Secrets Vault Manager
alirezarezvani/claude-skills
A skill your agent uses when the user asks to set up secret management infrastructure, integrate HashiCorp Vault, configure cloud secret stores (AWS Secrets Manager, Azure Key Vault, GCP Secret…
Store and reference encrypted secrets in Output SDK workflows using @outputai/core/credentials.
$ npx skills add growthxai/output --skill output-dev-credentials -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install growthxai/output output-dev-credentials --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/growthxai/output.git skills-src && mkdir -p .claude/skills && cp -r skills-src/coding_assistants/claude/plugins/outputai/skills/output-dev-credentials .claude/skills/output-dev-credentials && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "output-dev-credentials" agent skill from https://github.com/growthxai/output/tree/main/coding_assistants/claude/plugins/outputai/skills/output-dev-credentials into .claude/skills/output-dev-credentials/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "output-dev-credentials", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/growthxai/output/tree/main/coding_assistants/claude/plugins/outputai/skills/output-dev-credentialsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add growthxai/output --skill output-dev-credentials -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install growthxai/output output-dev-credentials --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/growthxai/output.git skills-src && mkdir -p .agents/skills && cp -r skills-src/coding_assistants/claude/plugins/outputai/skills/output-dev-credentials .agents/skills/output-dev-credentials && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "output-dev-credentials" agent skill from https://github.com/growthxai/output/tree/main/coding_assistants/claude/plugins/outputai/skills/output-dev-credentials into .agents/skills/output-dev-credentials/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "output-dev-credentials", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add growthxai/output --skill output-dev-credentials -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install growthxai/output output-dev-credentials --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/growthxai/output.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/coding_assistants/claude/plugins/outputai/skills/output-dev-credentials .cursor/skills/output-dev-credentials && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "output-dev-credentials" agent skill from https://github.com/growthxai/output/tree/main/coding_assistants/claude/plugins/outputai/skills/output-dev-credentials into .cursor/skills/output-dev-credentials/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "output-dev-credentials", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/growthxai/output.git --path coding_assistants/claude/plugins/outputai/skills/output-dev-credentials--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add growthxai/output --skill output-dev-credentials -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install growthxai/output output-dev-credentials --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/growthxai/output.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/coding_assistants/claude/plugins/outputai/skills/output-dev-credentials .gemini/skills/output-dev-credentials && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "output-dev-credentials" agent skill from https://github.com/growthxai/output/tree/main/coding_assistants/claude/plugins/outputai/skills/output-dev-credentials into .gemini/skills/output-dev-credentials/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "output-dev-credentials", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install growthxai/output output-dev-credentialsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add growthxai/output --skill output-dev-credentials -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/growthxai/output.git skills-src && mkdir -p .github/skills && cp -r skills-src/coding_assistants/claude/plugins/outputai/skills/output-dev-credentials .github/skills/output-dev-credentials && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "output-dev-credentials" agent skill from https://github.com/growthxai/output/tree/main/coding_assistants/claude/plugins/outputai/skills/output-dev-credentials into .github/skills/output-dev-credentials/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "output-dev-credentials", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add growthxai/output --skill output-dev-credentials -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install growthxai/output output-dev-credentials --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/growthxai/output.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/coding_assistants/claude/plugins/outputai/skills/output-dev-credentials .opencode/skills/output-dev-credentials && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "output-dev-credentials" agent skill from https://github.com/growthxai/output/tree/main/coding_assistants/claude/plugins/outputai/skills/output-dev-credentials into .opencode/skills/output-dev-credentials/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "output-dev-credentials", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
output-dev-credentialsStore and reference encrypted secrets in Output SDK workflows using @outputai/core/credentials.
Output Dev Credentials is an agent skill from growthxai/output. Store and reference encrypted secrets in Output SDK workflows using @outputai/core/credentials. Use when integrating API keys, database passwords, or third-party tokens.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: The open-source TypeScript framework for building AI workflows and agents. Designed for Claude Code describe what you want, Claude builds it, with all the best practices already… The licence is Apache-2.0.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 52b51ac. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadWriteEditBashGlobFrom allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript, bash and yaml).
From the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.service.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
OUTPUT_CREDENTIALS_KEYAPI_KEYSERVICE_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Output Dev Credentials loads about 2.2k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 588 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
4. Remove environment variables from `.env` filesallowed-tools: Read, Write, Edit, Bash, GlobAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from growthxai/output at commit 52b51ac, republished under its Apache-2.0 licence (© growthxai). 588 words, ~2,175 tokens.
.claude/skills/output-dev-credentials/SKILL.md (or your agent's skills folder).The @outputai/core/credentials package provides encrypted secrets management for Output SDK workflows. It replaces process.env patterns with a structured, encrypted YAML-based system that supports scoped credentials with deep merging.
process.env to encrypted credentialsMissingCredentialError, MissingKeyError)import { credentials } from '@outputai/core/credentials';credentials.get(path, defaultValue?)Safe read with optional default. Never throws.
