Agent skill

1password

by dxos in dxos/dxos

Get a credential (API key, token, password, certificate) from 1Password with the op CLI — only when OPSERVICEACCOUNTTOKEN is set (the cloud sandbox); in a local session never run op.

Custom licenceAuto-check: notesDevelopment

Install 1password

skills CLI
$ npx skills add dxos/dxos --skill 1password -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install dxos/dxos 1password --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/dxos/dxos.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/1password .claude/skills/1password && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
1password
GitHub stars
525
Token cost
~1k tokens
SKILL.md length
493 words
Files
1
Skills in repo
41
Repo updated
First seen
Licence
Custom licence

At a glance

Get a credential (API key, token, password, certificate) from 1Password with the op CLI — only when OPSERVICEACCOUNTTOKEN is set (the cloud sandbox); in a local session never run op.

  • A task needs a secret — before asking the user for one
  • SKILL.md covers Is it available?, Find the item, Use it without exposing it and When the item is not there
  • Calls python3; needs OP_SERVICE_ACCOUNT_TOKEN
  • Before asking them to create a .secrets/ file

What it does

1password is an agent skill from dxos/dxos. Get a credential (API key, token, password, certificate) from 1Password with the op CLI — only when OPSERVICEACCOUNTTOKEN is set (the cloud sandbox); in a local session never run op. Use whenever a task needs a secret — before asking the user for one, before asking them to create a .secrets/ file, and before concluding a credential is unavailable. Use when a script or README names an op:// reference or a .env.tpl.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. The repository describes itself as: TypeScript implementation of the DXOS protocols, SDK, toolchain and Composer.

When your agent uses it

  • A task needs a secret — before asking the user for one
  • Before asking them to create a .secrets/ file
  • Before concluding a credential is unavailable
  • README names an op:// reference

Example prompts

  • “/1password”

Requirements

  • Python 3
  • A credential in OP_SERVICE_ACCOUNT_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit f0fc12a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OP_SERVICE_ACCOUNT_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

1password loads about 1k tokens when it runs. Until then it costs about 111 tokens; SKILL.md has 493 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~111
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:8
    README names an `op://` reference or a `.env.tpl`.
  • NoteMentions a .env fileSKILL.md:59
    | A whole `.env` of references  | `op run --env-file=.env.tpl -- <cmd>`                           |
  • NoteMentions a .env fileSKILL.md:60
    r a template to a file   | `op inject -i .env.tpl -o .env` (the output must be gitignored) |
  • NoteMentions a .env fileSKILL.md:72
    `.env.tpl`), not values.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 493 words (~1,030 tokens).

“Use op only when OP_SERVICE_ACCOUNT_TOKEN is set. That token authenticates the CLI as a service account, so it reads a secret straight into the command that needs it with no prompt and nothing from the user. Without it, every op…”

— opening of SKILL.md by dxos, Custom licence
name
1password

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .agents/skills/1password of dxos/dxos.

Open the folder on GitHubat commit f0fc12a

Compare with similar skills

1password next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

1password compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
1password this skilldxos/dxos525—~1kAutomated safety check: NotesCustom licence
Vercel Composition Patternssupabase/supabase111k59 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 59 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from dxos/dxos

All 41 skills in this repo
  • Run the rule-driven agentic code review — discover rule blocks in the repo's .mdl files, prepare per-rule review groups (full project by default; diff-only with --pr-only), spawn one focused Sonnet…

    525 GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Forensically inspect and repair Composer browser profiles — offline (Chrome OPFS / SQLite extract) or live via /recovery.html debug port.

    525 GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • Migrate Oxfmt

    dxos/dxos

    Guide for migrating a project from Prettier or Biome to Oxfmt.

    525 GitHub starsUsed in 3 repos~2.2k tokens
    Auto-check passed
  • Moon

    dxos/dxos

    This skill should be used when the user asks to "configure moon", "set up moonrepo", "create moon tasks", "run moon commands", "configure moon workspace", "add moon project", "moon ci setup", "moon…

    525 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • Reference for SubductionPolicy (the four hooks authorizeConnect, authorizeFetch, authorizePut, filterAuthorizedFetch passed via Subduction.hydrate(..., policy) or new Repo({ subductionPolicy })).

    525 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Autocue

    dxos/dxos

    Record a demo of the running app that the agent drives itself — a .mdl QA test or an ad-hoc walkthrough — as a captioned .webm (or a screenshot), trimmed of dead air and ready to attach.

    525 GitHub stars~12k tokensUpdated today
    Auto-check passed

Categories

Questions about 1password

What does 1password do?

Get a credential (API key, token, password, certificate) from 1Password with the op CLI — only when OPSERVICEACCOUNTTOKEN is set (the cloud sandbox); in a local session never run op. 1password is an agent skill from dxos/dxos. Get a credential (API key, token, password, certificate) from 1Password with the op CLI — only when OPSERVICEACCOUNTTOKEN is set (the cloud sandbox); in a local session never run op.

When should I use 1password?

1password fits situations like: A task needs a secret — before asking the user for one; before asking them to create a .secrets/ file; before concluding a credential is unavailable; README names an op:// reference.

How do I install 1password in Claude Code?

Run `npx skills add dxos/dxos --skill 1password -a claude-code`. Or copy the skill folder (.agents/skills/1password in dxos/dxos) into .claude/skills/1password in your project. Claude Code loads it when a task matches its description.

How do I install 1password in Codex?

Run `npx skills add dxos/dxos --skill 1password -a codex`. Or copy the skill folder (.agents/skills/1password in dxos/dxos) into .agents/skills/1password in your project. Codex loads it when a task matches its description.

Can I use 1password in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add dxos/dxos --skill 1password -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/1password, .gemini/skills/1password, .github/skills/1password and .opencode/skills/1password in your project.

What does 1password need to run?

Going by SKILL.md and its folder, 1password needs the command-line tools its instructions call (python3) and credentials named OP_SERVICE_ACCOUNT_TOKEN. Our summary lists: Python 3; A credential in OP_SERVICE_ACCOUNT_TOKEN.

Does 1password access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is 1password safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does 1password use?

1password has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does 1password use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to 1password?

Skills that share tags, products or a category with 1password: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 296k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains 1password?

dxos (a GitHub organization) maintains it in dxos/dxos, which has 525 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on October 8, 2026.

Source: dxos/dxos on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.