SkillAgentSearch skills...

yao-secret

Secret management expert. ALWAYS invoke this skill when you need to read API keys, tokens, or other secrets configured by the user. Never hardcode credentials — use this skill to retrieve them securely.

Install / Use

npx skills add YaoApp/yao --skill yao-secret

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

82/100

Supported Platforms

Universal

Our assessment of yao-secret

yao-secret scores 82/100 on our quality scale, 1633rd of 3,044 Development & Engineering skills we index.

Its SKILL.md is 1.6 KB long, split into 5 sections with 2 code examples: moderately detailed.

With 8,024 GitHub stars, it is one of the more widely adopted skills in the catalogue.

Substance
20/30
Structure
16/20
Description
15/15
Adoption
17/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 4 days ago, so yao-secret is actively maintained.
  • No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
  • Its trust signals score 88/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

yao-secret compared with similar skills

All 4 of these similar skills score higher than yao-secret; compare them before choosing.

SkillScoreStarsUpdatedFormat
yao-secret (this skill)by YaoApp828.0k4d agoSKILL.md
Agent-Reachby Panniantong10085.8k12d agoCLAUDE.md
headroomby headroomlabs-ai10074.0k1d agoCLAUDE.md
ai-job-searchby MadsLorentzen10044.2ktodayCLAUDE.md
claude-howtoby luongnv8910041.7k1d agoCLAUDE.md

Frequently asked questions

How do I install yao-secret?
Run npx skills add YaoApp/yao --skill yao-secret. The install tabs above show the steps for each supported agent.
Which AI agents does yao-secret work with?
It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
Is yao-secret safe to use?
It declares no license and scores 88/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is yao-secret still maintained?
The repository was last updated 4 days ago, so yao-secret is actively maintained.

name: yao-secret description: Secret management expert. ALWAYS invoke this skill when you need to read API keys, tokens, or other secrets configured by the user. Never hardcode credentials — use this skill to retrieve them securely.

Secret Tools

Two tools for accessing user-configured secrets, called via bash.

secret_list

List available secret names and descriptions. Does not return secret values — use secret_read for that.

tai tool secret_list '{}'

No parameters required. Returns secrets configured for the current assistant.

secret_read

Read a secret value by name. Returns the decrypted value for use in scripts.

tai tool secret_read '{"name": "GITHUB_TOKEN"}'
tai tool secret_read '{"name": "AWS_SECRET_KEY"}'

| Parameter | Type | Required | Description | |-----------|--------|----------|----------------------------------------------------------| | name | string | yes | Secret key name (e.g. GITHUB_TOKEN, AWS_SECRET_KEY) |

Security: Never log, print, or expose the returned secret value in output visible to users.

Typical Workflow

  1. secret_list — discover what secrets are available
  2. secret_read — retrieve a specific secret by name
  3. Use the value in API calls, git auth, etc.

Guidelines

  • Always call secret_list first to check if a required secret exists before reading
  • Never hardcode API keys or tokens — always use secret_read
  • Secret values are decrypted at read time; treat them as sensitive
  • If a secret is not found, prompt the user to configure it in their settings
  • All output is JSON

Related Skills

View on GitHub
GitHub Stars8.0k
CategoryDevelopment
Updated4d ago
Forks716

Languages

Go

Trust signals

88/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

1 medium