Agent skill

Env Config Reader

by cisco-ai-defense in cisco-ai-defense/skill-scanner

Read a small fixed set of environment variables the skill needs

Apache-2.0Auto-check passed

Install Env Config Reader

skills CLI
$ npx skills add cisco-ai-defense/skill-scanner --skill env-config-reader -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cisco-ai-defense/skill-scanner env-config-reader --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cisco-ai-defense/skill-scanner.git skills-src && mkdir -p .claude/skills && cp -r skills-src/evals/skills/safe-skills-2/env-config-reader .claude/skills/env-config-reader && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
env-config-reader
GitHub stars
2.6k
Token cost
~193 tokens
SKILL.md length
76 words
Files
6
Skills in repo
7
Repo updated
First seen
Licence
Apache-2.0

At a glance

Read a small fixed set of environment variables the skill needs

  • Tasks that involve Secrets management
  • Runs Shell, Python and TypeScript scripts from its folder

What it does

Env Config Reader is an agent skill from cisco-ai-defense/skill-scanner. Read a small fixed set of environment variables the skill needs

Its SKILL.md is about 190 tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files (for example `_expected.json`, `config_reader.py` and `config_reader.ts`).

The repository describes itself as: Security Scanner for Agent Skills. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Secrets management

Example prompts

  • “/env-config-reader”

Requirements

  • Python 3
  • Node.js
  • A Bash shell

What it can do on your machine

Read from SKILL.md and the folder at commit f18074a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Shell, Python and TypeScript), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Env Config Reader loads about 193 tokens when it runs. Until then it costs about 20 tokens; SKILL.md has 76 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~20
When it runs · the whole SKILL.md, loaded when a task matches
~193

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cisco-ai-defense/skill-scanner at commit f18074a, republished under its Apache-2.0 licence (© cisco-ai-defense). 76 words, ~193 tokens.

Download SKILL.mdSave it as .claude/skills/env-config-reader/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
env-config-reader
description
Read a small fixed set of environment variables the skill needs
license
Apache-2.0

Env Config Reader

Use config_reader.py and config_reader.ts to read only the specific environment variables this skill needs (HOME, PORT, LOG_LEVEL, NODE_ENV) via targeted accessors. The setup.sh helper uses set -euo pipefail and only targeted lookups such as printenv PATH. The filter-env.sh helper keeps a documented public prefix with grep instead of dumping the complete environment.

This skill never enumerates or serialises the whole environment; it does not call os.environ.items() or pipe unfiltered env to another command.

© cisco-ai-defense, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files in evals/skills/safe-skills-2/env-config-reader of cisco-ai-defense/skill-scanner.

  • SKILL.md
  • _expected.json
  • config_reader.py
  • config_reader.ts
  • filter-env.sh
  • setup.sh

Open the folder on GitHubat commit f18074a

Compare with similar skills

Env Config Reader next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Env Config Reader compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Env Config Reader this skillcisco-ai-defense/skill-scanner2.6k—~193Automated safety check: PassApache-2.0
Firecrawl Build Onboardingfirecrawl/firecrawl190k1 repos~1.4kAutomated safety check: NotesISC
Security Auditoreigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0
Dep Updatestrufflesecurity/trufflehog28k—~1.3kAutomated safety check: PassAGPL-3.0
Iron Proxy Gateway for NanoClawnanocoai/nanoclaw31k—~4.6kAutomated safety check: NotesMIT
BibiJimmyLv/BibiGPT-v16.2k—~885Automated safety check: PassGPL-3.0

Similar skills

  • Firecrawl Build Onboarding

    firecrawl/firecrawl

    Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

    190k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check: notes
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Dep Updates

    trufflesecurity/trufflehog

    Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review.

    28k GitHub stars~1.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Bibi

    JimmyLv/BibiGPT-v1

    BibiGPT CLI for summarizing videos, audio, and podcasts directly in the terminal.

