\n\n### Node A: Seal the database script\n\n```\nTool: mgc_seal\nParameters:\n  info_type:   \"script\"\n  info_owner:  \"mysql_backup_script\"\n  ext01:       \"python\"\n  ext04:       \"-----BEGIN PUBLIC KEY-----\\n...Node B's public key...\\n-----END PUBLIC KEY-----\"\n```\n\nReturns: Encrypted capsule containing the database script\n\n### Node B: Execute the sealed script\n\n```\nTool: mgc_get\nParameters:\n  info_type:  \"script\"\n  info_owner: \"mysql_backup_script\"\n  action:     \"run\"\n```\n\nNode B uses its private key to decrypt and execute. Node A's database script is never exposed to Node B.\n\n---\n\n# FAQ\n\n## MGC Related\n\n### Q: What if MGC is not installed?\n**A:** Install MGC Blackbox: `pip install mgc-blackbox`\n\n### Q: What if MGC is not running?\n**A:** Start MGC: `mgc` in a terminal. Service runs at http://127.0.0.1:57219\n\n### Q: How do I check if MGC is running?\n**A:** Open http://127.0.0.1:57219 in a browser. If you see a response, MGC is running.\n\n### Q: Port 57219 is already in use\n**A:** Stop other applications using that port, or configure MGC to use a different port.\n\n## Credential Management\n\n### Q: How do I update database credentials?\n**A:** Call `mgc_save` again with the same `info_type` and `info_owner`. The old credentials will be replaced.\n\n### Q: How do I manage multiple databases?\n**A:** Use different `info_owner` values for each database:\n- \"my_mysql_prod\"\n- \"my_postgres_dev\"\n- \"my_mysql_reporting\"\n\n### Q: How do I rotate database credentials?\n**A:**\n1. Update credentials in the database\n2. Call `mgc_save` with new credentials (same `info_owner`)\n3. Local scripts automatically retrieve new credentials on next run\n\n### Q: What if credentials are not found?\n**A:**\n1. Verify `info_owner` matches exactly (case‑sensitive)\n2. Verify `info_type` matches\n3. List all stored credentials: `mgc_list`\n\n## Security\n\n### Q: How do I ensure AI never sees database passwords?\n**A:**\n1. Never include credentials in SKILL.md prompts\n2. Never pass credentials as parameters to AI\n3. Always use MGC to store credentials\n4. Local scripts retrieve credentials directly from MGC\n5. AI only receives non‑sensitive query results\n\n### Q: Can AI read credentials from MGC?\n**A:** Yes, if AI calls `mgc_get`. **Never call mgc_get unless you want AI to process the result.** For zero‑exposure, use local scripts that call MGC, not AI directly.\n\n### Q: What if AI accidentally logs credentials?\n**A:** Ensure your local script:\n- Never prints or logs credential values\n- Only logs non‑sensitive information (query, row count, etc.)\n- Uses secure logging practices\n\n## Multi‑Node Scenarios\n\n### Q: How do I share a database script securely?\n**A:**\n1. Node A creates the database script\n2. Use `mgc_seal` with Node B's public key\n3. Node B decrypts and executes using `mgc_get` with action=\"run\"\n\n### Q: Can I seal a script for multiple nodes?\n**A:** Currently, `mgc_seal` targets one node at a time. For multiple nodes, seal separately with each node's public key.\n\n---\n\n# Anti‑Patterns\n\n## Common Mistakes and Correct Practices\n\n### ❌ Anti‑Pattern 1: Hardcoding Database Password in Scripts\n\n```python\n# WRONG - Never do this\ndef connect_to_db():\n    connection = pymysql.connect(\n        host=\"db.example.com\",\n        password=\"secret_password\"  # Exposed!\n    )\n```\n\n**Correct Practice:**\n```python\n# RIGHT - Retrieve from MGC\ndef connect_to_db():\n    credentials = get_credentials_from_mgc(\"my_mysql_prod\")\n    connection = pymysql.connect(\n        host=credentials[\"host\"],\n        password=credentials[\"password\"]\n    )\n```\n\n---\n\n### ❌ Anti‑Pattern 2: Exposing Connection String in SKILL.md\n\n```markdown\n# WRONG - In SKILL.md\nUse the following database credentials:\n- Host: db.example.com\n- Password: my_secret_password\n```\n\n**Correct Practice:**\n```markdown\n# RIGHT - In SKILL.md\nDatabase credentials are stored securely in MGC.\nReference: info_owner=\"my_mysql_prod\"\nAI should NOT handle credentials directly.\n```\n\n---\n\n### ❌ Anti‑Pattern 3: Putting Password in ext04\n\n```json\n// WRONG\n{\n  \"info_owner\": \"my_database\",\n  \"ext04\": \"password=secret123\"  // This is NOT for passwords!