--- name: connect description: Automatically start Durumari login/signup and connect this workspace, using the installed service address without asking the user for a server URL or project IDs. --- # Connect Durumari Locate this plugin's root: two parents above this SKILL.md. Use its bundled `scripts/durumari_plugin.py` with Python 3.12 or newer. On Claude Code the host also provides `CLAUDE_PLUGIN_ROOT`. Resolve an absolute path; do not assume the shell starts in the plugin directory. 1. Inspect the current workspace and `durumari.yaml`. If already connected, use `status --workspace --client ` and reuse the existing OS-protected login. Do not recreate healthy profiles or copy another user's credentials. A repository mismatch must not prevent this workflow or ordinary chat. Run guided browser connect to reapprove the existing project; never edit `repository_id` yourself or weaken host trust. For the same folder, recovery validates the existing connection on the server and preserves its encrypted queue/key. For a copied/moved folder, browser approval creates a separate connection in the same project/source and retains the original profile and pending records without transmitting them from the new folder. Report retained pending records explicitly. Connection-file backups precede replacement; changes during browser approval require a fresh connect attempt. Reload the host, verify status/current Context and inspect the interrupted operation before resuming it. 2. The guided connect command installs a missing runtime from the packaged wheel and verified lock hashes. On macOS it also replaces an older runtime that lacks guided connect. On Windows, finish the normal update workflow and restart the host before retrying an older runtime; never replace an active managed Python process. Existing OS credentials and pending records are preserved. Obtain uv from Astral's official instructions if absent; do not run an unreviewed downloaded script. 3. Start connection yourself. Do not ask the user for a server address, project ID, source ID or a command to run. The command reuses the current workspace's `durumari.yaml` first; without a manifest it reads the trusted service address bundled with this installed plugin in `runtime/bundle.json`. Never borrow another repository's binding, browser-tab project or credentials. Only use `--server` when the user explicitly requests a different self-hosted server. A missing or invalid packaged address is an installation error: repair/update the plugin rather than guessing an endpoint or delegating setup to the user. 4. Run this from your execution tool (substitute the actual absolute plugin script and workspace). Browser mode works without terminal input: `python3 /scripts/durumari_plugin.py connect --workspace --client ` The command opens the server's browser login/signup page and waits for human approval. Show the browser continuation and ask the human to compare the displayed connection code, choose their personal space/team project and approve Context sharing and recording once. Keep the process alive and resume after approval; do not stop after merely printing instructions. The agent never chooses or approves the human's scope. Passwords, email verification codes and private exchange credentials stay out of the conversation, tool arguments, environment variables and settings. The plugin checks local setup before claiming scoped credentials. Failed/cancelled setup revokes its unconfigured connection, including a lost exchange response, while preserving browser login. Noninteractive mode refuses old servers requiring terminal choices. Password fallback requires an explicit human-terminal workflow; do not select it automatically. Existing source policy is not widened. Inspect local documentation before starting: use `--for-migration` when existing project documents need onboarding. After connection, automatically continue the migrate workflow through a private preview and review. Apply only within the user's authorized migration scope; connection consent alone does not authorize uploading every local document. Preserve originals and show material omissions or exclusions. 5. When login is required, run the same command with `--reauth`. Recovery keeps the connection, encryption key, pending records and host settings. It cannot restore revoked or expired grants, lost project access, or a blocked provider. Do not delete the old profile or queue, create another profile to bypass recovery, or use credentials from another host. Report a recovery denial for human resolution. 6. Project setup writes a secret-free `durumari.yaml`, managed entrypoint instructions, project-local MCP and supported collection hooks. It preserves explicitly disabled hooks. Inspect generated changes and preserve existing user settings. Follow the host's normal MCP/hook trust approval. Reload the host, run status, then read current Context through MCP. Only scoped project credentials are stored in the OS secure store. Existing-connection recovery uses a temporary account session that is closed after recovery; it preserves the original binding and encrypted outbox. The native plugin is reusable across repositories. Credentials belong to this device and host; MCP and collection hooks bind to this workspace. Installing the native plugin alone does not grant access to any project or prove automatic collection. Use the migrate workflow for historical documents and the context workflow for ongoing server-authoritative work. 7. After setup and live MCP access, continue the [automatic host capture verification](../status/references/automatic-capture.md) gate in the same workspace. Include it for both new-project creation and migration connections; do not stop at configuration or `ready: true`. Preserve human hook trust and explicit disable choices. For teams without Git, connect the selected local work folder exactly as a repository. If the user has chosen a new folder, pass `--create-workspace` to create it. When starting from a server project connection screen, pass its public project ID with `--requested-project`; this only pins selection and never grants access. New servers provide current secret-free connection files after browser approval. The runtime validates project/source/origin and hashes before merging the managed instructions, preserving existing content and disabled hooks. Each device keeps its own OS credentials. 8. After connect, inspect host_setup and effective_codex_config. A blocked Codex project layer is not ready. Explain local code execution trust separately from Context sharing. Only after explicit human consent to trust this exact workspace, rerun connect with --trust-workspace. Never approve hooks or forge trusted hashes. Reload the host and verify MCP and automatic capture independently.