Agent skill

Golem Add Secret Effect

by golemcloud in golemcloud/golem

Adding secrets to Effect-based Golem agents. An agent skill from golemcloud/golem.

Custom licenceAuto-check passed

Install Golem Add Secret Effect

skills CLI
$ npx skills add golemcloud/golem --skill golem-add-secret-effect -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install golemcloud/golem golem-add-secret-effect --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/golemcloud/golem.git skills-src && mkdir -p .claude/skills && cp -r skills-src/golem-skills/skills/effect/golem-add-secret-effect .claude/skills/golem-add-secret-effect && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
golem-add-secret-effect
GitHub stars
1.5k
Token cost
~2k tokens
SKILL.md length
631 words
Files
1
Skills in repo
289
Repo updated
First seen
Licence
Custom licence

At a glance

Adding secrets to Effect-based Golem agents. An agent skill from golemcloud/golem.

  • Works in 7 steps: Create a config service class with… → Mark each sensitive field with… → Attach the config class to defineAgent… → …
  • An @golemcloud/effect-golem agent needs API keys
  • SKILL.md covers Steps, Agent with Regular and Secret…, Nested and Structured Secrets and Preserve Redaction, plus 4 more sections
  • Needs DB_PASSWORD

What it does

Golem Add Secret Effect is an agent skill from golemcloud/golem. Adding secrets to Effect-based Golem agents. Use when an @golemcloud/effect-golem agent needs API keys, passwords, tokens, or other sensitive typed configuration without exposing plaintext in Effect values or logs.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: Golem Cloud is the agent-native platform for building AI agents and distributed applications that never lose state, never duplicate work, and never require you to build…

When your agent uses it

  • An @golemcloud/effect-golem agent needs API keys
  • Other sensitive typed configuration without exposing plaintext in Effect values

Example prompts

  • “/golem-add-secret-effect”

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Create a config service class with defineConfig(name, fields).
  2. Mark each sensitive field with Schema.Redacted(innerSchema).
  3. Attach the config class to defineAgent with config: MyAgentConfig.
  4. Yield the config service inside the method handler.
  5. Evaluate a regular field directly; evaluate a secret field's .get Effect.
  6. Keep the resulting Redacted.Redacted wrapped until the narrowest possible use site.
  7. Provision production values with golem secret; use secretDefaults only for development.

What it can do on your machine

Read from SKILL.md and the folder at commit efc90f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript, bash and yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DB_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Golem Add Secret Effect loads about 2k tokens when it runs. Until then it costs about 60 tokens; SKILL.md has 631 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~60
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 631 words (~1,971 tokens).

“Effect agents declare secrets as redacted fields in a defineConfig service. The host supplies a secret field on demand as an Effect Redacted.Redacted value. Keep that wrapper intact through Effect composition and logging, and call Redacted.value(...) only at the immediate…”

— opening of SKILL.md by golemcloud, Custom licence
name
golem-add-secret-effect

Read the full SKILL.md on GitHub

Files

Just SKILL.md in golem-skills/skills/effect/golem-add-secret-effect of golemcloud/golem.

Open the folder on GitHubat commit efc90f0

Compare with similar skills

Golem Add Secret Effect next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Golem Add Secret Effect compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Golem Add Secret Effect this skillgolemcloud/golem1.5k—~2kAutomated safety check: PassCustom licence
Openclaw Secret Scanning Maintaineropenclaw/openclaw392k—~2.5kAutomated safety check: PassMIT
Secret Scanninggithub/awesome-copilot40k1 repos~2.4kAutomated safety check: PassMIT
Secrets Managementdavila7/claude-code-templates32k12 repos~2kAutomated safety check: PassMIT
Golem Quota Effectgolemcloud/golem1.5k—~2kAutomated safety check: PassCustom licence
Golem Add Mysql Effectgolemcloud/golem1.5k—~2.1kAutomated safety check: PassCustom licence

Similar skills

  • Triage, redact, clean up, and resolve OpenClaw GitHub Secret Scanning alerts in issues or PRs.

    392k GitHub stars~2.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Secret Scanning

    github/awesome-copilot

    Official

    Guide for configuring and managing GitHub secret scanning, push protection, custom patterns, and secret alert remediation.

