Agent skill

Env Manager

by bobmatnyc in bobmatnyc/claude-mpm

Environment variable validation, security scanning, and management for Next.js, Vite, React, and Node.js applications

Custom licenceAuto-check: notesDevOps & Cloud

Install Env Manager

skills CLI
$ npx skills add bobmatnyc/claude-mpm --skill env-manager -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bobmatnyc/claude-mpm env-manager --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bobmatnyc/claude-mpm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugin/skills/universal-infrastructure-env-manager .claude/skills/env-manager && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
env-manager
GitHub stars
155
Token cost
~3.9k tokens
SKILL.md length
1,099 words
Files
9 (incl. references)
Skills in repo
52
Repo updated
First seen
Licence
Custom licence

At a glance

Environment variable validation, security scanning, and management for Next.js, Vite, React, and Node.js applications

  • Works in 4 steps: Never Logs Secrets: env-manager NEVER… → Client-Exposure Detection: Warns when… → Secret Sanitization: When generating… → …
  • Tasks that involve Secrets management
  • SKILL.md covers Overview, Why Use env-manager?, Quick Start and Usage Examples, plus 6 more sections
  • Calls python3, git and make; needs API_KEY and STRIPE_SECRET_KEY

What it does

Env Manager is an agent skill from bobmatnyc/claude-mpm. Environment variable validation, security scanning, and management for Next.js, Vite, React, and Node.js applications

Its SKILL.md is about 3.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including reference files (for example `.etag_cache.json`, `metadata.json` and `references/.etag_cache.json`).

It sits in DevOps & Cloud, covering Secrets management. It works with Next.js, React, Node.js and Vite. The repository describes itself as: Claude Multi-Agent Project Manager — multi-channel orchestration, GitHub-first SDK mode, and plugin system for Claude.

When your agent uses it

  • Tasks that involve Secrets management

Example prompts

  • “/env-manager”

Requirements

  • Python 3
  • Node.js
  • A credential in NEXT_PUBLIC_API_KEY
  • A credential in STRIPE_SECRET_KEY

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Never Logs Secrets: env-manager NEVER displays actual secret values in output
  2. Client-Exposure Detection: Warns when secrets are in NEXT_PUBLIC_, VITE_, REACT_APP_ variables
  3. Secret Sanitization: When generating .env.example, replaces secrets with safe placeholders
  4. No Network Calls: All validation is local, no data leaves your machine

What it can do on your machine

Read from SKILL.md and the folder at commit 25203d3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3
    • git
    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • img.shields.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY
    • STRIPE_SECRET_KEY
    • NEXT_PUBLIC_API_KEY
    • NEXT_PUBLIC_STRIPE_SECRET
    • NEW_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Env Manager loads about 3.9k tokens when it runs, and up to ~19k if it reads all its reference files. Until then it costs about 32 tokens; SKILL.md has 1,099 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~32
When it runs · the whole SKILL.md, loaded when a task matches
~3.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~19k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:41
    - Inconsistent .env files across team members
  • NoteMentions a .env fileSKILL.md:58
    # 1. Validate your .env file
  • NoteMentions a .env fileSKILL.md:59
    python3 scripts/validate_env.py .env
  • NoteMentions a .env fileSKILL.md:62
    python3 scripts/validate_env.py .env --framework nextjs
  • NoteMentions a .env fileSKILL.md:65
    python3 scripts/validate_env.py .env --compare-with .env.example
  • NoteMentions a .env fileSKILL.md:68
    python3 scripts/validate_env.py .env --generate-example .env.example
  • NoteMentions a .env fileSKILL.md:71
    python3 scripts/validate_env.py .env --json
  • NoteMentions a .env fileSKILL.md:80
    Validate a .env file for structural issues:
  • NoteMentions a .env fileSKILL.md:83
    python3 scripts/validate_env.py .env
  • NoteMentions a .env fileSKILL.md:108
    python3 scripts/validate_env.py .env.local --framework nextjs

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 1,099 words (~3,935 tokens).

“Comprehensive environment variable validation, security scanning, and management for modern web applications.”

— opening of SKILL.md by bobmatnyc, Custom licence
name
env-manager
progressive_disclosure.references
frameworks.md, security.md, synchronization.md, troubleshooting.md, validation.md

Read the full SKILL.md on GitHub

Files

SKILL.md and 8 other files (references) in plugin/skills/universal-infrastructure-env-manager of bobmatnyc/claude-mpm.

  • SKILL.md
  • .etag_cache.json
  • metadata.json
  • references/.etag_cache.json
  • references/frameworks.md
  • references/security.md
  • references/synchronization.md
  • references/troubleshooting.md
  • references/validation.md

Open the folder on GitHubat commit 25203d3

Compare with similar skills

Env Manager next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Env Manager compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Env Manager this skillbobmatnyc/claude-mpm155—~3.9kAutomated safety check: NotesCustom licence
Arkenvyamcodes/arkenv145—~2.5kAutomated safety check: PassMIT
Convex Self Hostingwaynesutton/markdown-site628—~1.4kAutomated safety check: PassMIT
Add React Analyticsgotempsh/temps826—~2.7kAutomated safety check: PassApache-2.0
Docker Containerizationailabs-393/ai-labs-claude-skills454—~2.1kAutomated safety check: NotesMIT
Fullstack DevHHU3637kr/skills1453 repos~8.6kAutomated safety check: NotesMIT

Similar skills

  • Arkenv

    yamcodes/arkenv

    Answer questions about ArkEnv and help implement environment variable validation.

