Agent skill

Secrets

by BuilderIO in BuilderIO/agent-native

Connect external services and keep app credentials scoped. An agent skill from BuilderIO/agent-native.

No licenceAuto-check passedBackend & APIs

Install Secrets

skills CLI
$ npx skills add BuilderIO/agent-native --skill secrets -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BuilderIO/agent-native secrets --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BuilderIO/agent-native.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/secrets .claude/skills/secrets && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secrets
GitHub stars
7.1k
Token cost
~824 tokens
SKILL.md length
414 words
Files
1
Skills in repo
102
Repo updated
First seen
Licence
None found

At a glance

Connect external services and keep app credentials scoped. An agent skill from BuilderIO/agent-native.

  • Works in 4 steps: Check the workspace connection catalog… → For OAuth, use the shared authorization… → If the app truly needs its own API key,… → …
  • Tasks that involve Backend development
  • SKILL.md covers Rule, Choose the credential source, Register an app-local API key and Resolve credentials on the…, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Secrets is an agent skill from BuilderIO/agent-native. Connect external services and keep app credentials scoped. Use before adding an API key, OAuth connection, provider setup, or server-side request that needs a user's or workspace's credential.

Its SKILL.md is about 820 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Backend development and OAuth and OpenID Connect. The repository describes itself as: A framework for building agentic apps.

When your agent uses it

  • Tasks that involve Backend development
  • Tasks that involve OAuth and OpenID Connect

Example prompts

  • “s or workspace”
  • “/secrets”

Requirements

  • A credential in EXAMPLE_SERVICE_API_KEY

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Check the workspace connection catalog first. If the provider is already
  2. For OAuth, use the shared authorization and token flow. Do not store access
  3. If the app truly needs its own API key, register it with the shared secrets
  4. Use deployment configuration only for a secret owned by the deployed app,

What it can do on your machine

Read from SKILL.md and the folder at commit e16da0c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secrets loads about 824 tokens when it runs. Until then it costs about 50 tokens; SKILL.md has 414 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~50
When it runs · the whole SKILL.md, loaded when a task matches
~824

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 414 words (~824 tokens).

“Credentials belong to the user, organization, workspace, or deployment that owns them. Reuse the strongest shared connection or credential flow available; never copy a value into app code or client-visible state.”

— opening of SKILL.md by BuilderIO
name
secrets
scope
dev

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .agents/skills/secrets of BuilderIO/agent-native.

Open the folder on GitHubat commit e16da0c

Compare with similar skills

Secrets next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secrets compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secrets this skillBuilderIO/agent-native7.1k—~824Automated safety check: PassNone
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Antipattern Preventiondoorkeeper-gem/doorkeeper5.5k—~1.1kAutomated safety check: PassMIT
Socialite Developmenthexlet-volunteers/hexlet-sicp1145 repos~1.2kAutomated safety check: PassMIT
Passport Developmenttrypostit/trypost678—~1.9kAutomated safety check: PassMIT
Frontmcp Auth UIagentfront/frontmcp146—~3.7kAutomated safety check: PassApache-2.0

Similar skills

  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Antipattern Prevention

    doorkeeper-gem/doorkeeper

    Avoid common Ruby and Rails antipatterns that degrade maintainability and performance.

    5.5k GitHub stars~1.1k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Socialite Development

    hexlet-volunteers/hexlet-sicp

    Manages OAuth social authentication with Laravel Socialite. An agent skill from hexlet-volunteers/hexlet-sicp.

    114 GitHub starsUsed in 5 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Passport Development

    trypostit/trypost

    Develops OAuth2 API authentication with Laravel Passport. An agent skill from trypostit/trypost.

    678 GitHub stars~1.9k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Frontmcp Auth UI

    agentfront/frontmcp

    A skill your agent uses when customizing, branding, or replacing the built-in FrontMCP OAuth pages (the login, consent, federated-select, incremental-authorization, and error pages) with your own…

    146 GitHub stars~3.7k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Cookbook Authentication

    databricks-solutions/databricks-apps-cookbook

    Implement authentication in Databricks Apps: get current user info, on-behalf-of-user (OBO) auth, service principal auth, and OAuth patterns.

    183 GitHub stars~1.8k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed

More from BuilderIO/agent-native

All 102 skills in this repo
  • Actions

    BuilderIO/agent-native

    How to create and run agent actions. An agent skill from BuilderIO/agent-native.

    7.1k GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed
  • Client Methods

    BuilderIO/agent-native

    Client method surface rules. An agent skill from BuilderIO/agent-native.

    7.1k GitHub stars~1.2k tokensUpdated yesterday
    Auto-check passed
  • Adding A Feature

    BuilderIO/agent-native

    The four-area checklist every new feature must complete. An agent skill from BuilderIO/agent-native.

    7.1k GitHub stars~4k tokensUpdated yesterday
    Auto-check passed
  • Address Feedback

    BuilderIO/agent-native

    Triage feedback from docs, issues, Slack threads, or pasted notes into verified bugs, UX proposals, unclear questions, and skipped noise.

    7.1k GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed
  • Audit Log

    BuilderIO/agent-native

    Durable, access-scoped, append-only record of who changed what app data, when, and whether it was the agent or a human.

    7.1k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Automations

    BuilderIO/agent-native

    Event-triggered and schedule-triggered automations with natural-language conditions.

    7.1k GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Secrets

What does Secrets do?

Connect external services and keep app credentials scoped. An agent skill from BuilderIO/agent-native. Secrets is an agent skill from BuilderIO/agent-native. Connect external services and keep app credentials scoped.

When should I use Secrets?

Secrets fits situations like: tasks that involve Backend development; tasks that involve OAuth and OpenID Connect.

How do I install Secrets in Claude Code?

Run `npx skills add BuilderIO/agent-native --skill secrets -a claude-code`. Or copy the skill folder (.agents/skills/secrets in BuilderIO/agent-native) into .claude/skills/secrets in your project. Claude Code loads it when a task matches its description.

How do I install Secrets in Codex?

Run `npx skills add BuilderIO/agent-native --skill secrets -a codex`. Or copy the skill folder (.agents/skills/secrets in BuilderIO/agent-native) into .agents/skills/secrets in your project. Codex loads it when a task matches its description.

Can I use Secrets in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BuilderIO/agent-native --skill secrets -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secrets, .gemini/skills/secrets, .github/skills/secrets and .opencode/skills/secrets in your project.

What does Secrets need to run?

SKILL.md names no scripts, command-line tools or credentials: Secrets is instructions for the agent only. Our summary lists: A credential in EXAMPLE_SERVICE_API_KEY.

Does Secrets access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Secrets safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Secrets use?

No licence was found for Secrets or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Secrets use?

About 824 tokens (SKILL.md is roughly 3.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Secrets?

Skills that share tags, products or a category with Secrets: Fortify Development (coollabsio/coolify, 63k stars), Antipattern Prevention (doorkeeper-gem/doorkeeper, 5.5k stars), Socialite Development (hexlet-volunteers/hexlet-sicp, 114 stars) and Passport Development (trypostit/trypost, 678 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secrets?

BuilderIO (a GitHub organization) maintains it in BuilderIO/agent-native, which has 7,087 GitHub stars. The repository holds 102 skills in this directory. The repository was last updated on October 8, 2026.

Source: BuilderIO/agent-native on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.