Agent skill

Sops Encryption

by BagelHole in BagelHole/DevOps-Security-Agent-Skills

Encrypt files and configs with Mozilla SOPS. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

MITAuto-check passedDevOps & Cloud

Install Sops Encryption

skills CLI
$ npx skills add BagelHole/DevOps-Security-Agent-Skills --skill sops-encryption -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BagelHole/DevOps-Security-Agent-Skills sops-encryption --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/security/secrets/sops-encryption .claude/skills/sops-encryption && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sops-encryption
GitHub stars
1.1k
Token cost
~539 tokens
SKILL.md length
85 words
Files
1
Skills in repo
39
Repo updated
First seen
Licence
MIT

At a glance

Encrypt files and configs with Mozilla SOPS. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

  • Encrypting configuration files
  • SKILL.md covers When to Use This Skill, Prerequisites, Installation and Basic Usage, plus 4 more sections
  • Calls brew and wget; reaches github.com
  • Kubernetes secrets

What it does

Sops Encryption is an agent skill from BagelHole/DevOps-Security-Agent-Skills. Encrypt files and configs with Mozilla SOPS. Integrate with AWS KMS, GCP KMS, or PGP for key management. Use when encrypting configuration files, Kubernetes secrets, or implementing GitOps with encrypted secrets.

Its SKILL.md is about 540 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Operations and SOPs, Cryptography and Container orchestration. It works with Kubernetes, Amazon Web Services and Google Cloud. The repository describes itself as: Agent-ready DevOps, security, infrastructure, and compliance knowledge base with 80+ skills across Kubernetes, Terraform, AWS/Azure/GCP, AI platform operations, container… The licence is MIT.

When your agent uses it

  • Encrypting configuration files
  • Kubernetes secrets
  • Implementing GitOps with encrypted secrets

Example prompts

  • “/sops-encryption”

What it can do on your machine

Read from SKILL.md and the folder at commit 0365f57. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • brew
    • wget

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sops Encryption loads about 539 tokens when it runs. Until then it costs about 57 tokens; SKILL.md has 85 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~539

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from BagelHole/DevOps-Security-Agent-Skills at commit 0365f57, republished under its MIT licence (© BagelHole). 85 words, ~539 tokens.

Download SKILL.mdSave it as .claude/skills/sops-encryption/SKILL.md (or your agent's skills folder).
name
sops-encryption
description
Encrypt files and configs with Mozilla SOPS. Integrate with AWS KMS, GCP KMS, or PGP for key management. Use when encrypting configuration files, Kubernetes secrets, or implementing GitOps with encrypted secrets.
license
MIT
metadata.author
devops-skills
metadata.version
1.0

SOPS Encryption

Encrypt secrets in configuration files while keeping structure visible.

When to Use This Skill

Use this skill when:

  • Encrypting secrets in Git
  • Implementing GitOps with secrets
  • Managing Kubernetes secrets as code
  • Encrypting configuration files

Prerequisites

  • SOPS installed
  • KMS access (AWS, GCP, Azure) or PGP key

Installation

bash
# macOS
brew install sops

# Linux
wget https://github.com/getsops/sops/releases/download/v3.8.0/sops-v3.8.0.linux.amd64
chmod +x sops-v3.8.0.linux.amd64
mv sops-v3.8.0.linux.amd64 /usr/local/bin/sops

Basic Usage

bash
# Encrypt with AWS KMS
sops --encrypt --kms arn:aws:kms:region:account:key/key-id secrets.yaml > secrets.enc.yaml

# Decrypt
sops --decrypt secrets.enc.yaml

# Edit encrypted file
sops secrets.enc.yaml

# Encrypt in place
sops --encrypt --in-place secrets.yaml

Configuration

yaml
# .sops.yaml
creation_rules:
  - path_regex: .*\.prod\.yaml$
    kms: arn:aws:kms:us-east-1:account:key/prod-key
  - path_regex: .*\.dev\.yaml$
    kms: arn:aws:kms:us-east-1:account:key/dev-key
  - path_regex: .*
    pgp: fingerprint

Kubernetes Integration

yaml
# encrypted secret
apiVersion: v1
kind: Secret
metadata:
  name: myapp-secrets
type: Opaque
stringData:
  password: ENC[AES256_GCM,data:encrypted...]
sops:
  kms:
    - arn: arn:aws:kms:region:account:key/key-id
bash
# With ArgoCD
# Install ksops plugin for ArgoCD to decrypt secrets

Best Practices

  • Store .sops.yaml in repository
  • Use different keys per environment
  • Rotate encryption keys regularly
  • Never commit unencrypted secrets
  • Use key aliases for readability

© BagelHole, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in security/secrets/sops-encryption of BagelHole/DevOps-Security-Agent-Skills.

