Agent skill

Output Dev Credentials

by growthxai in growthxai/output

Store and reference encrypted secrets in Output SDK workflows using @outputai/core/credentials.

Apache-2.0Auto-check: notes

Install Output Dev Credentials

skills CLI
$ npx skills add growthxai/output --skill output-dev-credentials -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install growthxai/output output-dev-credentials --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/growthxai/output.git skills-src && mkdir -p .claude/skills && cp -r skills-src/coding_assistants/claude/plugins/outputai/skills/output-dev-credentials .claude/skills/output-dev-credentials && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
output-dev-credentials
GitHub stars
440
Token cost
~2.2k tokens
SKILL.md length
588 words
Files
1
Skills in repo
52
Repo updated
First seen
Licence
Apache-2.0

At a glance

Store and reference encrypted secrets in Output SDK workflows using @outputai/core/credentials.

  • Works in 3 steps: Global Credentials → Environment-Specific Credentials → Per-Workflow Credentials
  • Integrating API keys
  • SKILL.md covers Overview, When to Use This Skill, Library API and CLI Commands, plus 8 more sections
  • Reaches api.service.com; needs OUTPUT_CREDENTIALS_KEY and API_KEY

What it does

Output Dev Credentials is an agent skill from growthxai/output. Store and reference encrypted secrets in Output SDK workflows using @outputai/core/credentials. Use when integrating API keys, database passwords, or third-party tokens.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: The open-source TypeScript framework for building AI workflows and agents. Designed for Claude Code describe what you want, Claude builds it, with all the best practices already… The licence is Apache-2.0.

When your agent uses it

  • Integrating API keys
  • Database passwords
  • Third-party tokens

Example prompts

  • “/output-dev-credentials”

Requirements

  • A credential in OUTPUT_CREDENTIALS_KEY
  • A credential in API_KEY
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash, Glob

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Global Credentials
  2. Environment-Specific Credentials
  3. Per-Workflow Credentials

What it can do on your machine

Read from SKILL.md and the folder at commit 52b51ac. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash
    • Glob

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript, bash and yaml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.service.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OUTPUT_CREDENTIALS_KEY
    • API_KEY
    • SERVICE_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Output Dev Credentials loads about 2.2k tokens when it runs. Until then it costs about 48 tokens; SKILL.md has 588 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~48
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:189
    4. Remove environment variables from `.env` files
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Edit, Bash, Glob

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from growthxai/output at commit 52b51ac, republished under its Apache-2.0 licence (© growthxai). 588 words, ~2,175 tokens.

Download SKILL.mdSave it as .claude/skills/output-dev-credentials/SKILL.md (or your agent's skills folder).
name
output-dev-credentials
description
Store and reference encrypted secrets in Output SDK workflows using @outputai/core/credentials. Use when integrating API keys, database passwords, or third-party tokens.
allowed-tools
Read, Write, Edit, Bash, Glob

Encrypted Credentials Management

Overview

The @outputai/core/credentials package provides encrypted secrets management for Output SDK workflows. It replaces process.env patterns with a structured, encrypted YAML-based system that supports scoped credentials with deep merging.

When to Use This Skill

  • Adding API keys or tokens to a workflow
  • Migrating from process.env to encrypted credentials
  • Setting up per-workflow or per-environment secrets
  • Debugging missing credential errors (MissingCredentialError, MissingKeyError)
  • Configuring custom credential providers (Vault, AWS Secrets Manager)

Library API

Import
typescript
import { credentials } from '@outputai/core/credentials';
credentials.get(path, defaultValue?)

Safe read with optional default. Never throws.

typescript
// Returns value or undefined
const region = credentials.get('aws.region');

// Returns value or default
const region = credentials.get('aws.region', 'us-east-1');
credentials.require(path)

Strict read. Throws MissingCredentialError if not found.

typescript
const apiKey = credentials.require('anthropic.api_key');
Error Types
ErrorThrown WhenFix
MissingCredentialErrorcredentials.require() path not foundAdd the credential via output credentials edit
MissingKeyErrorNo decryption key availableSet OUTPUT_CREDENTIALS_KEY env var or create .key file
InvalidCredentialsKeyErrorKey doesn't match the encrypted file, or the file is corruptedUse the key the file was encrypted with
MalformedCredentialsKeyErrorKey isn't exactly 64 hex charactersCheck the key for typos, whitespace, or truncation

All four extend FatalError, so a step that throws one fails without retries. A key error while resolving credential: env vars stops the worker at startup.

