Agent skill

Env Manager

by bobmatnyc in bobmatnyc/claude-mpm

Environment variable validation, synchronization, and management across local development, CI/CD, and deployment platforms

MITAuto-check: notesDevOps & Cloud

Install Env Manager

skills CLI
$ npx skills add bobmatnyc/claude-mpm --skill env-manager -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bobmatnyc/claude-mpm env-manager --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bobmatnyc/claude-mpm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/claude_mpm/skills/bundled/infrastructure/env-manager .claude/skills/env-manager && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
env-manager
GitHub stars
155
Token cost
~2k tokens
SKILL.md length
439 words
Files
10 (incl. scripts, references)
Skills in repo
51
Repo updated
First seen
Licence
MIT

At a glance

Environment variable validation, synchronization, and management across local development, CI/CD, and deployment platforms

  • Works in 5 steps: Never Log Secrets: All operations must… → Validate Before Deploy: Catch env issues… → Framework-Aware: Respect framework… → …
  • Tasks that involve Secrets management
  • SKILL.md covers Overview, When to Use This Skill, Core Principles and Quick Start, plus 6 more sections
  • Runs Python scripts from its folder; calls python

What it does

Env Manager is an agent skill from bobmatnyc/claude-mpm. Environment variable validation, synchronization, and management across local development, CI/CD, and deployment platforms

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 12 other files, including scripts and reference files (for example `INTEGRATION.md`, `README.md` and `examples/nextjs-env-structure.md`).

It sits in DevOps & Cloud, covering Secrets management, CI/CD and Deployment. It works with Next.js, Flask and Vercel. The repository describes itself as: Claude Multi-Agent Project Manager — multi-channel orchestration, GitHub-first SDK mode, and plugin system for Claude. The licence is MIT.

When your agent uses it

  • Tasks that involve Secrets management
  • Tasks that involve CI/CD
  • Tasks that involve Deployment

Example prompts

  • “/env-manager”

Requirements

  • Python 3
  • Node.js
  • Docker

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Never Log Secrets: All operations must NEVER display actual secret values
  2. Validate Before Deploy: Catch env issues locally, not in production
  3. Framework-Aware: Respect framework conventions (Next.js, Express, Flask)
  4. Platform-Specific: Generate correct configs for each deployment platform
  5. Security First: Scan for exposed secrets, validate .gitignore

What it can do on your machine

Read from SKILL.md and the folder at commit 25203d3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Env Manager loads about 2k tokens when it runs, and up to ~17k if it reads all its reference files. Until then it costs about 34 tokens; SKILL.md has 439 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~34
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~17k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:9
    when_to_use: "When managing .env files, deploying to Vercel/Railway/Heroku, syncing with secret managers, or trouble
  • NoteMentions a .env fileSKILL.md:10
    quick_start: "1. Validate local .env 2. Check security 3. Sync to platform 4. Verify deployment 5. Generate document
  • NoteMentions a .env fileSKILL.md:72
    # 1. Check local .env structure
  • NoteMentions a .env fileSKILL.md:73
    python scripts/validate_env.py .env
  • NoteMentions a .env fileSKILL.md:76
    python scripts/validate_env.py .env --compare .env.example
  • NoteMentions a .env fileSKILL.md:79
    python scripts/validate_env.py .env --framework nextjs
  • NoteMentions a .env fileSKILL.md:82
    python scripts/validate_env.py .env --check-duplicates
  • NoteMentions a .env fileSKILL.md:94
    ripts/scan_exposed.py --validate-formats .env
  • NoteMentions a .env fileSKILL.md:114
    # Generate .env.example from .env
  • NoteMentions a .env fileSKILL.md:115
    python scripts/validate_env.py .env --generate-example

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from bobmatnyc/claude-mpm at commit 25203d3, republished under its MIT licence (© bobmatnyc). 439 words, ~2,042 tokens.

