secret
Agents can read user-configured secrets at runtime using the `tai tool` CLI. Secrets are encrypted at rest (AES-256-GCM) and decrypted only when read.
Install / Use
npx skills add YaoApp/yao --skill secretInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Our assessment of secret
secret scores 86/100 on our quality scale, 1092nd of 3,044 Development & Engineering skills we index (top 36%).
Its SKILL.md is 2.0 KB long, well organised into 10 sections with 4 code examples: moderately detailed.
With 8,024 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 4 days ago, so secret is actively maintained.
- No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
- Its trust signals score 88/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
secret compared with similar skills
All 4 of these similar skills score higher than secret; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| secret (this skill)by YaoApp | 86 | 8.0k | 4d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 85.8k | 12d ago | CLAUDE.md |
| ai-job-searchby MadsLorentzen | 100 | 44.2k | today | CLAUDE.md |
| claude-howtoby luongnv89 | 100 | 41.7k | 1d ago | CLAUDE.md |
| algorithmic-artby anthropics | 100 | 177.9k | 5d ago | SKILL.md |
Frequently asked questions
- How do I install secret?
- Run
npx skills add YaoApp/yao --skill secret. The install tabs above show the steps for each supported agent. - Which AI agents does secret work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is secret safe to use?
- It declares no license and scores 88/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is secret still maintained?
- The repository was last updated 4 days ago, so secret is actively maintained.
Skill content
View source on GitHubSecret Management
Agents can read user-configured secrets at runtime using the tai tool CLI.
Secrets are encrypted at rest (AES-256-GCM) and decrypted only when read.
Available Tools
| Tool | Description |
|------|-------------|
| secret_list | List secret names and descriptions (no values) |
| secret_read | Read a single secret value by name |
Usage
Bash
# List available secrets
tai tool secret_list
# Read a secret
TOKEN=$(tai tool secret_read '{"name": "GITHUB_TOKEN"}' | jq -r '.value')
git clone "https://${TOKEN}@github.com/org/repo.git"
Node.js
const { execSync } = require("child_process");
function readSecret(name) {
const raw = execSync(
`tai tool secret_read '${JSON.stringify({ name })}'`,
{ encoding: "utf-8" }
);
return JSON.parse(raw).value;
}
const token = readSecret("GITHUB_TOKEN");
Python
import json
import subprocess
def read_secret(name: str) -> str:
result = subprocess.run(
["tai", "tool", "secret_read", json.dumps({"name": name})],
capture_output=True, text=True, check=True,
)
return json.loads(result.stdout)["value"]
token = read_secret("GITHUB_TOKEN")
PowerShell
function Read-Secret {
param([string]$Name)
$json = @{ name = $Name } | ConvertTo-Json -Compress
$result = tai tool secret_read $json | ConvertFrom-Json
return $result.value
}
$token = Read-Secret -Name "GITHUB_TOKEN"
Security Rules
- Never print or log secret values — Do not write secrets to stdout, stderr, or any log file.
- Never write secrets to files — Exception: SSH keys may be written to
~/.ssh/withchmod 600permissions. - Never send secrets to the LLM — Secret values must not appear in prompt content, system messages, or tool call results that are forwarded to the model.
- Scope isolation — Secrets are scoped per user per agent. An agent can only access secrets configured for it.
- Audit trail — Every
secret_readcall is logged in the audit trail with the caller's identity.
Related Skills
Agent-Reach
85.8kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
ai-job-search
44.2kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
claude-howto
41.7kA visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