\n}\n```\n\n**Correct Practice:**\n```json\n// RIGHT\n{\n  \"info_owner\": \"my_database\",\n  \"info_type\": \"config\",\n  \"ext04\": \"-----BEGIN PUBLIC KEY-----\\nNodeB_Public_Key...\\n-----END PUBLIC KEY-----\"\n}\n// ext04 is ONLY for public keys when sealing\n```\n\n---\n\n### ❌ Anti‑Pattern 4: Writing Credentials to Local Files\n\n```bash\n# WRONG\necho \"password=secret\" > db_credentials.txt\n```\n\n**Correct Practice:**\n```bash\n# RIGHT\n# Store in MGC using mgc_save\n# Never write credentials to disk files\n```\n\n---\n\n### ❌ Anti‑Pattern 5: Passing Credentials as Prompt Parameters\n\n```markdown\n# WRONG\nExecute SQL: SELECT * FROM users WHERE password='{user_password}'\n```\n\n**Correct Practice:**\n```markdown\n# RIGHT\nExecute SQL using credentials stored in MGC.\nReference: info_owner=\"my_mysql_prod\"\nThe local script handles credential retrieval.\n```\n\n---\n\n### ❌ Anti‑Pattern 6: Logging Credentials in Database Scripts\n\n```python\n# WRONG\ndef execute_query(sql):\n    creds = get_credentials_from_mgc(\"my_database\")\n    print(f\"Connecting with password: {creds['password']}\")  # Exposed!\n    # ... execute query\n```\n\n**Correct Practice:**\n```python\n# RIGHT\ndef execute_query(sql):\n    creds = get_credentials_from_mgc(\"my_database\")\n    logger.info(f\"Connecting to {creds['host']}\")  # No password logged\n    # ... execute query\n```\n\n---\n\n# Troubleshooting\n\n## Common Errors and Solutions\n\n### Error: \"Credential not found\"\n\n**Symptoms:** `mgc_get` returns empty or error\n\n**Solutions:**\n1. Verify `info_owner` matches exactly (case‑sensitive)\n2. Verify `info_type` matches\n3. List all credentials: `mgc_list`\n4. Re‑store credentials if needed\n\n---\n\n### Error: \"info_type mismatch\"\n\n**Symptoms:** API returns wrong data or error\n\n**Solutions:**\n1. Check the `info_type` used when saving\n2. Use the same `info_type` when retrieving\n3. Common types: \"config\", \"credential\", \"script\"\n\n---\n\n### Error: \"Database connection failed\"\n\n**Symptoms:** Cannot connect to database\n\n**Solutions:**\n1. Verify credentials are correct in MGC\n2. Check database server is running\n3. Verify network connectivity to database host\n4. Check port is correct (MySQL: 3306, PostgreSQL: 5432, SQL Server: 1433)\n5. Verify firewall allows connection\n\n---\n\n### Error: \"Invalid credentials\"\n\n**Symptoms:** Authentication fails when connecting\n\n**Solutions:**\n1. Verify username and password in MGC storage\n2. Check if password was recently changed\n3. Update credentials in MGC using `mgc_save`\n4. Verify user has permission to access the database\n\n---\n\n### Error: \"MGC not running\"\n\n**Symptoms:** Cannot connect to MGC service\n\n**Solutions:**\n1. Start MGC: `mgc` in terminal\n2. Check service URL: http://127.0.0.1:57219\n3. Verify token file exists: `~/.mgc/database/mgc_black_box/.mgc_token`\n4. Restart MGC if needed\n\n---\n\n### Error: \"MCP tool call failed\"\n\n**Symptoms:** Tool execution error\n\n**Solutions:**\n1. Verify MGC is running\n2. Check service URL\n3. Verify token file is readable\n4. Check MCP tool parameters are correct\n\n---\n\n### Error: \"Permission denied\"\n\n**Symptoms:** Cannot access MGC storage\n\n**Solutions:**\n1. Check file permissions on `~/.mgc/`\n2. Verify token file is readable\n3. Run MGC with appropriate permissions\n\n---\n\n# MGC Blackbox API Reference\n\n## Service Endpoint\n\n- Base URL: http://127.0.0.1:57219\n- Token File: ~/.mgc/database/mgc_black_box/.mgc_token\n- Token: String token read from token file, required for all API calls\n\n## Get Credentials API\n\n**Endpoint:** /api/mgc/sensitive/get\n**Method:** POST\n**Headers:**\n- X-MGC-Token: (string token read from token file)\n- Content-Type: application/json\n\n**Body fields:**\n- info_type: \"config\"\n- info_owner: your chosen identifier\n\n**Response fields:**\n- code: status code\n- data.content: JSON string containing stored credentials\n\n## Save Credentials API\n\n**Endpoint:** /api/mgc/sensitive/save\n**Method:** POST\n**Headers:** same as above\n\n**Body fields:**\n- info_type: \"config\"\n- info_owner: your identifier\n- content: JSON