// Returns value or undefined
const region = credentials.get('aws.region');
// Returns value or default
const region = credentials.get('aws.region', 'us-east-1');credentials.require(path)Strict read. Throws MissingCredentialError if not found.
const apiKey = credentials.require('anthropic.api_key');| Error | Thrown When | Fix |
|---|---|---|
MissingCredentialError | credentials.require() path not found | Add the credential via output credentials edit |
MissingKeyError | No decryption key available | Set OUTPUT_CREDENTIALS_KEY env var or create .key file |
InvalidCredentialsKeyError | Key doesn't match the encrypted file, or the file is corrupted | Use the key the file was encrypted with |
MalformedCredentialsKeyError | Key isn't exactly 64 hex characters | Check the key for typos, whitespace, or truncation |
All four extend FatalError, so a step that throws one fails without retries. A key error while resolving credential: env vars stops the worker at startup.
# Initialize credentials (generates key + encrypted YAML template)
output credentials init # Global
output credentials init -e production # Environment-specific
output credentials init -w payment_processing # Workflow-specific
# Edit credentials (decrypts, opens $EDITOR, re-encrypts on save)
output credentials edit # Global
output credentials edit -e production # Environment
output credentials edit -w payment_processing # Workflow
# Show decrypted credentials (debugging)
output credentials show # Global
output credentials show -e development # Environment
# Set a single credential value (no editor needed)
output credentials set anthropic.api_key sk-ant-... # Global
output credentials set stripe.key sk_live_... -w payment_processing # Workflow
# Get single credential value
output credentials get anthropic.api_key # Global
output credentials get stripe.key -w payment_processing # WorkflowFlags:
-e / --environment: Target environment (production or development, the only values the worker reads)-w / --workflow: Target a specific workflow-f / --force: init overwrites existing credentials; edit and set re-encrypt with the current key when it can't decrypt the file (discards existing values)-y / --yes: Skip the confirmation when set replaces a value of a different shape (set only)-e and -w are mutually exclusiveconfig/credentials.yml.enc # Encrypted YAML
config/credentials.key # Decryption key (DO NOT COMMIT)Key env var: OUTPUT_CREDENTIALS_KEY
config/credentials/production.yml.enc
config/credentials/production.keyKey env var: OUTPUT_CREDENTIALS_KEY_PRODUCTION
src/workflows/{name}/credentials.yml.enc
src/workflows/{name}/credentials.keyKey env var: OUTPUT_CREDENTIALS_KEY_{WORKFLOW_NAME} (uppercased)
For each scope, the key is resolved in order:
OUTPUT_CREDENTIALS_KEY, OUTPUT_CREDENTIALS_KEY_{ENV}, or OUTPUT_CREDENTIALS_KEY_{WORKFLOW})config/credentials.key)MissingKeyError if neither foundWorkflow credentials fall back to the global key if no workflow-specific key exists.
When a workflow has its own credentials, they deep-merge over global credentials. Workflow values win at the same path:
# Global (config/credentials.yml.enc)
anthropic:
api_key: sk-ant-global
aws:
region: us-east-1
# Workflow (src/workflows/my_workflow/credentials.yml.enc)
anthropic:
api_key: sk-ant-workflow-specific
stripe:
secret_key: sk_live_workflow
# Merged result at runtime:
# anthropic.api_key -> sk-ant-workflow-specific (overridden by workflow)
# aws.region -> us-east-1 (from global)
# stripe.secret_key -> sk_live_workflow (added by workflow)process.envimport { createKyClient } from '@outputai/http';
const API_KEY = process.env.SERVICE_API_KEY || '';
const client = createKyClient({
prefix: 'https://api.service.com',
headers: { Authorization: `Bearer ${API_KEY}` }
});import { createKyClient } from '@outputai/http';
import { credentials } from '@outputai/core/credentials';
const apiKey = credentials.require('service.api_key');
const client = createKyClient({
prefix: 'https://api.service.com',
headers: { Authorization: `Bearer ${apiKey}` }
});output credentials init to create the encrypted file and keyoutput credentials edit (or output credentials set <path> <value>) to add your secretsprocess.env.X reads with credentials.require('x') or credentials.get('x', default).env files*.key to .gitignoreReplace the default encrypted YAML backend with Vault, AWS Secrets Manager, etc.:
import { setProvider } from '@outputai/core/credentials';
setProvider({
loadGlobal: ({ environment }) => {
return fetchFromVault(`credentials/${environment || 'default'}`);
},
loadForWorkflow: ({ workflowName, environment }) => {
return fetchFromVault(`workflows/${workflowName}`) ?? null;
}
});Call setProvider() in a hook file listed under outputai.hookFiles, not in step code. Hook files load before the worker resolves credential: env vars, so those resolve through the custom provider too.
interface CredentialsProvider {
loadGlobal(context: { environment: string | undefined }): Record<string, unknown>;
loadForWorkflow(context: {
workflowName: string;
workflowDir: string | undefined;
environment?: string | undefined;
}): Record<string, unknown> | null;
}.key files - Add *.key to .gitignore.yml.enc files - Cannot be read without the key0o600 (owner-only read/write)editOUTPUT_CREDENTIALS_KEY in your pipelinecredentials imported from @outputai/core/credentialscredentials.require() used for mandatory secrets (not process.env)credentials.get() used with default for optional values*.key listed in .gitignoreoutput credentials initoutput credentials editoutput-credentials-init - Initializing credentials files for the first timeoutput-credentials-edit - Viewing and editing credential valuesoutput-credentials-env-vars - Wiring credentials to env vars with the credential: conventionoutput-dev-http-client-create - Creating HTTP clients that use credentialsoutput-dev-step-function - Using credentials in step functionsoutput-error-http-client - Troubleshooting HTTP client issues© growthxai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in coding_assistants/claude/plugins/outputai/skills/output-dev-credentials of growthxai/output.
