Integrate Social Auto Upload
Treat setup, login, account checks, and publishing as separate authorization gates. The pinned upstream has no LICENSE file.
Workflow
- Read references/integration.md before installation or CLI use.
- Confirm the user accepts evaluation-only use pending a valid upstream license. Do not redistribute or embed upstream code.
- Resolve the repository and verify remote, pin, worktree, Python version, and destination.
- For setup, preview dependency and browser downloads, then install only after approval.
- For login or account checks, state platform, account alias, browser mode, credential artifacts, and whether external state changes. Obtain explicit approval.
- For publishing, first produce a dry-run manifest containing platform, account, media, title, body, tags, thumbnail, product fields, schedule/timezone, and AIGC/copyright checks.
- Display the final manifest and ask for single-use approval immediately before the command that can publish. Never infer approval from earlier setup or drafting.
- Execute once. If the result is ambiguous, inspect status and stop; never retry publication automatically.
- Redact Cookies, session data, verification codes, QR payloads, and account files from logs and output.
Hard Stops
- Never write a verification code to
verify_code.txtunless the user explicitly authorizes that exact local action; remove it only after confirming the tool created/used it as expected. - Do not auto-download or auto-update
biliupwithout showing the effect and obtaining approval. - Do not use headless mode to bypass platform controls or perform unattended bulk posting.
- Prefer official platform interfaces or a user-controlled browser when the task does not specifically require SAU.
Agent Output
Return the repository pin, license warning, setup status, dry-run/final manifest, approval boundary, one command result, and rollback steps.