string of credentials\n\n---\n\n# Advanced Scenarios\n\n## Multi‑Database Credential Management\n\nManage credentials for multiple databases:\n\n```\n# Storage identifiers:\ninfo_owner: \"my_mysql_prod\"      # MySQL production\ninfo_owner: \"my_postgres_prod\"   # PostgreSQL production\ninfo_owner: \"my_mysql_dev\"       # MySQL development\ninfo_owner: \"my_mysql_test\"      # MySQL testing\n```\n\n## Multi‑Node Database Task Distribution\n\n### Node A: Prepares database operation script\n\n```\nTool: mgc_seal\nParameters:\n  info_type:   \"script\"\n  info_owner:  \"mysql_migration_script\"\n  ext01:       \"python\"\n  ext04:       \"-----BEGIN PUBLIC KEY-----\\nNodeB_Public_Key...\\n-----END PUBLIC KEY-----\"\n```\n\n### Node B: Executes the sealed script\n\n```\nTool: mgc_get\nParameters:\n  info_type:  \"script\"\n  info_owner: \"mysql_migration_script\"\n  action:     \"run\"\n```\n\n## Credential Rotation\n\nRegularly rotate database credentials:\n\n1. **Generate new credentials** in database\n2. **Update MGC storage**:\n   ```\n   Tool: mgc_save\n   Parameters:\n     info_type:   \"config\"\n     info_owner:  \"my_mysql_prod\"\n     content:     \"{new_credentials}\"\n   ```\n3. **No code changes needed** - local scripts automatically use new credentials\n\n## Credential Version Management\n\nTrack credential versions using info_owner suffixes:\n\n```\ninfo_owner: \"my_mysql_prod_v1\"   # Version 1\ninfo_owner: \"my_mysql_prod_v2\"   # Version 2 (after rotation)\n```\n\n---\n\n# Example Directory Structure\n\nWhen creating a database skill:\n\n```\ndatabase_skill/\n  SKILL.md           # Skill definition\n  README.md          # User documentation\n  scripts/           # Local scripts (conceptual)\n    execute_query.py\n    backup.py\n    migrate.py\n```\n\n---\n\n# Security Best Practices\n\n1. **Never embed credentials in code**\n2. **Use MGC for credential storage**\n3. **Retrieve credentials at runtime only**\n4. **Never\n\nArchive v1.0.1: 5 files, 5188 bytes\n\nFiles: manifest.json (1308b), README.md (1432b), skill-card.md (2167b), SKILL.md (4985b), _meta.json (140b)","readmeExcerpt":"Skill: Mgc Database Security Owner: zkeviny Summary: Secure database credential management using MGC Blackbox 1.5.2. Supports MySQL, PostgreSQL, SQLite, MariaDB and other databases. Credentials are stored encrypted; local scripts retrieve them via HTTP API at runtime, while AI agents never touch plaintext. Tags: latest:1.3.0 Version history: v1.3.0 | 2026-09-29T03:41:25.591Z | user Version 1.3.0 introduces major upgr","codeSnippets":[],"executableExamples":[{"language":"text","snippet":"pip install mgc-blackbox"},{"language":"text","snippet":"mgc"},{"language":"text","snippet":"data-analyst-secure-suite/\n├── SKILL.md                    # main document (this file)\n├── README.md                   # detailed usage guide\n├── manifest.json               # skill metadata\n├── agent_system_prompt.md      # Agent system-prompt template\n└── prompts/\n    ├── credential_management.md    # credential management\n    ├── script_management.md        # workflow & script management\n    ├── collaboration_management.md # sealed collaboration\n    └── knowledge_management.md     # knowledge management"},{"language":"text","snippet":"pip install mgc-blackbox>=1.5.2"},{"language":"text","snippet":"mgc"},{"language":"text","snippet":"data-analyst-secure-suite/\n├── SKILL.md                    # main document (this file)\n├── README.md                   # detailed usage guide\n├── manifest.json               # skill metadata\n├── agent_system_prompt.md      # Agent system-prompt template\n└── prompts/\n    ├── credential_management.md    # credential management\n    ├── script_management.md        # workflow & script management\n    ├── collaboration_management.md # sealed collaboration\n    └── knowledge_management.md     # knowledge management"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"spec: usk/3.0\nid: data-analyst-secure-suite\nversion: 1.3.0\nname: Secure Data Analyst Skill Suite\ndescription: A secure data analysis workflow suite based on MGC Blackbox 1.5.2+, providing credential protection, zero-exposure script & workflow application, sealed-package collaboration, and knowledge management. Supports MGC 1.5.2 workflow auto-recognition (import / from-import / relative paths / subprocess runtime routing). Includes a Data Analyst Agent system prompt template.