env_var_migration.he

env_var_migration.he is an agent for Claude Code from hyperledger-iroha/iroha. It costs 0 tokens per session (2,087 once invoked), scanned A, original, Apache-2.0.

A project-specific tracker for moving production settings from environment variables into the Iroha configuration system. The source text is not enough to describe broader use beyond that tracking work.

In plain words
What is it for?
Use it to track configuration migrations, distinguish development or test-only settings, and document planned changes.
Why use it?
It records completed migrations and guards against adding new production environment-variable work without documenting it.

Agent for Claude Code

Written for Claude Code: a Claude Code subagent (agents/*.md).

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add agents/hyperledger-iroha/iroha/env_var_migration.he
Clone the repo
git clone --depth 1 https://github.com/hyperledger-iroha/iroha

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for env_var_migration.he

README.md
[![agentmods](https://agentmods.dev/badge/agents/hyperledger-iroha/iroha/env_var_migration.he.svg)](https://agentmods.dev/agents/hyperledger-iroha/iroha/env_var_migration.he)
Your own site
<a href="https://agentmods.dev/agents/hyperledger-iroha/iroha/env_var_migration.he"><img src="https://agentmods.dev/badge/agents/hyperledger-iroha/iroha/env_var_migration.he.svg" alt="Measured on agentmods" height="20"></a>
Per session 0 Only the description is in the session, so the agent can decide to use it. The body loads when it is invoked.
When invoked 2,087 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00000 $0.02087
Opus 5 $0.00000 $0.01043
Sonnet 5 $0.00000 $0.00417
Haiku 4.5 $0.00000 $0.00209

Measured 4d ago against content hash a7f8a2973415, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade A, and why

env_var_migration.he scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 4d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

docs/source/agents/env_var_migration.he.md · 110 lines

How it starts

The opening of the file, as written. The whole thing — 110 lines — stays where its author put it; the contents beside it link to each section on GitHub.

מעקב הסבת Env → Config

מעקב זה מסכם מתגים של משתני סביבה הפונים לייצור, כפי שמופיעים ב‑ docs/source/agents/env_var_inventory.{json,md}, ואת נתיב ההסבה המתוכנן אל iroha_config (או תחימה מפורשת ל‑dev/test בלבד).

הערה: ci/check_env_config_surface.sh נכשל כעת כאשר מופיעים shims חדשים של env לייצור ביחס ל‑AGENTS_BASE_REF אלא אם מוגדר ENV_CONFIG_GUARD_ALLOW=1; תעדו כאן תוספות מכוונות לפני שימוש ב‑override.