CLI Commands

bash
# Initialize credentials (generates key + encrypted YAML template)
output credentials init                              # Global
output credentials init -e production                 # Environment-specific
output credentials init -w payment_processing         # Workflow-specific

# Edit credentials (decrypts, opens $EDITOR, re-encrypts on save)
output credentials edit                               # Global
output credentials edit -e production                  # Environment
output credentials edit -w payment_processing          # Workflow

# Show decrypted credentials (debugging)
output credentials show                               # Global
output credentials show -e development                 # Environment

# Set a single credential value (no editor needed)
output credentials set anthropic.api_key sk-ant-...    # Global
output credentials set stripe.key sk_live_... -w payment_processing # Workflow

# Get single credential value
output credentials get anthropic.api_key               # Global
output credentials get stripe.key -w payment_processing # Workflow

Flags:

  • -e / --environment: Target environment (production or development, the only values the worker reads)
  • -w / --workflow: Target a specific workflow
  • -f / --force: init overwrites existing credentials; edit and set re-encrypt with the current key when it can't decrypt the file (discards existing values)
  • -y / --yes: Skip the confirmation when set replaces a value of a different shape (set only)
  • Note: -e and -w are mutually exclusive

Three-Tier Scope System

1. Global Credentials
config/credentials.yml.enc    # Encrypted YAML
config/credentials.key        # Decryption key (DO NOT COMMIT)

Key env var: OUTPUT_CREDENTIALS_KEY

2. Environment-Specific Credentials
config/credentials/production.yml.enc
config/credentials/production.key

Key env var: OUTPUT_CREDENTIALS_KEY_PRODUCTION

3. Per-Workflow Credentials
src/workflows/{name}/credentials.yml.enc
src/workflows/{name}/credentials.key

Key env var: OUTPUT_CREDENTIALS_KEY_{WORKFLOW_NAME} (uppercased)

Key Resolution Chain

For each scope, the key is resolved in order:

  1. Environment variable (OUTPUT_CREDENTIALS_KEY, OUTPUT_CREDENTIALS_KEY_{ENV}, or OUTPUT_CREDENTIALS_KEY_{WORKFLOW})
  2. Key file on disk (e.g., config/credentials.key)
  3. Throws MissingKeyError if neither found

Workflow credentials fall back to the global key if no workflow-specific key exists.

Credential Merging

When a workflow has its own credentials, they deep-merge over global credentials. Workflow values win at the same path:

yaml
# Global (config/credentials.yml.enc)
anthropic:
  api_key: sk-ant-global
aws:
  region: us-east-1

# Workflow (src/workflows/my_workflow/credentials.yml.enc)
anthropic:
  api_key: sk-ant-workflow-specific
stripe:
  secret_key: sk_live_workflow

# Merged result at runtime:
# anthropic.api_key  -> sk-ant-workflow-specific  (overridden by workflow)
# aws.region         -> us-east-1                 (from global)
# stripe.secret_key  -> sk_live_workflow           (added by workflow)

Migration from process.env

Before (old pattern)
typescript
import { createKyClient } from '@outputai/http';

const API_KEY = process.env.SERVICE_API_KEY || '';

const client = createKyClient({
  prefix: 'https://api.service.com',
  headers: { Authorization: `Bearer ${API_KEY}` }
});
After (credentials pattern)
typescript
import { createKyClient } from '@outputai/http';
import { credentials } from '@outputai/core/credentials';

const apiKey = credentials.require('service.api_key');

const client = createKyClient({
  prefix: 'https://api.service.com',
  headers: { Authorization: `Bearer ${apiKey}` }
});
Show full SKILL.md (237 more words)Show less
Migration Steps
  1. Run output credentials init to create the encrypted file and key
  2. Run output credentials edit (or output credentials set <path> <value>) to add your secrets
  3. Replace process.env.X reads with credentials.require('x') or credentials.get('x', default)
  4. Remove environment variables from .env files
  5. Add *.key to .gitignore