    40k GitHub starsUsed in 1 repo~2.4k tokens
    DevOps & CloudAuto-check passed
  • Secrets Management

    davila7/claude-code-templates

    Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools.

    32k GitHub starsUsed in 12 repos~2k tokens
    DevOps & CloudAuto-check passed
  • Golem Quota Effect

    golemcloud/golem

    Adding resource quotas to an Effect-based Golem agent. An agent skill from golemcloud/golem.

    1.5k GitHub stars~2k tokensUpdated today
    Backend & APIsAuto-check passed
  • Golem Add Mysql Effect

    golemcloud/golem

    Uses MySQL from Effect-based Golem agents through @golemcloud/effect-golem/mysql.

    1.5k GitHub stars~2.1k tokensUpdated today
    DatabasesAuto-check passed
  • Using PostgreSQL from an Effect-based Golem agent through @golemcloud/effect-golem/postgres.

    1.5k GitHub stars~2.4k tokensUpdated today
    DatabasesAuto-check passed

More from golemcloud/golem

All 289 skills in this repo
  • Moonbit C Binding

    golemcloud/golem

    Guide for writing MoonBit bindings to C libraries using native FFI.

    1.5k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Adding Dependencies

    golemcloud/golem

    Adding or updating crate dependencies in the Golem workspace.

    1.5k GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Analysing CI Failures

    golemcloud/golem

    Analysing GitHub Actions CI failures from a run URL. An agent skill from golemcloud/golem.

    1.5k GitHub stars~862 tokensUpdated today
    Auto-check passed
  • Adds a built-in WASM plugin that is externally released and provisioned by the registry service.

    1.5k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • DB Migration Scripts

    golemcloud/golem

    Writing database migration SQL scripts. An agent skill from golemcloud/golem.

    1.5k GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • Debugging Hanging Tests

    golemcloud/golem

    Diagnosing and fixing hanging worker executor or integration tests.

    1.5k GitHub stars~879 tokensUpdated today
    Auto-check passed

Questions about Golem Add Secret Effect

What does Golem Add Secret Effect do?

Adding secrets to Effect-based Golem agents. An agent skill from golemcloud/golem. Golem Add Secret Effect is an agent skill from golemcloud/golem. Adding secrets to Effect-based Golem agents.

When should I use Golem Add Secret Effect?

Golem Add Secret Effect fits situations like: an @golemcloud/effect-golem agent needs API keys; other sensitive typed configuration without exposing plaintext in Effect values.

How do I install Golem Add Secret Effect in Claude Code?

Run `npx skills add golemcloud/golem --skill golem-add-secret-effect -a claude-code`. Or copy the skill folder (golem-skills/skills/effect/golem-add-secret-effect in golemcloud/golem) into .claude/skills/golem-add-secret-effect in your project. Claude Code loads it when a task matches its description.

How do I install Golem Add Secret Effect in Codex?

Run `npx skills add golemcloud/golem --skill golem-add-secret-effect -a codex`. Or copy the skill folder (golem-skills/skills/effect/golem-add-secret-effect in golemcloud/golem) into .agents/skills/golem-add-secret-effect in your project. Codex loads it when a task matches its description.

Can I use Golem Add Secret Effect in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add golemcloud/golem --skill golem-add-secret-effect -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/golem-add-secret-effect, .gemini/skills/golem-add-secret-effect, .github/skills/golem-add-secret-effect and .opencode/skills/golem-add-secret-effect in your project.

What does Golem Add Secret Effect need to run?

Going by SKILL.md and its folder, Golem Add Secret Effect needs credentials named DB_PASSWORD.

Does Golem Add Secret Effect access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Golem Add Secret Effect safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Golem Add Secret Effect use?

Golem Add Secret Effect has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Golem Add Secret Effect use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Golem Add Secret Effect?

Skills that share tags, products or a category with Golem Add Secret Effect: Openclaw Secret Scanning Maintainer (openclaw/openclaw, 392k stars), Secret Scanning (github/awesome-copilot, 40k stars), Secrets Management (davila7/claude-code-templates, 32k stars) and Golem Quota Effect (golemcloud/golem, 1.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Golem Add Secret Effect?

golemcloud (a GitHub organization) maintains it in golemcloud/golem, which has 1,507 GitHub stars. The repository holds 289 skills in this directory. The repository was last updated on October 9, 2026.

Source: golemcloud/golem on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.