Download SKILL.mdSave it as .claude/skills/env-manager/SKILL.md (or your agent's skills folder). This skill also uses 9 other files; get the full folder from GitHub.
name
env-manager
description
Environment variable validation, synchronization, and management across local development, CI/CD, and deployment platforms
version
1.0.0
category
infrastructure
progressive_disclosure.references
validation.md, security.md, synchronization.md, frameworks.md, troubleshooting.md
author
Claude MPM Team
license
MIT
requires_tools
bash, python
tags
environment-variables, deployment, security, devops, nextjs, vercel, railway
context_limit
800
effort
medium

Environment Variable Manager

Overview

Manage environment variables systematically across local development, CI/CD pipelines, and deployment platforms. Prevent common issues like missing variables, exposed secrets, platform misconfigurations, and framework-specific gotchas.

Core capabilities:

  • Validation: Check structure, completeness, naming conventions
  • Security: Scan for exposed secrets, validate .gitignore coverage
  • Synchronization: Sync with deployment platforms and secret managers
  • Framework Support: Next.js, Express, Flask, Django patterns
  • Documentation: Auto-generate .env.example and setup guides

When to Use This Skill

Activate when:

  • Setting up new project environment configuration
  • Deploying to Vercel, Railway, Heroku, or other platforms
  • Troubleshooting "works locally but not in production"
  • Managing secrets across multiple environments
  • Syncing variables with 1Password, AWS Secrets Manager
  • Creating .env.example documentation
  • Onboarding new developers (environment setup)
  • Migrating between deployment platforms
  • Framework-specific env configuration (Next.js NEXT_PUBLIC_ prefix)

Core Principles

  1. Never Log Secrets: All operations must NEVER display actual secret values
  2. Validate Before Deploy: Catch env issues locally, not in production
  3. Framework-Aware: Respect framework conventions (Next.js, Express, Flask)
  4. Platform-Specific: Generate correct configs for each deployment platform
  5. Security First: Scan for exposed secrets, validate .gitignore

Quick Start

Validation Workflow
bash
# 1. Check local .env structure
python scripts/validate_env.py .env

# 2. Check for missing variables
python scripts/validate_env.py .env --compare .env.example

# 3. Validate naming conventions
python scripts/validate_env.py .env --framework nextjs

# 4. Check for duplicates
python scripts/validate_env.py .env --check-duplicates
Security Workflow
bash
# 1. Scan for exposed secrets in code
python scripts/scan_exposed.py --scan-code

# 2. Check .gitignore coverage
python scripts/scan_exposed.py --check-gitignore

# 3. Validate secret formats
python scripts/scan_exposed.py --validate-formats .env
Synchronization Workflow
bash
# 1. Compare local vs platform
python scripts/sync_secrets.py --platform vercel --compare

# 2. Generate platform config
python scripts/sync_secrets.py --platform vercel --generate

# 3. Sync to platform (dry-run first)
python scripts/sync_secrets.py --platform vercel --sync --dry-run

# 4. Actual sync
python scripts/sync_secrets.py --platform vercel --sync
Documentation Workflow
bash
# Generate .env.example from .env
python scripts/validate_env.py .env --generate-example

# Generate setup documentation
python scripts/validate_env.py .env --generate-docs

Navigation

For detailed workflows and patterns:

Framework-Specific Quick Reference

Next.js
bash
# Validate Next.js env structure
# - NEXT_PUBLIC_* for client-side vars
# - Check .env.local, .env.production precedence
python scripts/validate_env.py .env --framework nextjs

# Files to manage:
# - .env.local (local development, gitignored)
# - .env.production (production, usually from platform)
# - .env (shared defaults, committed)
# - .env.example (documentation, committed)
Express/Node.js
bash
# Validate Node.js env structure
python scripts/validate_env.py .env --framework nodejs

# Standard structure:
# - process.env.NODE_ENV
# - process.env.PORT
# - process.env.DATABASE_URL
Python/Flask
bash
# Validate Python env structure
python scripts/validate_env.py .env --framework python

# Standard structure:
# - FLASK_APP
# - FLASK_ENV
# - DATABASE_URL (SQLAlchemy format)

Platform-Specific Quick Reference

Vercel
bash
# Generate vercel.json env config
python scripts/sync_secrets.py --platform vercel --generate

# Sync to Vercel project
python scripts/sync_secrets.py --platform vercel --sync

# Respects NEXT_PUBLIC_ prefix for client-side vars
Railway
bash
# Generate Railway config
python scripts/sync_secrets.py --platform railway --generate

