Agent skill

Output Credentials Env Vars

by growthxai in growthxai/output

Wire encrypted credentials to environment variables using the credential: convention.

Apache-2.0Auto-check: notesAI & LLM Engineering

Install Output Credentials Env Vars

skills CLI
$ npx skills add growthxai/output --skill output-credentials-env-vars -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install growthxai/output output-credentials-env-vars --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/growthxai/output.git skills-src && mkdir -p .claude/skills && cp -r skills-src/coding_assistants/claude/plugins/outputai/skills/output-credentials-env-vars .claude/skills/output-credentials-env-vars && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
output-credentials-env-vars
GitHub stars
442
Token cost
~930 tokens
SKILL.md length
296 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
Apache-2.0

At a glance

Wire encrypted credentials to environment variables using the credential: convention.

  • Works in 3 steps: Initialize credentials (if not done) → Update .env → Verify
  • Setting up LLM provider keys (ANTHROPICAPIKEY
  • SKILL.md covers When to Use This Skill, The credential: Convention, How It Works and Precedence Rules, plus 3 more sections
  • Calls npx; needs ANTHROPIC_API_KEY and OPENAI_API_KEY

What it does

Output Credentials Env Vars is an agent skill from growthxai/output. Wire encrypted credentials to environment variables using the credential: convention. Use when setting up LLM provider keys (ANTHROPICAPIKEY, OPENAIAPIKEY) or any env var that should come from encrypted credentials.

Its SKILL.md is about 930 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in AI & LLM Engineering, covering LLM API integration and Secrets management. It works with Anthropic API and OpenAI. The repository describes itself as: The open-source TypeScript framework for building AI workflows and agents. Designed for Claude Code describe what you want, Claude builds it, with all the best practices already… The licence is Apache-2.0.

When your agent uses it

  • Setting up LLM provider keys (ANTHROPICAPIKEY
  • Any env var that should come from encrypted credentials

Example prompts

  • “/output-credentials-env-vars”

Requirements

  • Node.js
  • A credential in ANTHROPIC_API_KEY
  • A credential in OPENAI_API_KEY
  • Pre-approved tools (allowed-tools): Read, Edit, Bash, Glob

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Initialize credentials (if not done)
  2. Update .env
  3. Verify

What it can do on your machine

Read from SKILL.md and the folder at commit 99ee298. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Edit
    • Bash
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ANTHROPIC_API_KEY
    • OPENAI_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Output Credentials Env Vars loads about 930 tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 296 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~930

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:13
    - Migrating from plaintext `.env` secrets to encrypted credentials
  • NoteMentions a .env fileSKILL.md:24
    ### Example `.env`
  • NoteMentions a .env fileSKILL.md:81
    ### Step 2: Update `.env`
  • NoteMentions a .env fileSKILL.md:102
    - [ ] `.env` uses `credential:<path>` values for the relevant env vars
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Edit, Bash, Glob

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from growthxai/output at commit 99ee298, republished under its Apache-2.0 licence (© growthxai). 296 words, ~930 tokens.

Download SKILL.mdSave it as .claude/skills/output-credentials-env-vars/SKILL.md (or your agent's skills folder).
name
output-credentials-env-vars
description
Wire encrypted credentials to environment variables using the credential: convention. Use when setting up LLM provider keys (ANTHROPIC_API_KEY, OPENAI_API_KEY) or any env var that should come from encrypted credentials.
allowed-tools
Read, Edit, Bash, Glob

Credentials as Environment Variables

When to Use This Skill

  • Setting up ANTHROPIC_API_KEY or OPENAI_API_KEY from encrypted credentials
  • Wiring any credential path to a process.env variable automatically
  • Migrating from plaintext .env secrets to encrypted credentials
  • Understanding why an env var is being resolved at worker startup

The credential: Convention

Any env var whose value starts with credential: is resolved from encrypted credentials at worker startup. The format is:

ENV_VAR_NAME=credential:<dot.path>
Example .env
bash
# These are resolved automatically from the global credentials
ANTHROPIC_API_KEY=credential:anthropic.api_key
OPENAI_API_KEY=credential:openai.api_key

# Any credential path works
MY_SERVICE_TOKEN=credential:my_service.token
DATABASE_URL=credential:postgres.url
Encrypted credentials (config/credentials.yml.enc)
yaml
anthropic:
  api_key: sk-ant-...        # → resolves ANTHROPIC_API_KEY

openai:
  api_key: sk-...            # → resolves OPENAI_API_KEY

my_service:
  token: tok_live_...        # → resolves MY_SERVICE_TOKEN

postgres:
  url: postgres://...        # → resolves DATABASE_URL

How It Works

When the worker starts, every env var set to credential:<path> is replaced with the decrypted value at that path. By the time a workflow runs, ANTHROPIC_API_KEY holds the real key and LLM SDKs read it as usual.