Open the folder on GitHubat commit 0365f57

Compare with similar skills

Sops Encryption next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sops Encryption compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sops Encryption this skillBagelHole/DevOps-Security-Agent-Skills1.1k—~539Automated safety check: PassMIT
Devopsnicepkg/auto-company1922 repos~814Automated safety check: PassMIT
Provider Bug Reviewmondoohq/mql411—~2.9kAutomated safety check: PassCustom licence
Kcli Cluster Deploymentkarmab/kcli653—~1.5kAutomated safety check: PassApache-2.0
Logfire Infrastructurepydantic/skills140—~1.8kAutomated safety check: PassMIT
Extend Discovery Typerunwhen-contrib/runwhen-local163—~1.7kAutomated safety check: PassApache-2.0

Similar skills

  • Devops

    nicepkg/auto-company

    Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm).

    192 GitHub starsUsed in 2 repos~814 tokens
    DevOps & CloudAuto-check passed
  • Deep static code review of an mql provider for logic errors, nil-handling bugs, pagination truncation, caching/id collisions, and other defects that silently give users wrong data.

    411 GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Guides deployment and management of Kubernetes clusters with kcli.

    653 GitHub stars~1.5k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Logfire Infrastructure

    pydantic/skills

    Official

    Monitor hosts, Docker containers, Kubernetes clusters, database/queue/cache servers, and cloud-provider metrics with Pydantic Logfire — no application code required.

    140 GitHub stars~1.8k tokensUpdated 7 days ago
    DevOps & CloudAuto-check passed
  • Extend Discovery Type

    runwhen-contrib/runwhen-local

    Add or enrich a resource type in an existing RunWhen Local discovery indexer (Azure azureapi, GCP gcpapi, AWS, or Kubernetes).

    163 GitHub stars~1.7k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Kcli

    karmab/kcli

    Comprehensive guide for kcli usage. An agent skill from karmab/kcli.

    653 GitHub stars~2.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: warnings

More from BagelHole/DevOps-Security-Agent-Skills

All 39 skills in this repo
  • Hashicorp Vault

    BagelHole/DevOps-Security-Agent-Skills

    Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~2k tokensUpdated 4 mo ago
    Auto-check passed
  • Incident Response

    BagelHole/DevOps-Security-Agent-Skills

    Handle security incidents with IR playbooks and procedures. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~4.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Kubernetes Ops

    BagelHole/DevOps-Security-Agent-Skills

    Deploy, scale, and manage Kubernetes workloads. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~2.3k tokensUpdated 4 mo ago
    Auto-check passed
  • Linux Hardening

    BagelHole/DevOps-Security-Agent-Skills

    Apply CIS benchmarks and secure Linux servers. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~662 tokensUpdated 4 mo ago
    Auto-check: notes
  • Prometheus Grafana

    BagelHole/DevOps-Security-Agent-Skills

    Set up metrics collection and visualization with Prometheus and Grafana.

    1.1k GitHub stars~2.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Vulnerability Scanning

    BagelHole/DevOps-Security-Agent-Skills

    Scan systems and dependencies for CVEs and security vulnerabilities.

    1.1k GitHub stars~2.4k tokensUpdated 4 mo ago
    Auto-check passed

Categories

Questions about Sops Encryption

What does Sops Encryption do?

Encrypt files and configs with Mozilla SOPS. An agent skill from BagelHole/DevOps-Security-Agent-Skills. Sops Encryption is an agent skill from BagelHole/DevOps-Security-Agent-Skills. Encrypt files and configs with Mozilla SOPS.

When should I use Sops Encryption?

Sops Encryption fits situations like: encrypting configuration files; Kubernetes secrets; implementing GitOps with encrypted secrets.

How do I install Sops Encryption in Claude Code?

Run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill sops-encryption -a claude-code`. Or copy the skill folder (security/secrets/sops-encryption in BagelHole/DevOps-Security-Agent-Skills) into .claude/skills/sops-encryption in your project. Claude Code loads it when a task matches its description.

How do I install Sops Encryption in Codex?

Run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill sops-encryption -a codex`. Or copy the skill folder (security/secrets/sops-encryption in BagelHole/DevOps-Security-Agent-Skills) into .agents/skills/sops-encryption in your project. Codex loads it when a task matches its description.

Can I use Sops Encryption in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill sops-encryption -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sops-encryption, .gemini/skills/sops-encryption, .github/skills/sops-encryption and .opencode/skills/sops-encryption in your project.

What does Sops Encryption need to run?

Going by SKILL.md and its folder, Sops Encryption needs the command-line tools its instructions call (brew and wget).

Does Sops Encryption access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Sops Encryption safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sops Encryption use?

Sops Encryption is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sops Encryption use?

About 539 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sops Encryption?

Skills that share tags, products or a category with Sops Encryption: Devops (nicepkg/auto-company, 192 stars), Provider Bug Review (mondoohq/mql, 411 stars), Kcli Cluster Deployment (karmab/kcli, 653 stars) and Logfire Infrastructure (pydantic/skills, 140 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sops Encryption?

BagelHole (a GitHub user) maintains it in BagelHole/DevOps-Security-Agent-Skills, which has 1,142 GitHub stars. The repository holds 39 skills in this directory. The repository was last updated on May 22, 2026.

Source: BagelHole/DevOps-Security-Agent-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.