--- name: healthmd-cli-operator description: Operate the standalone Health.md CLI against an open, paired iPhone. Use when the user asks to run pairing/status/export/extract/resume/cancel, automate an Apple Health export, inspect CLI JSON, or troubleshoot Manual IP/Tailscale connectivity without the Health.md macOS app. compatibility: Requires the installed portable `healthmd` command on macOS, Linux, or Windows and a current Health.md iPhone app. Direct CLI Access is required for live commands. Generated-file destinations work on macOS/Linux in protocol v1; Windows supports raw and extract. --- # Health.md CLI Operator Use the installed standalone `healthmd`. Do not use the monorepo's `apps/apple/scripts/healthmd`; it runs the legacy Swift compatibility client. The Health.md macOS app is not required. ## Rules - Direct Manual IP/Tailscale is the only portable transport. Never add `--transport nearby`. - On macOS/Linux use `NO_COLOR=1 TERM=dumb`, a hard `timeout`, and stdin from `/dev/null`. Give exports longer bounds than status. - Parse stdout JSON or the explicit output artifact. Add global `--json` whenever automation requires a structured result; interactive terminals otherwise render readable text. Pairing instructions and health-free progress may use stderr. - For an unfamiliar shape, run the incomplete command first: `healthmd export`, `extract`, `resume`, `cancel`, or a selected `query` returns local `healthmd.cli_guidance/1` with requirements and `request_sent: false`; it does not contact iPhone. - Never infer execution success from exit status alone. A zero exit may be non-network guidance; require the expected result schema/status before reporting completion. Failures use `healthmd.cli_error/1` with `help_command` and bounded `next_actions`. - Ask for physical iPhone actions when needed: open/unlock Health.md, scan a pairing QR with its in-app Direct CLI scanner (which connects automatically), enable Direct CLI Access, enter a fallback code, approve local-network access, or grant HealthKit read access. - Never print health values unless explicitly requested. Counts, dates, paths, statuses, and diagnostics are enough. - Never retry an unknown-outcome export blindly. Inspect its durable job first. ```text user/agent → standalone healthmd listener :17647 ← authenticated encrypted LAN/Tailscale connection → open paired iPhone → HealthKit → protected spool → output/destination ``` The Mac app, loopback port `17645`, Mac destination bookmark, and Mac app connection state are irrelevant. ## Preflight ```bash NO_COLOR=1 TERM=dumb timeout 15 healthmd --version