Values come from the global credentials for the current environment: config/credentials/<NODE_ENV>.yml.enc when it exists, otherwise config/credentials.yml.enc. Workflow-scoped credentials are never used for env vars, so keep these paths in the global file.

Precedence Rules

Real env var values always take precedence. If ANTHROPIC_API_KEY is already set to a non-credential: value (e.g. from the shell or a CI secret), it is never overwritten:

bash
# Real value - never replaced
ANTHROPIC_API_KEY=sk-ant-real-override

# Placeholder — gets replaced at startup
ANTHROPIC_API_KEY=credential:anthropic.api_key

This means you can override any credential ref at deploy time without changing files.

Setting Up the Convention

Step 1: Initialize credentials (if not done)
bash
npx output credentials init
npx output credentials edit   # Add anthropic.api_key, openai.api_key
Step 2: Update .env
bash
# Replace plaintext secrets with credential references
ANTHROPIC_API_KEY=credential:anthropic.api_key
OPENAI_API_KEY=credential:openai.api_key
Step 3: Verify

Start the worker and look for the log line:

[info] Credentials: Resolved credential env vars { vars: [ "ANTHROPIC_API_KEY", "OPENAI_API_KEY" ] }

If the log line lists your env vars, credentials are wired correctly.

Verification Checklist

  • config/credentials.yml.enc contains the target credential paths
  • .env uses credential:<path> values for the relevant env vars
  • Worker startup log shows Resolved credential env vars listing the expected env vars
  • First LLM workflow run succeeds (confirming ANTHROPIC_API_KEY is set correctly)
  • Setting a real env var in the shell overrides the credential ref
  • output-credentials-init — Create the encrypted credentials file
  • output-credentials-edit — Add/update credential values
  • output-dev-credentials — Full credentials system reference

© growthxai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in coding_assistants/claude/plugins/outputai/skills/output-credentials-env-vars of growthxai/output.

Open the folder on GitHubat commit 99ee298

Compare with similar skills

Output Credentials Env Vars next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Output Credentials Env Vars compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Output Credentials Env Vars this skillgrowthxai/output442—~930Automated safety check: NotesApache-2.0
ModLens Image Vision Bridgeliustack/modlens4.2k—~1.3kAutomated safety check: NotesMIT
Claude APIKocoro-lab/Kocoro4147 repos~4.5kAutomated safety check: PassApache-2.0
Using Ccproxy Inspectorstarbaser/ccproxy350—~2.7kAutomated safety check: PassCustom licence
Using Ccproxy APIstarbaser/ccproxy350—~4kAutomated safety check: PassCustom licence
Update Libstingly-dev/tingly-box351—~830Automated safety check: PassMPL-2.0

Similar skills

  • Gives text-only models sight by running the modlens CLI on an image path or URL and returning structured JSON evidence with transcribed text, layout and semantics.

    4.2k GitHub stars~1.3k tokensUpdated 7 days ago
    AI & LLM EngineeringAuto-check: notes
  • Claude API

    Kocoro-lab/Kocoro

    Build apps with the Claude API or Anthropic SDK. An agent skill from Kocoro-lab/Kocoro.

    414 GitHub starsUsed in 7 repos~4.5k tokens
    AI & LLM EngineeringAuto-check passed
  • Using Ccproxy Inspector

    starbaser/ccproxy

    Operates the ccproxy inspector MITM system for intercepting, inspecting, and transforming LLM API traffic.

    350 GitHub stars~2.7k tokensUpdated 2 mo ago
    AI & LLM EngineeringAuto-check passed
  • Using Ccproxy API

    starbaser/ccproxy

    Guides users through ccproxy as an OpenAI-compatible and Anthropic-compatible LLM API server with SDK integration, OAuth authentication, sentinel key substitution, model routing, and troubleshooting.

