Agent skill

Varlock Claude Skill

by aiskillstore in aiskillstore/marketplace

Secure environment variable management ensuring secrets are never exposed in Claude sessions, terminals, logs, or git commits

No licenceAuto-check passedDevelopment

Install Varlock Claude Skill

skills CLI
$ npx skills add aiskillstore/marketplace --skill varlock-claude-skill -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aiskillstore/marketplace varlock-claude-skill --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sickn33/varlock-claude-skill .claude/skills/varlock-claude-skill && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
varlock-claude-skill
GitHub stars
433
Used in
5 other repos
Token cost
~226 tokens
SKILL.md length
84 words
Files
2
Skills in repo
1,044
Repo updated
First seen
Licence
None found

At a glance

Secure environment variable management ensuring secrets are never exposed in Claude sessions, terminals, logs, or git commits

  • Tasks that involve Commit messages
  • SKILL.md covers Overview, When to Use This Skill and Instructions
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Secrets management

What it does

Varlock Claude Skill is an agent skill from aiskillstore/marketplace. Secure environment variable management ensuring secrets are never exposed in Claude sessions, terminals, logs, or git commits

Its SKILL.md is about 230 tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `skill-report.json`).

It sits in Development, covering Commit messages and Secrets management. The repository describes itself as: Security-audited skills for Claude, Codex & Claude Code. One-click install, quality verified.

When your agent uses it

  • Tasks that involve Commit messages
  • Tasks that involve Secrets management

Example prompts

  • “/varlock-claude-skill”

What it can do on your machine

Read from SKILL.md and the folder at commit 44923f3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Varlock Claude Skill loads about 226 tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 84 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~226

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 84 words (~226 tokens).

“Secure environment variable management ensuring secrets are never exposed in Claude sessions, terminals, logs, or git commits”

— opening of SKILL.md by aiskillstore
name
varlock-claude-skill
source
https://github.com/wrsmith108/varlock-claude-skill
risk
safe

Read the full SKILL.md on GitHub

Files

SKILL.md and 1 other file in skills/sickn33/varlock-claude-skill of aiskillstore/marketplace.

  • SKILL.md
  • skill-report.json

Open the folder on GitHubat commit 44923f3

Used in 5 other repositories

We found 14 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 5 other GitHub owners. This page covers the copy in aiskillstore/marketplace, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Varlock Claude Skill next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Varlock Claude Skill compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Varlock Claude Skill this skillaiskillstore/marketplace4335 repos~226Automated safety check: PassNone
Git HooksProrise-cool/Claude-Code-Multi-Agent306—~3.6kAutomated safety check: NotesNone
Secret Scanneralirezarezvani/claude-code-tresor777—~1.4kAutomated safety check: WarnMIT
Codex GuardAkimiya-z/codex-guard136—~564Automated safety check: PassMIT
Git Conventionswerf/werf4.7k—~1.3kAutomated safety check: PassApache-2.0
Git Gh Pat AuthNEventStore/NEventStore1.6k—~828Automated safety check: PassMIT

Similar skills

  • Git Hooks

    Prorise-cool/Claude-Code-Multi-Agent

    Central authority on git hook implementations, modern best practices, and tooling for .NET/C, JavaScript/TypeScript, Python, and polyglot repositories.

    306 GitHub stars~3.6k tokensUpdated 24 days ago
    DevelopmentAuto-check: notes
  • Secret Scanner

    alirezarezvani/claude-code-tresor

    Detect exposed secrets, API keys, credentials, and tokens in code.

    777 GitHub stars~1.4k tokensUpdated 3 mo ago
    DevelopmentAuto-check: warnings
  • Codex Guard

    Akimiya-z/codex-guard

    Pre-submit hygiene check for AI-agent-authored pull requests.

    136 GitHub stars~564 tokensUpdated 8 days ago
    DevelopmentAuto-check passed
  • werf conventions for branch names and commit messages. An agent skill from werf/werf.

    4.7k GitHub stars~1.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Git Gh Pat Auth

    NEventStore/NEventStore

    A skill your agent uses when: authenticating git and GitHub CLI for NEventStore tasks, fixing gh auth errors, setting PAT environment variables, preparing a shell session for git push and gh issue…

    1.6k GitHub stars~828 tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Commit

    ansible-collections/community.postgresql

    This skill should be used when the user asks to 'commit', 'create a commit', or 'git commit'.

