Turn the build sheet into runnable artifacts, then let the founder launch with
their own key. No script here touches the network or the key — the user runs
launch.sh.
python3 scripts/payload_generator.py \
--sheet ./my-agent/build-sheet.json --out-dir ./my-agent
# -> ./my-agent/payloads/{01-environment,02-agent,03-session,04-kickoff}.json
Agent toolset → always_allow; every MCP toolset → always_ask (baked into
the agent payload's permission_policies).python3 scripts/launch_script_writer.py --out-dir ./my-agent
launch.sh creates environment → agent → session → kickoff in order,
chaining IDs, and resumes on re-run (each step skips if its *.id file
exists). It reads $ANTHROPIC_API_KEY at runtime.python3 scripts/payload_validator.py --dir ./my-agent
FAIL blocks — especially a key_leak finding. Fix and re-run.[ -n "$ANTHROPIC_API_KEY" ] && echo "key present" || echo "export ANTHROPIC_API_KEY=... first"
Point the founder to platform.claude.com → API keys. Never print the key to
chat, never write it to a file.
export ANTHROPIC_API_KEY=... # in their shell, not in chat
./my-agent/launch.sh
Mark checkpoints with Console deep links. Then goal_state.py set --phase grade-iterate and advance.launch.sh reads it
from the environment; payload_validator.py scans for sk-ant-… leaks and FAILs.launch.sh continues from the last created ID.$ANTHROPIC_API_KEY
before anything. Cite: this SKILL, key-safety rules.always_ask. Cite:
cma-primitives.md (permissions).scripts/payload_generator.py — build sheet → 4 ordered API payloads.scripts/launch_script_writer.py — resumable BYOK curl launcher (no key handling).scripts/payload_validator.py — pre-launch check + API-key-leak scan.