Instructions for handling API keys and credentials safely, verifying their presence, and prompting the user to add them if missing using a safe protocol.

Apache-2.0Auto-check: notesResearch & Science

Install Credentials

skills CLI
$ npx skills add google-deepmind/science-skills --skill credentials -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install google-deepmind/science-skills credentials --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/google-deepmind/science-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/credentials .claude/skills/credentials && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
credentials
GitHub stars
3.2k
Token cost
~1k tokens
SKILL.md length
573 words
Files
1
Skills in repo
40
Repo updated
First seen
Licence
Apache-2.0

At a glance

Instructions for handling API keys and credentials safely, verifying their presence, and prompting the user to add them if missing using a safe protocol.

  • Research & Science work in your project
  • SKILL.md covers Safe Verification (No Leaks), Prompting the User to Add… and Running scripts requiring…
  • Needs ALPHAGENOME_API_KEY

What it does

Credentials is an agent skill from google-deepmind/science-skills. Instructions for handling API keys and credentials safely, verifying their presence, and prompting the user to add them if missing using a safe protocol.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Research & Science. The repository describes itself as: GDM Science Skills to speed up agentic scientific workflows with better grounding and higher token efficiency. Integrate insights from AlphaGenome, AFDB, UniProt and 30+ other… The licence is Apache-2.0.

When your agent uses it

  • Research & Science work in your project

Example prompts

  • “Use the credentials skill to instruction for handling API keys and credentials safely, verifying their presence, and prompting the user to add them…”
  • “/credentials”

Requirements

  • A credential in ALPHAGENOME_API_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 6883275. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ALPHAGENOME_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Credentials loads about 1k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 573 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:19
    the `.env` file (typically located in your home directory `~/.env` or the
  • NoteMentions a .env fileSKILL.md:28
    defined in `~/.env`. The `-s` flag ensures the command works cleanly even if
  • NoteMentions a .env fileSKILL.md:29
    `~/.env` does not exist yet.
  • NoteMentions a .env fileSKILL.md:32
    grep -sq "^CREDENTIAL_NAME=" ~/.env
  • NoteMentions a .env fileSKILL.md:41
    missing or the `.env` file does not exist yet), the credential is missing.
  • NoteMentions a .env fileSKILL.md:53
    > `.env` file if it does not already exist.
  • NoteMentions a .env fileSKILL.md:55
    **NEVER** run `cat ~/.env`, `grep "VAR" ~/.env` (without `-q`), `echo $VAR`, or
  • NoteMentions a .env fileSKILL.md:70
    ` with the resolved literal path to the `.env` file (usually
  • NoteMentions a .env fileSKILL.md:71
    `~/.env`).
  • NoteMentions a .env fileSKILL.md:89
    automatically from the `.env` file using `dotenv`.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from google-deepmind/science-skills at commit 6883275, republished under its Apache-2.0 licence (© google-deepmind). 573 words, ~1,039 tokens.

Download SKILL.mdSave it as .claude/skills/credentials/SKILL.md (or your agent's skills folder).
name
credentials
description
Instructions for handling API keys and credentials safely, verifying their presence, and prompting the user to add them if missing using a safe protocol.

Safe Credentials Protocol

Many skills require API keys or other credentials to function or to access higher rate limits. This skill defines the standard safe credentials protocol for verifying and prompting for these credentials without leaking sensitive keys into the agent context or the conversation history.

Safe Verification (No Leaks)

As soon as a skill that requires a credential or API key looks relevant to the user's request, you MUST immediately verify if the credential is present in the .env file (typically located in your home directory ~/.env or the project root) — before doing any other work for that skill.

CRITICAL: You must verify the presence of the credential without printing its value to the terminal or reading it into your context.

How to verify:

Use grep in quiet and suppress-errors mode (-sq) to check if the variable is defined in ~/.env. The -s flag ensures the command works cleanly even if ~/.env does not exist yet.

bash
grep -sq "^CREDENTIAL_NAME=" ~/.env

Replace CREDENTIAL_NAME with the actual credential name required by the calling skill (e.g., ALPHAGENOME_API_KEY or USER_EMAIL).