# Sync to Railway project
python scripts/sync_secrets.py --platform railway --sync
Heroku
bash
# Generate Heroku config
python scripts/sync_secrets.py --platform heroku --generate

# Sync via Heroku CLI
python scripts/sync_secrets.py --platform heroku --sync
Show full SKILL.md (206 more words)Show less

Key Reminders

  • NEVER log actual secret values - Always mask/redact in output
  • Validate before every deployment - Catch issues locally
  • Use .env.example for documentation - Keep it updated
  • Framework conventions matter - Next.js NEXT_PUBLIC_, Django DJANGO_SETTINGS_MODULE
  • Platform-specific quirks exist - Vercel auto-exposes NEXT_PUBLIC_*, Railway uses exact syntax
  • Secret managers are your friend - 1Password, AWS Secrets Manager for team sync
  • .gitignore is critical - NEVER commit .env files with secrets
  • Environment precedence can be tricky - Know your framework's loading order

Common Validation Checks

Structure Validation
  • No empty values (except explicitly allowed)
  • No inline comments (some parsers don't support)
  • Proper quoting for values with spaces
  • No duplicate keys
  • Valid key naming (UPPERCASE_WITH_UNDERSCORES)
Security Validation
  • No exposed secrets in code
  • .env files in .gitignore
  • No secrets in git history
  • API keys match expected format
  • No hardcoded URLs with credentials
Framework Validation (Next.js)
  • NEXT_PUBLIC_* for client-side vars only
  • No secrets in NEXT_PUBLIC_* vars
  • .env.local exists for local secrets
  • .env.example documents all vars
Platform Validation (Vercel)
  • All required vars defined
  • No conflicts between environments
  • Correct variable names (Vercel conventions)
  • Build-time vs runtime vars separated

Integration with Other Skills

  • docker-containerization - Environment variables in containers
  • security-scanning - Broader security checks including secrets
  • nextjs-local-dev - Next.js specific development patterns
  • systematic-debugging - Debug env-related issues
Workflow Integration
1. Developer creates .env.local
2. env-manager validates structure
3. env-manager scans for security issues
4. Developer generates .env.example
5. Before deploy: env-manager compares local vs platform
6. env-manager generates platform config
7. Developer reviews and confirms sync
8. env-manager syncs to platform
9. Deployment proceeds with verified configuration

Lines: 197 (including frontmatter) ✓ <200

© bobmatnyc, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 9 other files (scripts, references) in src/claude_mpm/skills/bundled/infrastructure/env-manager of bobmatnyc/claude-mpm.

  • SKILL.md
  • INTEGRATION.md
  • README.md
  • examples/nextjs-env-structure.md
  • references/frameworks.md
  • references/security.md
  • references/synchronization.md
  • references/troubleshooting.md
  • references/validation.md
  • scripts/validate_env.py

Open the folder on GitHubat commit 25203d3

Compare with similar skills

Env Manager next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Env Manager compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Env Manager this skillbobmatnyc/claude-mpm155—~2kAutomated safety check: NotesMIT
Deployments Cicdvercel/vercel-plugin3011 repos~3kAutomated safety check: PassCustom licence
Deploy Release Testvercel/next.js143k—~1.2kAutomated safety check: PassMIT
Phase 9 Deploymentww-w-ai/bkit-claude-code601—~2.7kAutomated safety check: NotesApache-2.0
Vercel DeploymentsBagelHole/DevOps-Security-Agent-Skills1.1k—~1.8kAutomated safety check: NotesMIT
Nextjs Deploymentgiuseppe-trisciuoglio/developer-kit356—~2.3kAutomated safety check: NotesMIT

Similar skills

  • Deployments Cicd

    vercel/vercel-plugin

    Official

    Vercel deployment and CI/CD expert guidance. An agent skill from vercel/vercel-plugin.

    301 GitHub starsUsed in 1 repo~3k tokens
    DevOps & CloudAuto-check passed
  • Deploy Release Test

    vercel/next.js

    Official

    Validate a commit-specific Next.js preview package and manually trigger the entire Next.js deployment test suite through the teste2edeployrelease.yml GitHub Actions workflow.

    143k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Phase 9 Deployment

    ww-w-ai/bkit-claude-code

    Deploy to production — CI/CD pipelines, environment config, deployment strategies.