\nauthor: MirginCipher Team\nlicense: MIT\ntags: security, data analysis, mgc, zero-exposure, local sandbox, credential management, workflow management, sealed collaboration, knowledge management, agent template, fuzzy search, auto-recognized workflow, sealed cross-script\nplatform_compatibility: windows, macos, linux\nrequires:\n  mgc_blackbox: \">=1.5.2\"\nchangelog:\n  - version: 1.3.0\n    changes:\n      - Upgraded to MGC 1.5.2+: added mgc_save_file (workflow folder storage), mgc_seal_package (workflow sealing), mgc_package (plaintext packaging).\n      - Script management refactor: upgraded from single-script to workflow-folder mode, with import / from-import / relative-path / subprocess auto-recognition.\n      - Credential management: unified info_type from 'credential' to 'token' to align with skill_spec.\n      - Added prompts/collaboration_management.md: dedicated workflow / skill-package sealed-authorization guide.\n      - Agent template: workflow examples upgraded from 5-step manual chain to find -> save_file -> run pattern.\n      - Added sealed-collaboration chapter (mgc_seal_package one-click seal of an entire workflow).\n      - Added recognizable cross-script patterns table (from-import / import / Path / subprocess).\n      - MCP tools list expanded to 10 (added mgc_save_file, mgc_seal_package, mgc_package).\n  - version: 1.2.0\n    changes:\n      - Synced with MGC Blackbox 1.4.10: added mgc_find (fuzzy search) and mgc_run (preferred over mgc_get action=run).\n      - Script management: replaced mgc_get(action='run') with dedicated mgc_run tool.\n      - Script management: added mgc_find workflow for locating scripts by name.\n      - Script sealing: clarified ext04 must be a multi-line PEM public key.\n      - Credential management: added mgc_find workflow.\n      - Knowledge management: added mgc_find workflow.\n      - Agent system prompt: documented the find -> get/run workflow pattern.\n  - version: 1.1.1\n    changes:\n      - Optimized documentation structure per review report\n      - Added 'Anti-patterns and pitfalls' chapter\n      - Added 'Complete use cases' chapter\n      - Unified prompt file-name references\n  - version: 1.1.0\n    changes:\n      - Consolidated prompts into three core modules: credential, script, knowledge management\n      - Added agent_system_prompt.md as a Data Analyst Agent system-prompt template\n      - Strengthened document structure and clarified each module's scenario and invocation\n  - version: 1.0.0\n    changes:\n      - Initial release\n---\n\n# Overview"},{"path":"README.md","content":"# Secure Data Analyst Skill Suite\n\n# Secure Data Analyst Skill Suite\n\n> **Version**: 1.3.0 · **Requires**: MGC Blackbox ≥ 1.5.2\n\nA secure data-analysis workflow suite built on **MGC Blackbox**, providing a hybrid mix of **skill prompts + Agent system-prompt template**, helping data analysts securely manage scripts, workflows, credentials, sealed collaboration, and knowledge on the local machine.\n\n---\n\n## What this suite is\n\nThis suite helps data analysts complete data-analysis workflows locally and securely:\n\n- **Database credential security** (zero exposure)\n- **Application of user-owned scripts & workflows** (query / clean / analyze)\n- **Auto-recognized workflows** (import / from-import / relative-path / subprocess runtime routing, 1.5.2+)\n- **Sealed-collaboration on workflows / skill packages** (one-key-per-node, node-bound, no resell, 1.5.2+)\n- **Knowledge management for analysis methods & prompts** (local encrypted storage)\n- **Optional Data Analyst Agent template** (auto-enforces the security boundary)\n\nAll sensitive operations require explicit user authorization. This suite does not provide any automated data-access capability.\n\n---\n\n## Prerequisites\n\n- Python 3.10+\n- Install MGC Blackbox:\n  ```\n  pip install mgc-blackbox>=1.5.2\n  ```\n- Start MGC:\n  ```\n  mgc\n  ```\n- Available MCP tools: mgc_save, mgc_save_file, mgc_get, mgc_run, mgc_seal, mgc_seal_package, mgc_package, mgc_list, mgc_find, mgc_open_webui\n- Token file: `~/.mgc/database/mgc_black_box/.mgc_token`\n\n---\n\n## Core capabilities\n\n### 1. Credential management (`credential_management.md`)\n\nSecurely store and use database keys, API tokens, and other secrets.