Agent skill

Interactive Login

by yc-software in yc-software/qm

How to complete browser/interactive logins (aws / gh / glab / gcloud).

MITAuto-check passed

Install Interactive Login

skills CLI
$ npx skills add yc-software/qm --skill interactive-login -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yc-software/qm interactive-login --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yc-software/qm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills-seed/interactive-login .claude/skills/interactive-login && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
interactive-login
GitHub stars
15k
Token cost
~1.3k tokens
SKILL.md length
752 words
Files
1
Skills in repo
29
Repo updated
First seen
Licence
MIT

At a glance

How to complete browser/interactive logins (aws / gh / glab / gcloud).

  • SKILL.md covers When backgrounding works, When it will NOT work (don't… and Boundaries
  • Calls aws, gh and glab

What it does

Interactive Login is an agent skill from yc-software/qm. How to complete browser/interactive logins (aws / gh / glab / gcloud). The platform backgrounds the login poller so it survives the human's browser round-trip — and when that does NOT work.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Amazon Web Services and Google Cloud. The repository describes itself as: Multiplayer agent harness for work. The licence is MIT.

Example prompts

  • “/interactive-login”

Requirements

  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit 23af31b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws
    • gh
    • glab
    • gcloud

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, gh, glab and gcloud, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Interactive Login loads about 1.3k tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 752 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yc-software/qm at commit 23af31b, republished under its MIT licence (© yc-software). 752 words, ~1,263 tokens.

Download SKILL.mdSave it as .claude/skills/interactive-login/SKILL.md (or your agent's skills folder).
name
interactive-login
description
How to complete browser/interactive logins (aws / gh / glab / gcloud). The platform backgrounds the login poller so it survives the human's browser round-trip — and when that does NOT work.

Interactive login (and what backgrounding can and can't do)

Some logins are interactive: the CLI prints a verification URL + one-time code, then polls the provider until the human approves in a browser, and only then writes the token to $HOME. Run that as a plain blocking execute and it either hangs your whole turn waiting for a human, or — worse — the turn's sandbox is torn down at turn end and the poller dies before the human finishes, so nothing is ever saved. The next turn starts over and loops forever.

You usually don't have to manage any of this. Just run the native login command.

bash
aws sso login --use-device-code

AWS (and CLIs that log in through AWS SSO): always pass --use-device-code (aws sso login ≥ CLI v2 2.22). The bare form uses a PKCE flow that redirects to 127.0.0.1 and only completes if the approving browser is on the same machine as the CLI. Since the user approves on their computer, that flow can never finish on the agent computer; --use-device-code forces the device-grant (URL + code, completed by server-side polling) that works cross-device.

On the resident, per-scope agent computer (the production substrate), the platform recognizes these as interactive logins and runs each as a durable process session (ADR 0002): it returns the verification URL + code to you immediately instead of blocking, and keeps polling the provider on the agent computer across turns. (This recognition is wired only where the backend supports process sessions — on a per-turn local/docker sandbox nothing intercepts the command and it just blocks; see "When it will NOT work".) When the human approves, the poller writes the token into the durable $HOME and exits. Give the user the URL + code, tell them to approve, then on a later turn re-run the same command (or any command for that tool) — if approval landed, the platform reports you're already authenticated; if not, you get the same URL

  • code back. Each pending login self-expires (~10–15 min); if it lapses, just run the login again.

So the right pattern is: run the native login, hand over the URL + code, continue, and re-check later. You do not poll in a loop, you do not hold the turn open, and you do not hand-roll the exchange yourself.

When backgrounding works

  • The agent computer is a resident, per-scope machine (the production substrate — SANDBOX=fly): it has durable process sessions and a durable $HOME, so a login started in one turn is still polling in the next and the token persists.
  • The command is one of the recognized native flows: aws sso login, gh auth login, glab auth login, gcloud auth login. The platform knows these poll-then-write and keeps them alive for you.
Show full SKILL.md (310 more words)Show less

When it will NOT work (don't rely on it)

  • On a per-turn sandbox (local/docker dev). Those backends have no process sessions and are torn down at the end of every turn — there is nothing to keep the poller alive across the human's approval. An interactive browser login cannot complete there. Use a non-interactive path instead: a token via env or --with-token / --token --stdin, a service-account / credentials file, or --cred-file. The platform deliberately leaves those non-interactive token forms to run normally (it only backgrounds the interactive login).
  • For logins the platform doesn't recognize. A CLI that prompts for a username/password at the TTY, or a bespoke OAuth flow that isn't in the list above, is not backgrounded — it runs as an ordinary blocking command and will hang and then die at turn teardown. Prefer that tool's non-interactive/token auth, or ask the user to provide a token you can configure.
  • For arbitrary processes you spawn yourself. Backgrounding with & / nohup does not make a process survive between turns. Only declared session kinds are kept alive past teardown, and today only the interactive-login broker is wired in. A dev server, a long build, or a sleep you launch will be reaped when the turn ends — don't architect a task around "I'll leave it running in the background."

