yao-secret
Secret management expert. ALWAYS invoke this skill when you need to read API keys, tokens, or other secrets configured by the user. Never hardcode credentials — use this skill to retrieve them securely.
Install / Use
npx skills add YaoApp/yao --skill yao-secretInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Our assessment of yao-secret
yao-secret scores 82/100 on our quality scale, 1633rd of 3,044 Development & Engineering skills we index.
Its SKILL.md is 1.6 KB long, split into 5 sections with 2 code examples: moderately detailed.
With 8,024 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 4 days ago, so yao-secret is actively maintained.
- No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
- Its trust signals score 88/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
yao-secret compared with similar skills
All 4 of these similar skills score higher than yao-secret; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| yao-secret (this skill)by YaoApp | 82 | 8.0k | 4d ago | SKILL.md |
| Agent-Reachby Panniantong | 100 | 85.8k | 12d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.0k | 1d ago | CLAUDE.md |
| ai-job-searchby MadsLorentzen | 100 | 44.2k | today | CLAUDE.md |
| claude-howtoby luongnv89 | 100 | 41.7k | 1d ago | CLAUDE.md |
Frequently asked questions
- How do I install yao-secret?
- Run
npx skills add YaoApp/yao --skill yao-secret. The install tabs above show the steps for each supported agent. - Which AI agents does yao-secret work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is yao-secret safe to use?
- It declares no license and scores 88/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is yao-secret still maintained?
- The repository was last updated 4 days ago, so yao-secret is actively maintained.
Skill content
View source on GitHubname: yao-secret description: Secret management expert. ALWAYS invoke this skill when you need to read API keys, tokens, or other secrets configured by the user. Never hardcode credentials — use this skill to retrieve them securely.
Secret Tools
Two tools for accessing user-configured secrets, called via bash.
secret_list
List available secret names and descriptions. Does not return secret values — use secret_read for that.
tai tool secret_list '{}'
No parameters required. Returns secrets configured for the current assistant.
secret_read
Read a secret value by name. Returns the decrypted value for use in scripts.
tai tool secret_read '{"name": "GITHUB_TOKEN"}'
tai tool secret_read '{"name": "AWS_SECRET_KEY"}'
| Parameter | Type | Required | Description |
|-----------|--------|----------|----------------------------------------------------------|
| name | string | yes | Secret key name (e.g. GITHUB_TOKEN, AWS_SECRET_KEY) |
Security: Never log, print, or expose the returned secret value in output visible to users.
Typical Workflow
secret_list— discover what secrets are availablesecret_read— retrieve a specific secret by name- Use the value in API calls, git auth, etc.
Guidelines
- Always call
secret_listfirst to check if a required secret exists before reading - Never hardcode API keys or tokens — always use
secret_read - Secret values are decrypted at read time; treat them as sensitive
- If a secret is not found, prompt the user to configure it in their settings
- All output is JSON
Related Skills
Agent-Reach
85.8kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.0kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
ai-job-search
44.2kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
claude-howto
41.7kA visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
