Secure GitHub Actions
vechain/x-app-template
Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.
Loads a missing environment variable or API key from the team's Infisical workspace into the current shell, or runs a command with all project secrets injected.
$ npx skills add Devin-AXIS/iPolloWork --skill get-env-var -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Devin-AXIS/iPolloWork get-env-var --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Devin-AXIS/iPolloWork.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.opencode/skills/get-env-var .claude/skills/get-env-var && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "get-env-var" agent skill from https://github.com/Devin-AXIS/iPolloWork/tree/main/.opencode/skills/get-env-var into .claude/skills/get-env-var/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "get-env-var", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Devin-AXIS/iPolloWork/tree/main/.opencode/skills/get-env-varType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Devin-AXIS/iPolloWork --skill get-env-var -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Devin-AXIS/iPolloWork get-env-var --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Devin-AXIS/iPolloWork.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.opencode/skills/get-env-var .agents/skills/get-env-var && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "get-env-var" agent skill from https://github.com/Devin-AXIS/iPolloWork/tree/main/.opencode/skills/get-env-var into .agents/skills/get-env-var/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "get-env-var", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Devin-AXIS/iPolloWork --skill get-env-var -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Devin-AXIS/iPolloWork get-env-var --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Devin-AXIS/iPolloWork.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.opencode/skills/get-env-var .cursor/skills/get-env-var && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "get-env-var" agent skill from https://github.com/Devin-AXIS/iPolloWork/tree/main/.opencode/skills/get-env-var into .cursor/skills/get-env-var/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "get-env-var", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Devin-AXIS/iPolloWork.git --path .opencode/skills/get-env-var--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Devin-AXIS/iPolloWork --skill get-env-var -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Devin-AXIS/iPolloWork get-env-var --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Devin-AXIS/iPolloWork.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.opencode/skills/get-env-var .gemini/skills/get-env-var && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "get-env-var" agent skill from https://github.com/Devin-AXIS/iPolloWork/tree/main/.opencode/skills/get-env-var into .gemini/skills/get-env-var/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "get-env-var", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Devin-AXIS/iPolloWork get-env-varInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Devin-AXIS/iPolloWork --skill get-env-var -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Devin-AXIS/iPolloWork.git skills-src && mkdir -p .github/skills && cp -r skills-src/.opencode/skills/get-env-var .github/skills/get-env-var && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "get-env-var" agent skill from https://github.com/Devin-AXIS/iPolloWork/tree/main/.opencode/skills/get-env-var into .github/skills/get-env-var/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "get-env-var", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Devin-AXIS/iPolloWork --skill get-env-var -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Devin-AXIS/iPolloWork get-env-var --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Devin-AXIS/iPolloWork.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.opencode/skills/get-env-var .opencode/skills/get-env-var && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "get-env-var" agent skill from https://github.com/Devin-AXIS/iPolloWork/tree/main/.opencode/skills/get-env-var into .opencode/skills/get-env-var/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "get-env-var", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
get-env-varLoads a missing environment variable or API key from the team's Infisical workspace into the current shell, or runs a command with all project secrets injected.
When a command needs a token or API key that is not set, this skill fetches it from the team's Infisical workspace instead of asking you to paste it. For one secret, the agent exports it inside command substitution using the Infisical CLI's plain and silent flags. It can add an environment slug or a folder path, and the repository's tracked `.infisical.json` links the project and makes `dev` the default environment. To expose every project secret to a single process only, the agent runs that command through `infisical run`.
Setup is once per machine: install the CLI with Homebrew on macOS, check login with `infisical user get`, and run `infisical login` if that fails. Non-interactive runs such as CI use an `INFISICAL_TOKEN` machine identity. The rules are strict: never print or log a secret value, never write one to a file, commit message, pull request body or comment, and if a secret does not exist, stop and tell you which name and environment to add rather than inventing a value.
Read from SKILL.md and the folder at commit 71a74ad. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
brewFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
BLOB_READ_WRITE_TOKENINFISICAL_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Get Env Var from Infisical loads about 516 tokens when it runs. Until then it costs about 59 tokens; SKILL.md has 249 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 249 words (~516 tokens).
“Fetch a secret from the team's Infisical workspace into the current shell so the next command can use it.”
Just SKILL.md in .opencode/skills/get-env-var of Devin-AXIS/iPolloWork.
Open the folder on GitHubat commit 71a74ad
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Devin-AXIS/iPolloWork, which our catalogue first saw on October 7, 2026.
