Official agent skill

Encrypted Saved Objects

by elastic in elastic/kibana

Encrypted Saved Objects (ESO) in Kibana — registration, AAD attribute choices, partial update safety, model version migrations with createModelVersion, canEncrypt checks, and Serverless constraints.

OfficialCustom licenceAuto-check passedBackend & APIs

Install Encrypted Saved Objects

skills CLI
$ npx skills add elastic/kibana --skill encrypted-saved-objects -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install elastic/kibana encrypted-saved-objects --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/elastic/kibana.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/encrypted-saved-objects .claude/skills/encrypted-saved-objects && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
encrypted-saved-objects
GitHub stars
21k
Token cost
~4.3k tokens
SKILL.md length
1,678 words
Files
1
Skills in repo
40
Repo updated
First seen
Licence
Custom licence

At a glance

Encrypted Saved Objects (ESO) in Kibana — registration, AAD attribute choices, partial update safety, model version migrations with createModelVersion, canEncrypt checks, and Serverless constraints.

  • Works in 2 steps: Register the Saved Object type with Core → Register with the ESO Service
  • Working with ESO types
  • SKILL.md covers Overview, When to Use ESOs, Registration and Partial Update Safety, plus 7 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Encrypted Saved Objects is an agent skill from elastic/kibana, published by the product's own GitHub organization. Encrypted Saved Objects (ESO) in Kibana — registration, AAD attribute choices, partial update safety, model version migrations with createModelVersion, canEncrypt checks, and Serverless constraints. Use when creating, modifying, or working with ESO types.

Its SKILL.md is about 4.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Serverless. It works with Elasticsearch. The repository describes itself as: Your window into all of your data.

When your agent uses it

  • Working with ESO types
  • Tasks that involve Serverless

Example prompts

  • “/encrypted-saved-objects”

Workflow steps

2 steps, taken from the step headings in SKILL.md.

  1. Register the Saved Object type with Core
  2. Register with the ESO Service

What it can do on your machine

Read from SKILL.md and the folder at commit ee7c86b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • elastic.co

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Encrypted Saved Objects loads about 4.3k tokens when it runs. Until then it costs about 70 tokens; SKILL.md has 1,678 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~70
When it runs · the whole SKILL.md, loaded when a task matches
~4.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 1,678 words (~4,318 tokens).

“An Encrypted Saved Object (ESO) is a Saved Object type registered with the ESO Service to specify:”

— opening of SKILL.md by elastic, Custom licence
name
encrypted-saved-objects

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .agents/skills/encrypted-saved-objects of elastic/kibana.

Open the folder on GitHubat commit ee7c86b

Compare with similar skills

Encrypted Saved Objects next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Encrypted Saved Objects compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Encrypted Saved Objects this skillelastic/kibana21k—~4.3kAutomated safety check: PassCustom licence
Cloud Onboardingelastic/agent-skills592—~4.1kAutomated safety check: PassApache-2.0
Cloud Provisioningelastic/agent-skills592—~5.4kAutomated safety check: PassApache-2.0
Amazon Opensearch Serviceaws/agent-toolkit-for-aws2.8k—~2.4kAutomated safety check: PassApache-2.0
Arcgis To Portaljsdatopian/portaljs2.4k1 repos~2kAutomated safety check: PassMIT
AWS Serverless Edazxkane/aws-skills3674 repos~3.2kAutomated safety check: PassMIT

Similar skills

  • Cloud Onboarding

    elastic/agent-skills

    Official

    Onboard an Elastic Cloud organization: configure the elastic CLI's Cloud context and API key, establish a default region, then invite users, assign predefined or custom Serverless project roles, and…

    592 GitHub stars~4.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Cloud Provisioning

    elastic/agent-skills

    Official

    Provision and operate Elastic Cloud infrastructure: create, connect to, update, and delete Serverless projects (Elasticsearch, Observability, Security); manage traffic filters (IP and AWS…

    592 GitHub stars~5.4k tokensUpdated today
    Backend & APIsAuto-check passed
  • Amazon Opensearch Service

    aws/agent-toolkit-for-aws

    Official

    Guides migration, provisioning, search, log-analytics, trace-analytics, and Agentic AI Assistant workflows for Amazon OpenSearch Service and Serverless across six capabilities — migration…

    2.8k GitHub stars~2.4k tokensUpdated today
    Data & AnalyticsAuto-check passed
  • Arcgis To Portaljs

    datopian/portaljs

    Migrate a whole ArcGIS Hub site into a PortalJS Arc portal end-to-end.

