The CLI reads six environment variables at runtime: GITHUB_TOKEN, MALETA_CLI_HOME, MALETA_API_ORIGIN, MALETA_DEVICE_TOKEN, MALETA_ALLOW_INSECURE_ORIGIN, and MALETA_NO_BROWSER. The packages/core package does not read any environment variables.
#GITHUB_TOKEN
GITHUB_TOKENToken sent as
authorization: Bearer <token>in GitHub API requests. It only raises the request limit for public skills; the CLI works without it.
- The header is only attached when the request host is in the fixed list:
api.github.com,github.comandraw.githubusercontent.com. Any other host is rejected withrefusing GitHub token on a non-GitHub host. - The value is sent to the child process making the request through
stdin, never as a command-line argument, so it does not appear in the process list. - The token is never written to disk or printed: it does not appear in
[error] …or in--dry-runoutput. - Redirects are followed manually and only to the three allowed hosts; a
Locationoutside them is rejected. - A
401or403response becomes the single messageGitHub access denied or rate limited— the CLI does not read rate-limit headers.
GITHUB_TOKEN=ghp_exemplo maleta install --file ./maleta.json#Directories, API, and device
MALETA_CLI_HOMEOverrides the home directory used to build skill destinations and store credentials and state. When set to a non-empty value,
~points to that value.MALETA_API_ORIGINOverrides the origin used by device commands; trailing slashes are removed. With
MALETA_DEVICE_TOKEN, it also sets the origin of the environment-provided credential.MALETA_DEVICE_TOKENOverrides
credentials.jsonfor CI and headless machines. The environment credential takes precedence over the file;loginandlogoutreject operations that would create or remove this external credential.MALETA_ALLOW_INSECURE_ORIGINWhen set to exactly
1, allows a non-HTTPSMALETA_API_ORIGINfor local development. Otherwise, the device API rejects the insecure origin.MALETA_NO_BROWSERWhen set to exactly
1, preventsmaleta loginfrom opening a browser. The URL and code are still printed; the CLI also skips the browser when stdout is not a TTY.
- The value is resolved with
path.resolve; a relative path is interpreted from the process's cwd. - It only affects the
~/.claude/skillsand~/.agents/skillsdestinations. It does not change the skill source or the location of packaged assets. - The variable is not persisted in any file or copied to
maleta.json.
MALETA_CLI_HOME=/tmp/qa-home maleta install --file ./maleta.json#The browser token is separate
On public skill pages, the token is stored in sessionStorage under the key maleta-gh-token for the tab session only and sent as token <valor> exclusively to https://api.github.com. On the first visit, an old copy of that key in localStorage is deleted. This is independent of GITHUB_TOKEN: the CLI does not read browser storage, and the browser does not read the process environment. To learn what is stored and how to delete it, see the privacy policy.