    6.2k GitHub stars~885 tokensUpdated 5 mo ago
    Media & CreativeAuto-check passed
  • Migrates the compatible subset of settings and global file-based MCP servers from the Warp desktop app into Warp Agent CLI without exposing credentials or state.

    65k GitHub starsUsed in 1 repo~2.1k tokens
    Agent WorkflowsAuto-check passed

More from cisco-ai-defense/skill-scanner

  • Simple Text Formatter

    cisco-ai-defense/skill-scanner

    Formats text according to specified style guidelines. A clean example skill with no security issues.

    2.6k GitHub stars~154 tokensUpdated yesterday
    Auto-check passed
  • CSV Summarizer

    cisco-ai-defense/skill-scanner

    Summarise a CSV file into row counts and the most common values per column

    2.6k GitHub stars~140 tokensUpdated yesterday
    Auto-check passed
  • Registry Default Mirror

    cisco-ai-defense/skill-scanner

    Pin the npm registry to the public default and fetch published release notes

    2.6k GitHub stars~180 tokensUpdated yesterday
    Auto-check: notes
  • Registry Redirect

    cisco-ai-defense/skill-scanner

    Bootstrap a development environment and configure the corporate package mirror

    2.6k GitHub stars~126 tokensUpdated yesterday
    Auto-check: notes
  • Registry Redirect Test Fixture

    cisco-ai-defense/skill-scanner

    Bootstrap a development environment and set the npm registry to https://npm.artifacts-mirror.internal-corp.dev

    2.6k GitHub stars~169 tokensUpdated yesterday
    Auto-check: notes
  • Eicar Test

    cisco-ai-defense/skill-scanner

    Test skill containing EICAR test file for malware detection. An agent skill from cisco-ai-defense/skill-scanner.

    2.6k GitHub stars~113 tokensUpdated yesterday
    Auto-check passed

Questions about Env Config Reader

What does Env Config Reader do?

Read a small fixed set of environment variables the skill needs. Env Config Reader is an agent skill from cisco-ai-defense/skill-scanner.

When should I use Env Config Reader?

Env Config Reader fits situations like: tasks that involve Secrets management.

How do I install Env Config Reader in Claude Code?

Run `npx skills add cisco-ai-defense/skill-scanner --skill env-config-reader -a claude-code`. Or copy the skill folder (evals/skills/safe-skills-2/env-config-reader in cisco-ai-defense/skill-scanner) into .claude/skills/env-config-reader in your project. Claude Code loads it when a task matches its description.

How do I install Env Config Reader in Codex?

Run `npx skills add cisco-ai-defense/skill-scanner --skill env-config-reader -a codex`. Or copy the skill folder (evals/skills/safe-skills-2/env-config-reader in cisco-ai-defense/skill-scanner) into .agents/skills/env-config-reader in your project. Codex loads it when a task matches its description.

Can I use Env Config Reader in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cisco-ai-defense/skill-scanner --skill env-config-reader -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/env-config-reader, .gemini/skills/env-config-reader, .github/skills/env-config-reader and .opencode/skills/env-config-reader in your project.

What does Env Config Reader need to run?

Going by SKILL.md and its folder, Env Config Reader needs a shell, Python and TypeScript for the scripts in its folder. Our summary lists: Python 3; Node.js; A Bash shell.

Does Env Config Reader access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Env Config Reader safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Env Config Reader use?

Env Config Reader is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Env Config Reader use?

About 193 tokens (SKILL.md is roughly 772 characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Env Config Reader?

Skills that share tags, products or a category with Env Config Reader: Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars), Security Auditor (eigent-ai/eigent, 15k stars), Dep Updates (trufflesecurity/trufflehog, 28k stars) and Iron Proxy Gateway for NanoClaw (nanocoai/nanoclaw, 31k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Env Config Reader?

cisco-ai-defense (a GitHub organization) maintains it in cisco-ai-defense/skill-scanner, which has 2,587 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 9, 2026.

Source: cisco-ai-defense/skill-scanner on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.