  • If the command succeeds (exit code 0), the credential is present. You can proceed.
  • If the command fails (any non-zero exit code — whether the credential is missing or the .env file does not exist yet), the credential is missing. You MUST IMMEDIATELY stop and prompt the user to add it using the instructions in Prompting the User to Add Credentials before attempting to run any scripts or tools. Do not conclude the turn by simply stating that the key is missing.

[!CRITICAL] If verification fails (any non-zero exit code), you MUST NOT attempt to execute any tools or scripts from the calling skill, nor should you conclude the turn by simply reporting the missing key. You MUST IMMEDIATELY generate the appropriate terminal command from the templates below and prompt the user to run it. The template command will create the .env file if it does not already exist.

NEVER run cat ~/.env, grep "VAR" ~/.env (without -q), echo $VAR, or printenv to check for credentials.

Show full SKILL.md (235 more words)Show less

Prompting the User to Add Credentials

If a credential is missing, do NOT ask the user to paste it into the chat. This would leak the value into the agent's context and the conversation history.

Instead, you MUST generate a specific command for the user to run in their terminal by replacing the placeholders in one of the templates below.

CRITICAL: Before presenting the command to the user, you MUST replace:

  • CREDENTIAL_NAME with the actual variable name needed (e.g., ALPHAGENOME_API_KEY, USER_EMAIL).
  • ENV_FILE with the resolved literal path to the .env file (usually ~/.env).
Template

All credentials are treated as sensitive. The read -s flag hides the user's typing. You MUST inform the user that their typing will be hidden.

CRITICAL: When requesting a credential, you MUST also provide the user with the appropriate registration link or instructions provided by the calling skill so they know how to obtain the value if they do not have one.

bash
printf "Enter CREDENTIAL_NAME (typing hidden): " && read -s val && echo && echo "CREDENTIAL_NAME=$val" >> "ENV_FILE" && echo "Saved."

Running scripts requiring credentials

All helper scripts inside the calling skills load these credentials automatically from the .env file using dotenv.

You do NOT need to manually read the keys, export them to the shell environment, or pass them as CLI arguments, when calling the helper scripts that require them. As long as you have verified the key is present in .env using the safe protocol above, simply run the script directly — the script will load the credential automatically.

© google-deepmind, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/credentials of google-deepmind/science-skills.

Open the folder on GitHubat commit 6883275

Compare with similar skills

Credentials next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Credentials compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Credentials this skillgoogle-deepmind/science-skills3.2k—~1kAutomated safety check: NotesApache-2.0
Hypothesis Generationspacering-net/codeg3.8k15 repos~3.6kAutomated safety check: NotesMIT
GitHub Deep Researchbytedance/deer-flow83k5 repos~1.3kAutomated safety check: PassMIT
Nature Paper CardYuan1z0825/nature-skills46k2 repos~2.1kAutomated safety check: PassApache-2.0
Read arXiv Paperkarpathy/nanochat58k2 repos~494Automated safety check: PassMIT
Content Research Writerweapp-tailwindcss/weapp-tailwindcss1.9k25 repos~3.5kAutomated safety check: PassMIT

Similar skills

  • Hypothesis Generation

    spacering-net/codeg

    Structured hypothesis formulation from observations. An agent skill from spacering-net/codeg.

    3.8k GitHub starsUsed in 15 repos~3.6k tokens
    Research & ScienceAuto-check: notes
  • GitHub Deep Research

    bytedance/deer-flow

    Researches a GitHub repository over four rounds using the GitHub API and web search, then writes a structured markdown report with timeline, metrics and Mermaid diagrams.

    83k GitHub starsUsed in 5 repos~1.3k tokens
    Research & ScienceAuto-check passed
  • Nature Paper Card

    Yuan1z0825/nature-skills

    Builds a structured deep-reading card for one scientific paper, covering methods, how experiments support claims, limitations and research ideas, with a script to prepare the source.

    46k GitHub starsUsed in 2 repos~2.1k tokens
    Research & ScienceAuto-check passed
  • Read arXiv Paper

    karpathy/nanochat

    Fetches the TeX source of an arXiv paper from its URL, reads it and writes a markdown summary tied to the nanochat project.

    58k GitHub starsUsed in 2 repos~494 tokens
    Research & ScienceAuto-check passed
  • Content Research Writer

    weapp-tailwindcss/weapp-tailwindcss

    Assists in writing high-quality content by conducting research, adding citations, improving hooks, iterating on outlines, and providing real-time feedback on each section.