\n\n**Scenarios**\n- Need to connect to databases or external services\n- Scripts need safe access to credentials\n- Team members share database/service **access rights** (not the data itself)\n- Team members share **analysis methods and scripts** across the team and outside (via workflow sealed authorization)\n\n**What it provides**\n- Local encrypted storage\n- AI never sees the plaintext credentials\n- Scripts can call credentials with zero exposure\n- All accesses require user authorization\n\n**How the agent uses it**\nThe agent, after user authorization, reads credentials but never sees plaintext.\n\n---\n\n### 2. Workflow management (`script_management.md`)\n\nManage user-owned query / clean / analyze scripts — both as single scripts and as workflow folders.\n\n**Scenarios**\n- User wants to apply their own scripts or workflows\n- Scripts need safe access to credentials\n- Multi-script workflows need auto-recognition of import / subprocess call relationships (1.5.2+)\n- Workflows need cross-team collaboration (sealed)\n- Need to build a complete data-analysis chain (query → clean → analyze)\n\n**What it provides**\n- Single-script encrypted storage (`mgc_save`)\n- Workflow-folder encrypted storage with auto-recognition of import / subprocess (`mgc_save_file`, 1.5.2+)\n- AI never sees the script content\n- Scripts call credentials with zero exposure\n- Single-"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7dbqpp9139vnzrg035qhwfk18947vg\",\n  \"slug\": \"mgc-database-security\",\n  \"version\": \"1.3.0\",\n  \"publishedAt\": 1790653285591\n}"},{"path":"agent_system_prompt.md","content":"# Secure Data Analyst Agent — System Prompt Template (Safety Version)\n\nYou are a **Secure Data Analyst Workflow Assistant** that helps data analysts use MGC Blackbox (≥ 1.5.2) to securely manage and apply their own scripts and workflows on the local machine.\nYou are NOT an automated execution engine. You must strictly obey the security boundary and obtain explicit user authorization before any sensitive operation.\n\n---\n\n## Your role\n\nYou are a **workflow assistant**, not an automation engine.\nYour goal is, after the user authorizes it, to safely apply the user's scripts and workflows via MGC Blackbox and to assist in managing the full workflow.\n\nYou must not make decisions on behalf of the user, and you must not execute anything without authorization.\n\n---\n\n## Security boundary you must obey\n\n### You must NEVER:\n\n- Access any credential without user authorization\n- Access or view script content without user authorization\n- Generate, modify, or infer user scripts\n- Apply scripts or workflows without user authorization\n- Transmit any data to an external system\n- Chain multiple workflow steps without explicit confirmation\n- Auto-select a script name (`info_owner` must be explicitly supplied by the user)\n- Automate data access, cleaning, analysis, or transport\n\n### You MUST:\n\n- Request user authorization before any sensitive operation\n- Only apply scripts and workflows through MGC Blackbox\n- Return results without exposing script logic\n- Only use user-owned scripts\n- Ensure all operations happen on the user's local machine\n- Refer to the prompts in this skill suite when the user asks about workflows\n\n---\n\n## How to use this skill suite\n\n### 1. Credential management\n\nWhen the user wants to store credentials:\n\n```\nAsk: \"Do you authorize storing these credentials in MGC?\"\n- If yes: direct the user to the MGC WebUI\n- You NEVER handle credential content directly\n```\n\n---\n\n### 2. Workflow application (find → save_file → run, 1.5.2+)\n\nWhen the user requests running a data-analysis workflow, use the **find → run** self-describing workflow:\n\n```\nStep 1 — Locate the workflow (mgc_find, fuzzy-search by name):\nmatches = mgc_find(\n    info_owner=\"<partial name>\",  # e.g. \"monthly_sales\" matches \"monthly_sales_analysis\"\n)\n# matches returns a metadata list — NEVER plaintext.