//! `credential-helper ` — implements git's //! credential-helper protocol (`gitcredentials(7)`) so a cloned repo's //! `.git/config` only ever holds a *reference* to this command, never //! the forge token itself. `clone` configures the new repo's //! `credential.helper` to invoke this subcommand; git then calls it //! fresh on every fetch/push, reading the token from its usual //! on-disk location (the per-agent `forge-token` file, or the //! `--forge