    1.9k GitHub starsUsed in 25 repos~3.5k tokens
    Research & ScienceAuto-check passed
  • Peer Review

    spacering-net/codeg

    Structured manuscript/grant review with checklist-based evaluation.

    3.8k GitHub starsUsed in 18 repos~5.9k tokens
    Research & ScienceAuto-check: notes

More from google-deepmind/science-skills

All 40 skills in this repo
  • Alphafold Database Fetch And Analyze

    google-deepmind/science-skills

    Retrieve and analyze AlphaFold predicted structures for a protein.

    3.2k GitHub starsUsed in 2 repos~1.2k tokens
    Auto-check passed
  • Alphagenome Single Variant Analysis

    google-deepmind/science-skills

    Analyzes genetic variant effects on gene expression (RNA-seq), chromatin accessibility (DNASE), histone marks (ChIP), and transcription factors using the AlphaGenome API.

    3.2k GitHub starsUsed in 2 repos~3k tokens
    Auto-check: notes
  • Chembl Database

    google-deepmind/science-skills

    Query the ChEMBL database for bioactive molecules, drug targets, bioactivity data, approved drugs, and chemical structures.

    3.2k GitHub starsUsed in 2 repos~2.9k tokens
    Auto-check passed
  • Clinical Trials Database

    google-deepmind/science-skills

    Query ClinicalTrials.gov via APIv2. An agent skill from google-deepmind/science-skills.

    3.2k GitHub starsUsed in 2 repos~3.2k tokens
    Auto-check passed
  • Clinvar Database

    google-deepmind/science-skills

    A skill your agent uses when needing clinical significance, pathogenicity classifications (e.g., Pathogenic, Benign, VUS), clinical evidence rationales, or finding "hard positive" benchmark controls…

    3.2k GitHub starsUsed in 2 repos~3.9k tokens
    Auto-check: notes
  • Dbsnp Database

    google-deepmind/science-skills

    A skill your agent uses when you want to look up, map, and search for short genetic variants (SNPs, indels) in NCBI's dbSNP database.

    3.2k GitHub starsUsed in 2 repos~3.4k tokens
    Auto-check: notes

Questions about Credentials

What does Credentials do?

Instructions for handling API keys and credentials safely, verifying their presence, and prompting the user to add them if missing using a safe protocol. Credentials is an agent skill from google-deepmind/science-skills. Instructions for handling API keys and credentials safely, verifying their presence, and prompting the user to add them if missing using a safe protocol.

When should I use Credentials?

Credentials fits situations like: research & Science work in your project.

How do I install Credentials in Claude Code?

Run `npx skills add google-deepmind/science-skills --skill credentials -a claude-code`. Or copy the skill folder (skills/credentials in google-deepmind/science-skills) into .claude/skills/credentials in your project. Claude Code loads it when a task matches its description.

How do I install Credentials in Codex?

Run `npx skills add google-deepmind/science-skills --skill credentials -a codex`. Or copy the skill folder (skills/credentials in google-deepmind/science-skills) into .agents/skills/credentials in your project. Codex loads it when a task matches its description.

Can I use Credentials in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google-deepmind/science-skills --skill credentials -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/credentials, .gemini/skills/credentials, .github/skills/credentials and .opencode/skills/credentials in your project.

What does Credentials need to run?

Going by SKILL.md and its folder, Credentials needs credentials named ALPHAGENOME_API_KEY. Our summary lists: A credential in ALPHAGENOME_API_KEY.

Does Credentials access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Credentials safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Credentials use?

Credentials is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Credentials use?

About 1k tokens (SKILL.md is roughly 4.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Credentials?

Skills that share tags, products or a category with Credentials: Hypothesis Generation (spacering-net/codeg, 3.8k stars), GitHub Deep Research (bytedance/deer-flow, 83k stars), Nature Paper Card (Yuan1z0825/nature-skills, 46k stars) and Read arXiv Paper (karpathy/nanochat, 58k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Credentials?

google-deepmind (a GitHub organization) maintains it in google-deepmind/science-skills, which has 3,216 GitHub stars. The repository holds 40 skills in this directory. The repository was last updated on September 15, 2026.

Source: google-deepmind/science-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.