Open the folder on GitHubat commit 52b51ac
Output Dev Credentials next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Output Dev Credentials this skillgrowthxai/output | 440 | — | ~2.2k | Automated safety check: Notes | Apache-2.0 | |
| Secrets Vault Manageralirezarezvani/claude-skills | 28k | 1 repos | ~3.6k | Automated safety check: Notes | MIT | |
| Openclaw Secret Scanning Maintaineropenclaw/openclaw | 392k | — | ~2.5k | Automated safety check: Pass | MIT | |
| Secret Scanninggithub/awesome-copilot | 40k | 1 repos | ~2.4k | Automated safety check: Pass | MIT | |
| Leaked Secretsthedaviddias/Front-End-Checklist | 74k | — | ~596 | Automated safety check: Notes | MIT | |
| Secrets Managementdavila7/claude-code-templates | 32k | 12 repos | ~2k | Automated safety check: Pass | MIT |
alirezarezvani/claude-skills
A skill your agent uses when the user asks to set up secret management infrastructure, integrate HashiCorp Vault, configure cloud secret stores (AWS Secrets Manager, Azure Key Vault, GCP Secret…
openclaw/openclaw
Triage, redact, clean up, and resolve OpenClaw GitHub Secret Scanning alerts in issues or PRs.
github/awesome-copilot
Guide for configuring and managing GitHub secret scanning, push protection, custom patterns, and secret alert remediation.
thedaviddias/Front-End-Checklist
A skill your agent uses when reviewing client-side JavaScript, HTML source, or git history for exposed credentials, API keys, or tokens.
davila7/claude-code-templates
Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools.
mukul975/Anthropic-Cybersecurity-Skills
Deploy HashiCorp Vault for centralized secrets management, covering dynamic secret generation for databases and cloud providers, transit encryption, PKI certificate management, and Kubernetes…
growthxai/output
Zod schema constraints that Anthropic rejects or silently ignores when sent as structured-output tool definitions via aiSdk.Output.object().
growthxai/output
Implement an Output SDK workflow from a plan document. An agent skill from growthxai/output.
growthxai/output
View, edit, and set encrypted credentials in an Output.ai project.
growthxai/output
Wire encrypted credentials to environment variables using the credential: convention.
growthxai/output
Initialize encrypted credentials for an Output.ai project. An agent skill from growthxai/output.
growthxai/output
Debug Output SDK workflow issues. An agent skill from growthxai/output.
Store and reference encrypted secrets in Output SDK workflows using @outputai/core/credentials. Output Dev Credentials is an agent skill from growthxai/output. Store and reference encrypted secrets in Output SDK workflows using @outputai/core/credentials.
Output Dev Credentials fits situations like: integrating API keys; database passwords; third-party tokens.
Run `npx skills add growthxai/output --skill output-dev-credentials -a claude-code`. Or copy the skill folder (coding_assistants/claude/plugins/outputai/skills/output-dev-credentials in growthxai/output) into .claude/skills/output-dev-credentials in your project. Claude Code loads it when a task matches its description.
Run `npx skills add growthxai/output --skill output-dev-credentials -a codex`. Or copy the skill folder (coding_assistants/claude/plugins/outputai/skills/output-dev-credentials in growthxai/output) into .agents/skills/output-dev-credentials in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add growthxai/output --skill output-dev-credentials -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/output-dev-credentials, .gemini/skills/output-dev-credentials, .github/skills/output-dev-credentials and .opencode/skills/output-dev-credentials in your project.
Going by SKILL.md and its folder, Output Dev Credentials needs credentials named OUTPUT_CREDENTIALS_KEY, API_KEY and SERVICE_API_KEY. Our summary lists: A credential in OUTPUT_CREDENTIALS_KEY; A credential in API_KEY. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash, Glob.
SKILL.md names 1 domain. In commands or code: api.service.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Output Dev Credentials is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Output Dev Credentials: Secrets Vault Manager (alirezarezvani/claude-skills, 28k stars), Openclaw Secret Scanning Maintainer (openclaw/openclaw, 392k stars), Secret Scanning (github/awesome-copilot, 40k stars) and Leaked Secrets (thedaviddias/Front-End-Checklist, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
growthxai (a GitHub organization) maintains it in growthxai/output, which has 440 GitHub stars. The repository holds 52 skills in this directory. The repository was last updated on October 7, 2026.
Source: growthxai/output on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.