    601 GitHub stars~2.7k tokensUpdated 12 days ago
    DevOps & CloudAuto-check: notes
  • Vercel Deployments

    BagelHole/DevOps-Security-Agent-Skills

    Deploy frontend and full-stack apps on Vercel with previews, edge functions, environment promotion, and production guardrails.

    1.1k GitHub stars~1.8k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check: notes
  • Nextjs Deployment

    giuseppe-trisciuoglio/developer-kit

    Provides comprehensive patterns for deploying Next.js applications to production.

    356 GitHub stars~2.3k tokensUpdated 29 days ago
    DevOps & CloudAuto-check: notes
  • Vercel Deploy

    aiskillstore/marketplace

    A skill your agent uses when deploying Next.js applications to Vercel.

    430 GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from bobmatnyc/claude-mpm

All 51 skills in this repo
  • Build MCP Server

    bobmatnyc/claude-mpm

    Create high-quality MCP servers that enable LLMs to effectively interact with external services.

    155 GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Session Analyzer

    bobmatnyc/claude-mpm

    Debug and teach agentic coding: a deterministic-first session timeline + cost report, with optional narrative polish and a standalone JSX visualiser.

    155 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check passed
  • Software Patterns

    bobmatnyc/claude-mpm

    Decision framework for architectural patterns including DI, SOA, Repository, Domain Events, Circuit Breaker, and Anti-Corruption Layer.

    155 GitHub stars~1.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Verification Before Completion

    bobmatnyc/claude-mpm

    Run verification commands and confirm output before claiming success

    155 GitHub starsUsed in 2 repos~1k tokens
    Auto-check passed
  • Dependency Audit

    bobmatnyc/claude-mpm

    Dependency audit and cleanup workflow for maintaining healthy project dependencies.

    155 GitHub stars~3.5k tokensUpdated 1 mo ago
    Auto-check passed
  • Migration Wizard

    bobmatnyc/claude-mpm

    General protocol for executing migration skill wizards - service installation and configuration guides

    155 GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed

Categories

Questions about Env Manager

What does Env Manager do?

Environment variable validation, synchronization, and management across local development, CI/CD, and deployment platforms. Env Manager is an agent skill from bobmatnyc/claude-mpm.

When should I use Env Manager?

Env Manager fits situations like: tasks that involve Secrets management; tasks that involve CI/CD; tasks that involve Deployment.

How do I install Env Manager in Claude Code?

Run `npx skills add bobmatnyc/claude-mpm --skill env-manager -a claude-code`. Or copy the skill folder (src/claude_mpm/skills/bundled/infrastructure/env-manager in bobmatnyc/claude-mpm) into .claude/skills/env-manager in your project. Claude Code loads it when a task matches its description.

How do I install Env Manager in Codex?

Run `npx skills add bobmatnyc/claude-mpm --skill env-manager -a codex`. Or copy the skill folder (src/claude_mpm/skills/bundled/infrastructure/env-manager in bobmatnyc/claude-mpm) into .agents/skills/env-manager in your project. Codex loads it when a task matches its description.

Can I use Env Manager in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bobmatnyc/claude-mpm --skill env-manager -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/env-manager, .gemini/skills/env-manager, .github/skills/env-manager and .opencode/skills/env-manager in your project.

What does Env Manager need to run?

Going by SKILL.md and its folder, Env Manager needs Python for the scripts in its folder and the command-line tools its instructions call (python). Our summary lists: Python 3; Node.js; Docker.

Does Env Manager access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Env Manager safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Env Manager use?

Env Manager is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Env Manager use?

About 2k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 14k tokens, read only when the agent opens those files.

What are the alternatives to Env Manager?

Skills that share tags, products or a category with Env Manager: Deployments Cicd (vercel/vercel-plugin, 301 stars), Deploy Release Test (vercel/next.js, 143k stars), Phase 9 Deployment (ww-w-ai/bkit-claude-code, 601 stars) and Vercel Deployments (BagelHole/DevOps-Security-Agent-Skills, 1.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Env Manager?

bobmatnyc (a GitHub user) maintains it in bobmatnyc/claude-mpm, which has 155 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on August 31, 2026.

Source: bobmatnyc/claude-mpm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.