הסבות שהושלמו

  • IVM ABI opt-out — הוסר IVM_ALLOW_NON_V1_ABI; הקומפיילר כעת דוחה ABI שאינו v1 ללא תנאי עם בדיקת יחידה המגנה על נתיב השגיאה.
  • IVM debug banner env shim — הוסר ה‑env opt‑out IVM_SUPPRESS_BANNER; השתקת הבאנר זמינה עדיין דרך setter פרוגרמטי.
  • IVM cache/sizing — הועברה הגדרת cache/prover/GPU דרך iroha_config (pipeline.{cache_size,ivm_cache_max_decoded_ops,ivm_cache_max_bytes,ivm_prover_threads}, accel.max_gpus) והוסרו shims של env בזמן ריצה. Hosts קוראים כעת ל‑ ivm::ivm_cache::configure_limits ו‑ivm::zk::set_prover_threads, בדיקות משתמשות ב‑CacheLimitsGuard במקום דריסות env.
  • Connect queue root — נוסף connect.queue.root (ברירת מחדל: ~/.iroha/connect) לתצורת הלקוח והועבר דרך ה‑CLI וה‑JS diagnostics. עזרי JS פותרים את התצורה (או rootDir מפורש) ומכבדים את IROHA_CONNECT_QUEUE_ROOT רק ב‑dev/test דרך allowEnvOverride; התבניות מתעדות את ה‑knob כך שמפעילים לא צריכים עוד דריסות env.
  • Izanami network opt-in — נוסף דגל CLI/config מפורש allow_net לכלי הכאוס Izanami; הרצות כעת דורשות allow_net=true/--allow-net ו‑
  • IVM banner beep — הוחלף ה‑env shim IROHA_BEEP במתגי תצורה ivm.banner.{show,beep} (ברירת מחדל: true/true). חיווט banner/beep קורא כעת רק תצורה בייצור; בניות dev/test עדיין מכבדות את דריסת ה‑env עבור טוגלים ידניים.
  • DA spool override (tests only) — ה‑override IROHA_DA_SPOOL_DIR תחום כעת מאחורי עוזרי cfg(test); קוד ייצור תמיד שואב את נתיב ה‑spool מהתצורה.
  • Crypto intrinsics — הוחלפו IROHA_DISABLE_SM_INTRINSICS / IROHA_ENABLE_SM_INTRINSICS במדיניות תצורה מונעת crypto.sm_intrinsics (auto/force-enable/force-disable) והוסר ה‑guard IROHA_SM_OPENSSL_PREVIEW. Hosts מיישמים את המדיניות בעת ההפעלה; benches/tests יכולים לבחור להפעיל דרך CRYPTO_SM_INTRINSICS, ו‑OpenSSL preview מכבד כעת רק את דגל התצורה. Izanami כבר דורש --allow-net/תצורה שמורה, והבדיקות נשענות כעת על knob זה ולא על מתגי env כלליים.
  • FastPQ GPU tuning — נוספו knobs תצורה fastpq.metal.{max_in_flight,threadgroup_width,metal_trace,metal_debug_enum,metal_debug_fused} (ברירת מחדל: None/None/false/false/false) והועברו דרך parsing ה‑CLI; שימסי FASTPQ_METAL_* / FASTPQ_DEBUG_* מתנהגים כ‑fallback ל‑dev/test בלבד ומתעלמים מהם לאחר טעינת תצורה (גם כאשר התצורה משאירה אותם ריקים); התיעוד והמלאי רועננו כדי לסמן את ההסבה.【crates/irohad/src/main.rs:2609】【crates/iroha_core/src/fastpq/lane.rs:109】【crates/fastpq_prover/src/overrides.rs:11】 (IVM_DECODE_TRACE, IVM_DEBUG_WSV, IVM_DEBUG_COMPACT, IVM_DEBUG_INVALID, IVM_DEBUG_REGALLOC, IVM_DEBUG_METAL_ENUM, IVM_DEBUG_METAL_SELFTEST, IVM_FORCE_METAL_ENUM, IVM_FORCE_METAL_SELFTEST_FAIL, IVM_FORCE_CUDA_SELFTEST_FAIL, IVM_DISABLE_METAL, IVM_DISABLE_CUDA) מוגדרים כעת מאחורי בניות debug/test באמצעות helper משותף כך שבינאריים של ייצור מתעלמים מהם תוך שמירת knobs לאבחון מקומי. מלאי ה‑env נוצר מחדש כדי לשקף את תחום dev/test בלבד.
  • FASTPQ fixture updatesFASTPQ_UPDATE_FIXTURES מופיע כעת רק בבדיקות אינטגרציה של FASTPQ; מקורות ייצור אינם קוראים עוד את מתג ה‑env והמלאי משקף את תחום test בלבד.
  • Inventory refresh + scope detection — כלי המלאי של env מתייג כעת קבצי build.rs כ‑build scope ומעקוב אחר מודולי #[cfg(test)]/integration harness כך שמתגים ייעודיים לבדיקות (למשל, IROHA_TEST_*, IROHA_RUN_IGNORED) ודגלי build של CUDA מופיעים מחוץ לספירת הייצור. המלאי חודש Dec 07, 2025 (518 refs / 144 vars) כדי לשמור על diff ירוק של env‑config guard.
  • P2P topology env shim release guardIROHA_P2P_TOPOLOGY_UPDATE_MS מפעיל כעת שגיאת אתחול דטרמיניסטית בבניות release (warn‑only ב‑debug/test) כך שצמתי ייצור מסתמכים אך ורק על network.peer_gossip_period_ms. מלאי ה‑env נוצר מחדש כדי לשקף את ה‑guard ואת מסווג ה‑cfg!‑guarded המעודכן שמתחם toggles כ‑debug/test.

Read the full file on GitHub · 110 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 4d ago First seen · 110 lines · 0 tokens per session scan A a7f8a2973415

Subscribe to this mod's changes

env_var_migration.he is an agent published in the GitHub repository hyperledger-iroha/iroha (488 stars, last pushed today), licensed Apache-2.0. It costs nothing until one of its globs matches a file; then it loads 2,087 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-01.