    350 GitHub stars~4k tokensUpdated 2 mo ago
    AI & LLM EngineeringAuto-check passed
  • Update Libs

    tingly-dev/tingly-box

    Update the libs/ SDK submodules (openai-go, anthropic-sdk-go, go-genai) to new upstream/fork versions, adapt tingly-box to API changes, and verify with build + vet + tests.

    351 GitHub stars~830 tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Get API Docs

    sudomakes/backroad

    A skill your agent uses when you need documentation for a third-party library, SDK, or API before writing code that uses it — for example, "use the OpenAI API", "call the Stripe API", "use the…

    162 GitHub stars~1k tokensUpdated 3 mo ago
    AI & LLM EngineeringAuto-check passed

More from growthxai/output

All 50 skills in this repo
  • Output Build Workflow

    growthxai/output

    Implement an Output SDK workflow from a plan document. An agent skill from growthxai/output.

    442 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Output Credentials Edit

    growthxai/output

    View, edit, and set encrypted credentials in an Output.ai project.

    442 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check: notes
  • Output Credentials Init

    growthxai/output

    Initialize encrypted credentials for an Output.ai project. An agent skill from growthxai/output.

    442 GitHub stars~803 tokensUpdated yesterday
    Auto-check: notes
  • Output Debug Workflow

    growthxai/output

    Debug Output SDK workflow issues. An agent skill from growthxai/output.

    442 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed
  • Output Dev Agent Class

    growthxai/output

    Use the Agent class for multi-step tool loops, conversation history, streaming progress, and reusable LLM agents.

    442 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check passed
  • Output Dev Code Style

    growthxai/output

    Code style conventions for Output SDK workflow projects. An agent skill from growthxai/output.

    442 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check: notes

Questions about Output Credentials Env Vars

What does Output Credentials Env Vars do?

Wire encrypted credentials to environment variables using the credential: convention. Output Credentials Env Vars is an agent skill from growthxai/output. Wire encrypted credentials to environment variables using the credential: convention.

When should I use Output Credentials Env Vars?

Output Credentials Env Vars fits situations like: setting up LLM provider keys (ANTHROPICAPIKEY; any env var that should come from encrypted credentials.

How do I install Output Credentials Env Vars in Claude Code?

Run `npx skills add growthxai/output --skill output-credentials-env-vars -a claude-code`. Or copy the skill folder (coding_assistants/claude/plugins/outputai/skills/output-credentials-env-vars in growthxai/output) into .claude/skills/output-credentials-env-vars in your project. Claude Code loads it when a task matches its description.

How do I install Output Credentials Env Vars in Codex?

Run `npx skills add growthxai/output --skill output-credentials-env-vars -a codex`. Or copy the skill folder (coding_assistants/claude/plugins/outputai/skills/output-credentials-env-vars in growthxai/output) into .agents/skills/output-credentials-env-vars in your project. Codex loads it when a task matches its description.

Can I use Output Credentials Env Vars in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add growthxai/output --skill output-credentials-env-vars -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/output-credentials-env-vars, .gemini/skills/output-credentials-env-vars, .github/skills/output-credentials-env-vars and .opencode/skills/output-credentials-env-vars in your project.

What does Output Credentials Env Vars need to run?

Going by SKILL.md and its folder, Output Credentials Env Vars needs the command-line tools its instructions call (npx) and credentials named ANTHROPIC_API_KEY and OPENAI_API_KEY. Our summary lists: Node.js; A credential in ANTHROPIC_API_KEY; A credential in OPENAI_API_KEY. Its frontmatter pre-approves these tools: Read, Edit, Bash, Glob.

Does Output Credentials Env Vars access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Output Credentials Env Vars safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Output Credentials Env Vars use?

Output Credentials Env Vars is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Output Credentials Env Vars use?

About 930 tokens (SKILL.md is roughly 3.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Output Credentials Env Vars?

Skills that share tags, products or a category with Output Credentials Env Vars: ModLens Image Vision Bridge (liustack/modlens, 4.2k stars), Claude API (Kocoro-lab/Kocoro, 414 stars), Using Ccproxy Inspector (starbaser/ccproxy, 350 stars) and Using Ccproxy API (starbaser/ccproxy, 350 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Output Credentials Env Vars?

growthxai (a GitHub organization) maintains it in growthxai/output, which has 442 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on October 9, 2026.

Source: growthxai/output on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.