197a18314f
* fix: warn agents off driving interactive console TUIs via pty on Windows Driving 'gh auth login' (and other survey-style console TUIs) through a pty background process on Windows silently hangs: these programs read Win32 console key events via ReadConsoleInput, not the stdin byte stream, so Enter keypresses submitted over process stdin never register. The agent-visible symptom is a prompt frozen at 'Press Enter to open browser...' while the user sees nothing, and a turn interrupt then kills the process, invalidating any device code the user already entered on github.com. Two guidance fixes, both proven in a live session on Windows 10: - agent/prompt_builder.py: extend _WINDOWS_BASH_SHELL_HINT to steer agents toward non-interactive paths (flags, --with-token, config files, curl-polled OAuth device flow) instead of answering console prompts programmatically. - skills/github/github-auth: document the pitfall and add the manual OAuth device-flow procedure (curl against gh's public client_id, poll for the token, finish with 'gh auth login --with-token'), which succeeded first try after two interactive attempts hung. * fix: send CRLF for Enter on Windows PTY submit; correct root cause in guidance Review feedback (helix4u) was right on both counts: 1. Root cause correction. gh's 'Press Enter to open browser' prompt is waitForEnter -> bufio.Scanner reading stdin, not a survey/console-API prompt. The real bug is ours: submit_stdin appended a bare \n, and through pywinpty/ConPTY a lone \n is not delivered as a line terminator, so the child's blocking line read never returns. Verified empirically against pywinpty 2.0.15 with a readline() child: \n -> hang, \r -> line delivered, \r\n -> line delivered. Fix: submit_stdin now appends \r\n for Windows PTY sessions (POSIX PTYs and Popen pipes keep \n). Windows-only regression tests cover the PTY and pipe branches. 2. Prompt hint rewritten: instead of claiming Windows console TUIs cannot be driven, it now says to use process(submit) rather than raw writes with bare \n, and to prefer non-interactive paths when a CLI offers one. 3. Skill device flow rewritten as an executable script: parses the device-code response, polls per the returned interval, handles authorization_pending / slow_down (+5s per GitHub docs) / expired_token / access_denied / unexpected responses, pipes the token straight into gh without echoing it, and drops the undocumented workflow scope (repo,read:org,gist is the documented minimum for gh auth login --with-token). The pitfall note is narrowed to the reproduced condition.