Get Env Var from Infisical next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Get Env Var from Infisical this skillDevin-AXIS/iPolloWork | 6.7k | 1 repos | ~516 | Automated safety check: Pass | Custom licence | |
| Secure GitHub Actionsvechain/x-app-template | 450 | — | ~1.2k | Automated safety check: Pass | MIT | |
| Detecting Compromised Cloud Credentialsmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | |
| Implementing Azure Defender For Cloudmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.1k | Automated safety check: Pass | Apache-2.0 | |
| Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~818 | Automated safety check: Pass | Apache-2.0 | |
| Azure Keyvault Pymicrosoft/skills | 3.1k | — | ~2.4k | Automated safety check: Pass | MIT |
vechain/x-app-template
Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.
mukul975/Anthropic-Cybersecurity-Skills
Detect compromised cloud credentials across AWS, Azure, and GCP by analyzing anomalous API activity, impossible-travel patterns, and credential-stuffing indicators using GuardDuty, Microsoft…
mukul975/Anthropic-Cybersecurity-Skills
Enable Microsoft Defender for Cloud (CSPM + CWPP) across VMs, containers, SQL, storage, and Key Vault, using Azure Policy for evaluation, Log Analytics for telemetry, Azure Arc for hybrid coverage…
mukul975/Anthropic-Cybersecurity-Skills
Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…
microsoft/skills
Azure Key Vault SDK for Python. An agent skill from microsoft/skills.
jonathan-vella/apex
ANALYSIS SKILL — Azure compliance and security auditing: best practices, Key Vault expiration monitoring, resource validation.
Devin-AXIS/iPolloWork
A code-change gate for the iPolloWork repository: search and reuse first, keep one source of truth, justify every new file or dependency, and audit the change.
Devin-AXIS/iPolloWork
Reproduces iPolloWork enterprise TLS behavior in a Daytona Windows sandbox by installing a fake corporate CA and proving the app and its runtimes use the OS trust store.
Devin-AXIS/iPolloWork
Builds a reusable iPolloWork template for Design, Slides or PPT, or HyperFrames Video through conversation, keeping a manifest, reusable variables and a validated package current.
Devin-AXIS/iPolloWork
Scaffolds an OpenCode plugin for iPolloWork with the right async factory shape, zod-based tool definitions and hook registration, and explains where to place and register it.
Devin-AXIS/iPolloWork
Has an agent drive the real app through CDP and capture clean, defect-free product screenshots, gated by DOM, pixel and vision checks in a loop.
Devin-AXIS/iPolloWork
Launches a standalone Chrome or Chromium in a Daytona sandbox and drives it over CDP for web sign-in, OAuth and other flows that should bypass the Electron app.
Categories
Loads a missing environment variable or API key from the team's Infisical workspace into the current shell, or runs a command with all project secrets injected. When a command needs a token or API key that is not set, this skill fetches it from the team's Infisical workspace instead of asking you to paste it. For one secret, the agent exports it inside command substitution using the Infisical CLI's plain and silent flags.
Get Env Var from Infisical fits situations like: A script fails because an environment variable is not set; A token or API key is missing from the shell environment; loading secrets from Infisical before running a command; running one process with all project secrets injected.
Run `npx skills add Devin-AXIS/iPolloWork --skill get-env-var -a claude-code`. Or copy the skill folder (.opencode/skills/get-env-var in Devin-AXIS/iPolloWork) into .claude/skills/get-env-var in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Devin-AXIS/iPolloWork --skill get-env-var -a codex`. Or copy the skill folder (.opencode/skills/get-env-var in Devin-AXIS/iPolloWork) into .agents/skills/get-env-var in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Devin-AXIS/iPolloWork --skill get-env-var -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/get-env-var, .gemini/skills/get-env-var, .github/skills/get-env-var and .opencode/skills/get-env-var in your project.
Going by SKILL.md and its folder, Get Env Var from Infisical needs the command-line tools its instructions call (brew) and credentials named BLOB_READ_WRITE_TOKEN and INFISICAL_TOKEN. Our summary lists: The Infisical CLI (installed with Homebrew on macOS); An Infisical login, or an INFISICAL_TOKEN machine identity for CI; A repository linked with `.infisical.json`.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Get Env Var from Infisical has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.
About 516 tokens (SKILL.md is roughly 2.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Get Env Var from Infisical: Secure GitHub Actions (vechain/x-app-template, 450 stars), Detecting Compromised Cloud Credentials (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Implementing Azure Defender For Cloud (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Devin-AXIS (a GitHub user) maintains it in Devin-AXIS/iPolloWork, which has 6,717 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on October 6, 2026.
Source: Devin-AXIS/iPolloWork on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.