    144 GitHub stars~553 tokensUpdated 16 days ago
    DevelopmentAuto-check passed

More from aiskillstore/marketplace

All 1,044 skills in this repo
  • Code Stats

    aiskillstore/marketplace

    Analyze codebase with tokei (fast line counts by language) and difft (semantic AST-aware diffs).

    433 GitHub starsUsed in 1 repo~697 tokens
    Auto-check: notes
  • Data Processing

    aiskillstore/marketplace

    Process JSON with jq and YAML/TOML with yq. An agent skill from aiskillstore/marketplace.

    433 GitHub starsUsed in 1 repo~720 tokens
    Auto-check: notes
  • Doc Scanner

    aiskillstore/marketplace

    Scans for project documentation files (AGENTS.md, CLAUDE.md, GEMINI.md, COPILOT.md, CURSOR.md, WARP.md, and 15+ other formats) and synthesizes guidance.

    433 GitHub starsUsed in 1 repo~644 tokens
    Auto-check: notes
  • File Search

    aiskillstore/marketplace

    Modern file and content search using fd, ripgrep (rg), and fzf.

    433 GitHub starsUsed in 1 repo~598 tokens
    Auto-check: notes
  • Find Replace

    aiskillstore/marketplace

    Modern find-and-replace using sd (simpler than sed) and batch replacement patterns.

    433 GitHub starsUsed in 1 repo~527 tokens
    Auto-check: notes
  • Project Planner

    aiskillstore/marketplace

    Detects stale project plans and suggests session commands. An agent skill from aiskillstore/marketplace.

    433 GitHub starsUsed in 1 repo~504 tokens
    Auto-check passed

Questions about Varlock Claude Skill

What does Varlock Claude Skill do?

Secure environment variable management ensuring secrets are never exposed in Claude sessions, terminals, logs, or git commits. Varlock Claude Skill is an agent skill from aiskillstore/marketplace.

When should I use Varlock Claude Skill?

Varlock Claude Skill fits situations like: tasks that involve Commit messages; tasks that involve Secrets management.

How do I install Varlock Claude Skill in Claude Code?

Run `npx skills add aiskillstore/marketplace --skill varlock-claude-skill -a claude-code`. Or copy the skill folder (skills/sickn33/varlock-claude-skill in aiskillstore/marketplace) into .claude/skills/varlock-claude-skill in your project. Claude Code loads it when a task matches its description.

How do I install Varlock Claude Skill in Codex?

Run `npx skills add aiskillstore/marketplace --skill varlock-claude-skill -a codex`. Or copy the skill folder (skills/sickn33/varlock-claude-skill in aiskillstore/marketplace) into .agents/skills/varlock-claude-skill in your project. Codex loads it when a task matches its description.

Can I use Varlock Claude Skill in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aiskillstore/marketplace --skill varlock-claude-skill -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/varlock-claude-skill, .gemini/skills/varlock-claude-skill, .github/skills/varlock-claude-skill and .opencode/skills/varlock-claude-skill in your project.

What does Varlock Claude Skill need to run?

SKILL.md names no scripts, command-line tools or credentials: Varlock Claude Skill is instructions for the agent only.

Does Varlock Claude Skill access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Varlock Claude Skill safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Varlock Claude Skill use?

No licence was found for Varlock Claude Skill or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Varlock Claude Skill use?

About 226 tokens (SKILL.md is roughly 904 characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Varlock Claude Skill?

Skills that share tags, products or a category with Varlock Claude Skill: Git Hooks (Prorise-cool/Claude-Code-Multi-Agent, 306 stars), Secret Scanner (alirezarezvani/claude-code-tresor, 777 stars), Codex Guard (Akimiya-z/codex-guard, 136 stars) and Git Conventions (werf/werf, 4.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Varlock Claude Skill?

aiskillstore (a GitHub organization) maintains it in aiskillstore/marketplace, which has 433 GitHub stars. The repository holds 1,044 skills in this directory. The repository was last updated on October 10, 2026.

Source: aiskillstore/marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.