Boundaries

  • A backgrounded login session is scope-keyed to the requesting scope and lives on that scope's computer only — it never crosses the data boundary; another principal in the same thread cannot read your session or use the resulting auth.
  • A session is a host for resident state, not an authority. The login only completes the auth exchange; any side-effecting or destructive command you run afterward still goes through the normal approval path.
  • Never echo the token, one-time code reuse, client secret, or resulting credentials into the channel — hand over only the verification URL + code the human needs.

© yc-software, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills-seed/interactive-login of yc-software/qm.

Open the folder on GitHubat commit 23af31b

Compare with similar skills

Interactive Login next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Interactive Login compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Interactive Login this skillyc-software/qm15k—~1.3kAutomated safety check: PassMIT
Cloud Cost Optimizationwshobson/agents40k13 repos~1.7kAutomated safety check: PassMIT
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2596 repos~1.1kAutomated safety check: NotesCustom licence
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only
Excalidraw Diagram Studiotech-leads-club/agent-skills7k—~3.6kAutomated safety check: PassCC-BY-4.0
TerrasharkLukasNiessen/terrashark715—~843Automated safety check: PassMIT

Similar skills

  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 13 repos~1.7k tokens
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    259 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Excalidraw Diagram Studio

    tech-leads-club/agent-skills

    Generates Excalidraw diagram files from plain descriptions, choosing among flowcharts, mind maps, architecture, swimlane, class, sequence and ER diagrams.

    7k GitHub stars~3.6k tokensUpdated 17 days ago
    DevelopmentAuto-check passed
  • Terrashark

    LukasNiessen/terrashark

    Prevent Terraform/OpenTofu hallucinations by diagnosing and fixing failure modes: identity churn, secret exposure, blast-radius mistakes, CI drift, and compliance gate gaps.

    715 GitHub stars~843 tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Spotinfo

    alexei-led/spotinfo

    Query Spot/preemptible VM prices, savings and interruption risk across AWS, GCP and Azure with the spotinfo CLI.

    164 GitHub stars~1.8k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed

More from yc-software/qm

All 29 skills in this repo
  • Admin

    yc-software/qm

    Act for an org admin — the admin API (scope directory, per-scope config & SOUL, any scope's memory, transcripts & captured prompts, files, user roster & external users, audit/errors/metrics/egress)…

    15k GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Browse

    yc-software/qm

    Drive a real stealth browser from your shell — act on websites (order food, file an expense, pull data behind a login), with per-person persistent sign-ins via the provider's managed auth (Kernel…

    15k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • Composio

    yc-software/qm

    Show the app connection picker or setup widget when users ask to connect apps, reopen setup, or need an app that isn't connected yet.

    15k GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Dev Instance

    yc-software/qm

    Run the current worktree as a production-shaped local dev instance with web, Slack, or both, on a real LLM + Postgres.

    15k GitHub stars~3.7k tokensUpdated today
    Auto-check: notes
  • GitHub GitLab

    yc-software/qm

    Work with GitHub and GitLab repositories through resident gh/glab/git auth on the agent computer.

    15k GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Google Workspace

    yc-software/qm

    Read and act on the user's Gmail, Google Calendar, and Google Tasks through per-user OAuth.

    15k GitHub stars~1.8k tokensUpdated today
    Auto-check passed

Questions about Interactive Login

What does Interactive Login do?

How to complete browser/interactive logins (aws / gh / glab / gcloud). Interactive Login is an agent skill from yc-software/qm. How to complete browser/interactive logins (aws / gh / glab / gcloud).

How do I install Interactive Login in Claude Code?

Run `npx skills add yc-software/qm --skill interactive-login -a claude-code`. Or copy the skill folder (skills-seed/interactive-login in yc-software/qm) into .claude/skills/interactive-login in your project. Claude Code loads it when a task matches its description.

How do I install Interactive Login in Codex?

Run `npx skills add yc-software/qm --skill interactive-login -a codex`. Or copy the skill folder (skills-seed/interactive-login in yc-software/qm) into .agents/skills/interactive-login in your project. Codex loads it when a task matches its description.

Can I use Interactive Login in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yc-software/qm --skill interactive-login -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/interactive-login, .gemini/skills/interactive-login, .github/skills/interactive-login and .opencode/skills/interactive-login in your project.

What does Interactive Login need to run?

Going by SKILL.md and its folder, Interactive Login needs the command-line tools its instructions call (aws, gh, glab and gcloud). Our summary lists: Docker.

Does Interactive Login access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Interactive Login safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Interactive Login use?

Interactive Login is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Interactive Login use?

About 1.3k tokens (SKILL.md is roughly 5.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Interactive Login?

Skills that share tags, products or a category with Interactive Login: Cloud Cost Optimization (wshobson/agents, 40k stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 259 stars), Terravision Cloud Diagrams (patrickchugh/terravision, 1.6k stars) and Excalidraw Diagram Studio (tech-leads-club/agent-skills, 7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Interactive Login?

yc-software (a GitHub organization) maintains it in yc-software/qm, which has 15,357 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 6, 2026.

Source: yc-software/qm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.