SkillAgentSearch skills...

secret

Agents can read user-configured secrets at runtime using the `tai tool` CLI. Secrets are encrypted at rest (AES-256-GCM) and decrypted only when read.

Install / Use

npx skills add YaoApp/yao --skill secret

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

86/100

Supported Platforms

Universal

Our assessment of secret

secret scores 86/100 on our quality scale, 1092nd of 3,044 Development & Engineering skills we index (top 36%).

Its SKILL.md is 2.0 KB long, well organised into 10 sections with 4 code examples: moderately detailed.

With 8,024 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
20/30
Structure
20/20
Description
15/15
Adoption
17/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 4 days ago, so secret is actively maintained.
  • No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
  • Its trust signals score 88/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

secret compared with similar skills

All 4 of these similar skills score higher than secret; compare them before choosing.

SkillScoreStarsUpdatedFormat
secret (this skill)by YaoApp868.0k4d agoSKILL.md
Agent-Reachby Panniantong10085.8k12d agoCLAUDE.md
ai-job-searchby MadsLorentzen10044.2ktodayCLAUDE.md
claude-howtoby luongnv8910041.7k1d agoCLAUDE.md
algorithmic-artby anthropics100177.9k5d agoSKILL.md

Frequently asked questions

How do I install secret?
Run npx skills add YaoApp/yao --skill secret. The install tabs above show the steps for each supported agent.
Which AI agents does secret work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is secret safe to use?
It declares no license and scores 88/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is secret still maintained?
The repository was last updated 4 days ago, so secret is actively maintained.

Secret Management

Agents can read user-configured secrets at runtime using the tai tool CLI. Secrets are encrypted at rest (AES-256-GCM) and decrypted only when read.

Available Tools

| Tool | Description | |------|-------------| | secret_list | List secret names and descriptions (no values) | | secret_read | Read a single secret value by name |

Usage

Bash

# List available secrets
tai tool secret_list

# Read a secret
TOKEN=$(tai tool secret_read '{"name": "GITHUB_TOKEN"}' | jq -r '.value')
git clone "https://${TOKEN}@github.com/org/repo.git"

Node.js

const { execSync } = require("child_process");

function readSecret(name) {
  const raw = execSync(
    `tai tool secret_read '${JSON.stringify({ name })}'`,
    { encoding: "utf-8" }
  );
  return JSON.parse(raw).value;
}

const token = readSecret("GITHUB_TOKEN");

Python

import json
import subprocess

def read_secret(name: str) -> str:
    result = subprocess.run(
        ["tai", "tool", "secret_read", json.dumps({"name": name})],
        capture_output=True, text=True, check=True,
    )
    return json.loads(result.stdout)["value"]

token = read_secret("GITHUB_TOKEN")

PowerShell

function Read-Secret {
    param([string]$Name)
    $json = @{ name = $Name } | ConvertTo-Json -Compress
    $result = tai tool secret_read $json | ConvertFrom-Json
    return $result.value
}

$token = Read-Secret -Name "GITHUB_TOKEN"

Security Rules

  1. Never print or log secret values — Do not write secrets to stdout, stderr, or any log file.
  2. Never write secrets to files — Exception: SSH keys may be written to ~/.ssh/ with chmod 600 permissions.
  3. Never send secrets to the LLM — Secret values must not appear in prompt content, system messages, or tool call results that are forwarded to the model.
  4. Scope isolation — Secrets are scoped per user per agent. An agent can only access secrets configured for it.
  5. Audit trail — Every secret_read call is logged in the audit trail with the caller's identity.

Related Skills

View on GitHub
GitHub Stars8.0k
CategoryDevelopment
Updated4d ago
Forks716

Languages

Go

Trust signals

88/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

1 medium