\n# If multiple matches, ask the user to disambiguate; if exactly one, proceed.\n\nStep 2 — Request authorization:\n\"Do you authorize running the workflow <info_owner from matches>?\"\n\nStep 3 — If authorized, run the workflow through MGC:\nresult = mgc_run(\n    info_owner=\"<info_owner>\",\n    diff_2=\"<info_owner>\",\n)\n# MGC auto-recognizes the package's import / subprocess relationships and routes through sealed execution.\n# Returns {\"pid\": 12345, \"status\": \"started\"}\n\nStep 4 — Return the run status without exposing script logic\n```\n\n> **Note**: Workflow output must be written to an explicit file path, or into a database / MGC itself. MGC never returns plaintext script content.\n\n---\n\n### 3. Single-scrip"},{"path":"prompts/collaboration_management.md","content":"# Workflow & Skill Package Sealed Collaboration\n\nThis document guides data analysts on how to securely seal and deliver workflows or skill packages to other nodes in **MGC Blackbox ≥ 1.5.2**, enabling \"usable but unreadable, runnable but unresellable\" cross-team / cross-organization collaboration.\n\nAll sensitive operations must be explicitly authorized by the user before proceeding.\n\n---\n\n# 1. Why Sealed Collaboration Is Needed\n\nCommon collaboration pain points in data analysis workflows:\n\n| Scenario | Pain Point | MGC Solution |\n|----------|-----------|--------------|\n| Data team delivers analysis workflow to business team | Don't want business team to see source code or modify logic | After workflow sealing, recipient can only run, never read |\n| External analyst delivers analysis package to customer | Customer resells source to peers after delivery | AES key bound to customer node, cannot re-seal |\n| Cross-department sharing of analysis methodology | Worry about core algorithm leakage | Seal the entire workflow at once, core algorithms locked inside scripts |\n| Delivering to multiple customers | Each customer needs independent authorization | One key per customer, each customer has independent key |\n\n> **Core principle**: Delivery equals authorization. After sealing, the recipient can only run — cannot read, modify, or resell.\n\n---\n\n# 2. Workflow Sealing vs Skill Package Sealing\n\nMGC supports two sealed collaboration modes:\n\n| Dimension | Workflow Sealing | Skill Package Sealing |\n|-----------|------------------|------------------------|\n| **Sealing Target** | Analysis script folder (run.py + helpers/) | Complete skill package with SKILL.md |\n| **Sealing Tool** | `mgc_seal_package` | `mgc_seal_package` |\n| **Recipient Usage** | `mgc_run` directly invokes entry script | AI reads SKILL.md instructions and calls corresponding scripts |\n| **Use Case** | Deliver a \"one-click run\" analysis tool to business team | Deliver a complete \"AI-understandable usage guide\" package to client |\n| **SKILL.md Included?** | Not required | Required (recipient AI's usage manual) |\n| **Recipient AI Visibility** | Sees only run status | Can read SKILL.md (plaintext), but cannot see script source code |\n\n> **Selection guidance**:\n> - If the recipient only needs to \"execute your analysis\", use **Workflow Sealing**\n> - If the recipient needs AI to autonomously call different scripts per your package, use **Skill Package Sealing**\n\n---\n\n# 3. End-to-End Collaboration Flow\n\n## 3.1 Complete Flow\n\n```\nAuthor Node                                         Recipient Node (Client / Team)\n───────────                                        ──────────────────────\n\n1. Save workflow / skill package\n   mgc_save_file(path=\"./my_workflow\")\n   → MGC auto-recognizes import / subprocess relationships\n\n2. Recipient fetches their own public key            mgc_get(info_type=\"__NODE_PUB__\",\n   (Public key is not secret; any channel OK)         info_owner=\"__NODE_PUB__\")\n                         "}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":2175,"uniquenessScore":34,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-11T16:39:11.403Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-11T16:39:11.403Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-11T20:57:16.524Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}