Custom Providers

Replace the default encrypted YAML backend with Vault, AWS Secrets Manager, etc.:

typescript
import { setProvider } from '@outputai/core/credentials';

setProvider({
  loadGlobal: ({ environment }) => {
    return fetchFromVault(`credentials/${environment || 'default'}`);
  },
  loadForWorkflow: ({ workflowName, environment }) => {
    return fetchFromVault(`workflows/${workflowName}`) ?? null;
  }
});

Call setProvider() in a hook file listed under outputai.hookFiles, not in step code. Hook files load before the worker resolves credential: env vars, so those resolve through the custom provider too.

Provider Interface
typescript
interface CredentialsProvider {
  loadGlobal(context: { environment: string | undefined }): Record<string, unknown>;
  loadForWorkflow(context: {
    workflowName: string;
    workflowDir: string | undefined;
    environment?: string | undefined;
  }): Record<string, unknown> | null;
}

Security Considerations

  • Never commit .key files - Add *.key to .gitignore
  • Safe to commit .yml.enc files - Cannot be read without the key
  • Key file permissions - Created with mode 0o600 (owner-only read/write)
  • Temp file cleanup - Plaintext overwritten with null bytes before deletion during edit
  • Use env vars in CI/CD - Set OUTPUT_CREDENTIALS_KEY in your pipeline
  • Encryption - AES-256-GCM with unique random nonce per encryption

Verification Checklist

  • credentials imported from @outputai/core/credentials
  • credentials.require() used for mandatory secrets (not process.env)
  • credentials.get() used with default for optional values
  • *.key listed in .gitignore
  • Credentials initialized via output credentials init
  • Secrets added via output credentials edit
  • output-credentials-init - Initializing credentials files for the first time
  • output-credentials-edit - Viewing and editing credential values
  • output-credentials-env-vars - Wiring credentials to env vars with the credential: convention
  • output-dev-http-client-create - Creating HTTP clients that use credentials
  • output-dev-step-function - Using credentials in step functions
  • output-error-http-client - Troubleshooting HTTP client issues

© growthxai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in coding_assistants/claude/plugins/outputai/skills/output-dev-credentials of growthxai/output.

Open the folder on GitHubat commit 52b51ac

Compare with similar skills

Output Dev Credentials next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Output Dev Credentials compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Output Dev Credentials this skillgrowthxai/output440—~2.2kAutomated safety check: NotesApache-2.0
Secrets Vault Manageralirezarezvani/claude-skills28k1 repos~3.6kAutomated safety check: NotesMIT
Openclaw Secret Scanning Maintaineropenclaw/openclaw392k—~2.5kAutomated safety check: PassMIT
Secret Scanninggithub/awesome-copilot40k1 repos~2.4kAutomated safety check: PassMIT
Leaked Secretsthedaviddias/Front-End-Checklist74k—~596Automated safety check: NotesMIT
Secrets Managementdavila7/claude-code-templates32k12 repos~2kAutomated safety check: PassMIT

Similar skills

  • Secrets Vault Manager

    alirezarezvani/claude-skills

    A skill your agent uses when the user asks to set up secret management infrastructure, integrate HashiCorp Vault, configure cloud secret stores (AWS Secrets Manager, Azure Key Vault, GCP Secret…

    28k GitHub starsUsed in 1 repo~3.6k tokens
    DevOps & CloudAuto-check: notes
  • Triage, redact, clean up, and resolve OpenClaw GitHub Secret Scanning alerts in issues or PRs.

    392k GitHub stars~2.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Secret Scanning

    github/awesome-copilot

    Official

    Guide for configuring and managing GitHub secret scanning, push protection, custom patterns, and secret alert remediation.

    40k GitHub starsUsed in 1 repo~2.4k tokens
    DevOps & CloudAuto-check passed
  • Leaked Secrets

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing client-side JavaScript, HTML source, or git history for exposed credentials, API keys, or tokens.