    2.4k GitHub starsUsed in 1 repo~2k tokens
    Backend & APIsAuto-check passed
  • AWS Serverless Eda

    zxkane/aws-skills

    AWS serverless and event-driven architecture expert based on Well-Architected Framework.

    367 GitHub starsUsed in 4 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • AI Model Nodejs

    TencentCloudBase/CloudBase-AI-Toolkit

    A skill your agent uses for Node.js backend AI via @cloudbase/node-sdk (=3.16.0) — cloud functions, CloudRun, Express/Koa/NestJS, serverless APIs, scheduled jobs, LLM proxies, agent orchestration.

    1.1k GitHub starsUsed in 3 repos~5k tokens
    Backend & APIsAuto-check passed

More from elastic/kibana

All 40 skills in this repo
  • Official

    Migrate Kibana Cypress E2E tests (.cy.ts) to Scout (Playwright).

    21k GitHub stars~3.8k tokensUpdated today
    Auto-check passed
  • Activate Connector

    elastic/kibana

    Official

    Creates a connector instance in a running Kibana. An agent skill from elastic/kibana.

    21k GitHub stars~1.9k tokensUpdated today
    Auto-check: notes
  • Codeql

    elastic/kibana

    Official

    Work with CodeQL in Kibana — write, test, and debug custom queries locally, fetch scan results from GitHub, and validate inline suppression comments.

    21k GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Debug Oas

    elastic/kibana

    Official

    A skill your agent uses when debugging OpenAPI (OAS) issues for a specific API area in Kibana by scoping validation output with one or more --path filters, then separating structural invalid-OAS…

    21k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Evals Write Spec

    elastic/kibana

    Official

    Write LLM evaluation spec files with datasets, tasks, and evaluators using the @kbn/evals Playwright fixture.

    21k GitHub stars~2.3k tokensUpdated today
    Auto-check passed
  • Kbn GitHub

    elastic/kibana

    Official

    GitHub interactions via gh CLI for the Kibana repo. An agent skill from elastic/kibana.

    21k GitHub stars~1.3k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Encrypted Saved Objects

What does Encrypted Saved Objects do?

Encrypted Saved Objects (ESO) in Kibana — registration, AAD attribute choices, partial update safety, model version migrations with createModelVersion, canEncrypt checks, and Serverless constraints. Encrypted Saved Objects is an agent skill from elastic/kibana, published by the product's own GitHub organization. Encrypted Saved Objects (ESO) in Kibana — registration, AAD attribute choices, partial update safety, model version migrations with createModelVersion, canEncrypt checks, and Serverless constraints.

When should I use Encrypted Saved Objects?

Encrypted Saved Objects fits situations like: working with ESO types; tasks that involve Serverless.

How do I install Encrypted Saved Objects in Claude Code?

Run `npx skills add elastic/kibana --skill encrypted-saved-objects -a claude-code`. Or copy the skill folder (.agents/skills/encrypted-saved-objects in elastic/kibana) into .claude/skills/encrypted-saved-objects in your project. Claude Code loads it when a task matches its description.

How do I install Encrypted Saved Objects in Codex?

Run `npx skills add elastic/kibana --skill encrypted-saved-objects -a codex`. Or copy the skill folder (.agents/skills/encrypted-saved-objects in elastic/kibana) into .agents/skills/encrypted-saved-objects in your project. Codex loads it when a task matches its description.

Can I use Encrypted Saved Objects in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add elastic/kibana --skill encrypted-saved-objects -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/encrypted-saved-objects, .gemini/skills/encrypted-saved-objects, .github/skills/encrypted-saved-objects and .opencode/skills/encrypted-saved-objects in your project.

What does Encrypted Saved Objects need to run?

SKILL.md names no scripts, command-line tools or credentials: Encrypted Saved Objects is instructions for the agent only.

Does Encrypted Saved Objects access the network?

SKILL.md names 1 domain. As links in the text: elastic.co. This is read from the text; nothing was executed.

Is Encrypted Saved Objects safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Encrypted Saved Objects use?

Encrypted Saved Objects has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Encrypted Saved Objects use?

About 4.3k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Encrypted Saved Objects?

Skills that share tags, products or a category with Encrypted Saved Objects: Cloud Onboarding (elastic/agent-skills, 592 stars), Cloud Provisioning (elastic/agent-skills, 592 stars), Amazon Opensearch Service (aws/agent-toolkit-for-aws, 2.8k stars) and Arcgis To Portaljs (datopian/portaljs, 2.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Encrypted Saved Objects?

elastic (a GitHub organization, an official publisher) maintains it in elastic/kibana, which has 21,310 GitHub stars. The repository holds 40 skills in this directory. The repository was last updated on October 8, 2026.

Source: elastic/kibana on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.