    145 GitHub stars~2.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Convex Self Hosting

    waynesutton/markdown-site

    Integrate Convex static self hosting into existing apps using the latest upstream instructions from get-convex/self-hosting every time.

    628 GitHub stars~1.4k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed
  • Add React Analytics

    gotempsh/temps

    Add Temps analytics to React applications with comprehensive tracking capabilities including page views, custom events, scroll tracking, engagement monitoring, session recording, and Web Vitals…

    826 GitHub stars~2.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Docker Containerization

    ailabs-393/ai-labs-claude-skills

    This skill should be used when containerizing applications with Docker, creating Dockerfiles, docker-compose configurations, or deploying containers to various platforms.

    454 GitHub stars~2.1k tokensUpdated 11 mo ago
    DevOps & CloudAuto-check: notes
  • Fullstack Dev

    HHU3637kr/skills

    Full-stack backend architecture and frontend-backend integration guide.

    145 GitHub starsUsed in 3 repos~8.6k tokens
    Backend & APIsAuto-check: notes
  • Deploy To Temps

    gotempsh/temps

    Deploy applications to the Temps platform with automatic framework detection, Dockerfile generation, and container orchestration.

    826 GitHub stars~1.3k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from bobmatnyc/claude-mpm

All 52 skills in this repo
  • Build MCP Server

    bobmatnyc/claude-mpm

    Create high-quality MCP servers that enable LLMs to effectively interact with external services.

    155 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Env Manager

    bobmatnyc/claude-mpm

    Environment variable validation, synchronization, and management across local development, CI/CD, and deployment platforms

    155 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check: notes
  • Session Analyzer

    bobmatnyc/claude-mpm

    Debug and teach agentic coding: a deterministic-first session timeline + cost report, with optional narrative polish and a standalone JSX visualiser.

    155 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Software Patterns

    bobmatnyc/claude-mpm

    Decision framework for architectural patterns including DI, SOA, Repository, Domain Events, Circuit Breaker, and Anti-Corruption Layer.

    155 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Verification Before Completion

    bobmatnyc/claude-mpm

    Run verification commands and confirm output before claiming success

    155 GitHub starsUsed in 2 repos~1k tokens
    Auto-check passed
  • Dependency Audit

    bobmatnyc/claude-mpm

    Dependency audit and cleanup workflow for maintaining healthy project dependencies.

    155 GitHub stars~3.5k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Env Manager

What does Env Manager do?

Environment variable validation, security scanning, and management for Next.js, Vite, React, and Node.js applications. Env Manager is an agent skill from bobmatnyc/claude-mpm.

When should I use Env Manager?

Env Manager fits situations like: tasks that involve Secrets management.

How do I install Env Manager in Claude Code?

Run `npx skills add bobmatnyc/claude-mpm --skill env-manager -a claude-code`. Or copy the skill folder (plugin/skills/universal-infrastructure-env-manager in bobmatnyc/claude-mpm) into .claude/skills/env-manager in your project. Claude Code loads it when a task matches its description.

How do I install Env Manager in Codex?

Run `npx skills add bobmatnyc/claude-mpm --skill env-manager -a codex`. Or copy the skill folder (plugin/skills/universal-infrastructure-env-manager in bobmatnyc/claude-mpm) into .agents/skills/env-manager in your project. Codex loads it when a task matches its description.

Can I use Env Manager in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bobmatnyc/claude-mpm --skill env-manager -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/env-manager, .gemini/skills/env-manager, .github/skills/env-manager and .opencode/skills/env-manager in your project.

What does Env Manager need to run?

Going by SKILL.md and its folder, Env Manager needs the command-line tools its instructions call (python3, git and make) and credentials named API_KEY, STRIPE_SECRET_KEY, NEXT_PUBLIC_API_KEY and NEXT_PUBLIC_STRIPE_SECRET. Our summary lists: Python 3; Node.js; A credential in NEXT_PUBLIC_API_KEY; A credential in STRIPE_SECRET_KEY.

Does Env Manager access the network?

SKILL.md names 1 domain. As links in the text: img.shields.io. This is read from the text; nothing was executed.

Is Env Manager safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Env Manager use?

Env Manager has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Env Manager use?

About 3.9k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 15k tokens, read only when the agent opens those files.

What are the alternatives to Env Manager?

Skills that share tags, products or a category with Env Manager: Arkenv (yamcodes/arkenv, 145 stars), Convex Self Hosting (waynesutton/markdown-site, 628 stars), Add React Analytics (gotempsh/temps, 826 stars) and Docker Containerization (ailabs-393/ai-labs-claude-skills, 454 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Env Manager?

bobmatnyc (a GitHub user) maintains it in bobmatnyc/claude-mpm, which has 155 GitHub stars. The repository holds 52 skills in this directory. The repository was last updated on August 31, 2026.

Source: bobmatnyc/claude-mpm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.