    74k GitHub stars~596 tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Secrets Management

    davila7/claude-code-templates

    Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools.

    32k GitHub starsUsed in 12 repos~2k tokens
    DevOps & CloudAuto-check passed
  • Implementing Secrets Management With Vault

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy HashiCorp Vault for centralized secrets management, covering dynamic secret generation for databases and cloud providers, transit encryption, PKI certificate management, and Kubernetes…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from growthxai/output

All 52 skills in this repo
  • Zod schema constraints that Anthropic rejects or silently ignores when sent as structured-output tool definitions via aiSdk.Output.object().

    440 GitHub stars~597 tokensUpdated yesterday
    Auto-check passed
  • Output Build Workflow

    growthxai/output

    Implement an Output SDK workflow from a plan document. An agent skill from growthxai/output.

    440 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check passed
  • Output Credentials Edit

    growthxai/output

    View, edit, and set encrypted credentials in an Output.ai project.

    440 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check: notes
  • Wire encrypted credentials to environment variables using the credential: convention.

    440 GitHub stars~930 tokensUpdated yesterday
    Auto-check: notes
  • Output Credentials Init

    growthxai/output

    Initialize encrypted credentials for an Output.ai project. An agent skill from growthxai/output.

    440 GitHub stars~803 tokensUpdated yesterday
    Auto-check: notes
  • Output Debug Workflow

    growthxai/output

    Debug Output SDK workflow issues. An agent skill from growthxai/output.

    440 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed

Questions about Output Dev Credentials

What does Output Dev Credentials do?

Store and reference encrypted secrets in Output SDK workflows using @outputai/core/credentials. Output Dev Credentials is an agent skill from growthxai/output. Store and reference encrypted secrets in Output SDK workflows using @outputai/core/credentials.

When should I use Output Dev Credentials?

Output Dev Credentials fits situations like: integrating API keys; database passwords; third-party tokens.

How do I install Output Dev Credentials in Claude Code?

Run `npx skills add growthxai/output --skill output-dev-credentials -a claude-code`. Or copy the skill folder (coding_assistants/claude/plugins/outputai/skills/output-dev-credentials in growthxai/output) into .claude/skills/output-dev-credentials in your project. Claude Code loads it when a task matches its description.

How do I install Output Dev Credentials in Codex?

Run `npx skills add growthxai/output --skill output-dev-credentials -a codex`. Or copy the skill folder (coding_assistants/claude/plugins/outputai/skills/output-dev-credentials in growthxai/output) into .agents/skills/output-dev-credentials in your project. Codex loads it when a task matches its description.

Can I use Output Dev Credentials in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add growthxai/output --skill output-dev-credentials -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/output-dev-credentials, .gemini/skills/output-dev-credentials, .github/skills/output-dev-credentials and .opencode/skills/output-dev-credentials in your project.

What does Output Dev Credentials need to run?

Going by SKILL.md and its folder, Output Dev Credentials needs credentials named OUTPUT_CREDENTIALS_KEY, API_KEY and SERVICE_API_KEY. Our summary lists: A credential in OUTPUT_CREDENTIALS_KEY; A credential in API_KEY. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash, Glob.

Does Output Dev Credentials access the network?

SKILL.md names 1 domain. In commands or code: api.service.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Output Dev Credentials safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Output Dev Credentials use?

Output Dev Credentials is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Output Dev Credentials use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Output Dev Credentials?

Skills that share tags, products or a category with Output Dev Credentials: Secrets Vault Manager (alirezarezvani/claude-skills, 28k stars), Openclaw Secret Scanning Maintainer (openclaw/openclaw, 392k stars), Secret Scanning (github/awesome-copilot, 40k stars) and Leaked Secrets (thedaviddias/Front-End-Checklist, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Output Dev Credentials?

growthxai (a GitHub organization) maintains it in growthxai/output, which has 440 GitHub stars. The repository holds 52 skills in this directory. The repository was last updated on October 7, 2026.

Source: growthxai/output on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.