Agent skill

2password

by kitlangton in kitlangton/2password

A skill your agent uses for any password, API key, token, credential, secret, or 1Password task, including finding credentials, injecting them into commands or env files, saving new API keys…

MITAuto-check: notes

Install 2password

skills CLI
$ npx skills add kitlangton/2password --skill 2password -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kitlangton/2password 2password --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kitlangton/2password.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/2password .claude/skills/2password && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
2password
GitHub stars
276
Token cost
~1.7k tokens
SKILL.md length
746 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses for any password, API key, token, credential, secret, or 1Password task, including finding credentials, injecting them into commands or env files, saving new API keys…

  • Including finding credentials
  • SKILL.md covers Rules, Find credentials, Use credentials and Save a new API key, plus 6 more sections
  • Calls gh; needs OP_SERVICE_ACCOUNT_TOKEN and OPENAI_API_KEY
  • Injecting them into commands

What it does

2password is an agent skill from kitlangton/2password. Use for any password, API key, token, credential, secret, or 1Password task, including finding credentials, injecting them into commands or env files, saving new API keys, checking or updating login passwords, auditing vaults, and setting up unattended access. Prefer the 2password CLI over raw op whenever it covers the task.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: 1Password for coding agents: find, use, and save secrets without exposing them. The licence is MIT.

When your agent uses it

  • Including finding credentials
  • Injecting them into commands
  • Saving new API keys
  • Updating login passwords

Example prompts

  • “/2password”

Requirements

  • A credential in OPENAI_API_KEY
  • A credential in STRIPE_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit e011177. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OP_SERVICE_ACCOUNT_TOKEN
    • OPENAI_API_KEY
    • STRIPE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

2password loads about 1.7k tokens when it runs. Until then it costs about 84 tokens; SKILL.md has 746 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~84
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:30
    2password env write .env.tpl "OPENAI_API_KEY=op://Personal/OpenAI API Key/credential" "STRIPE_KEY=op://Work/Stripe API K
  • NoteMentions a .env fileSKILL.md:31
    2password env run .env.tpl -- bun run dev       # preferred: no plaintext on disk
  • NoteMentions a .env fileSKILL.md:32
    2password env resolve .env.tpl --output .env    # only when a real file is required (mode 0600)
  • NoteMentions a .env fileSKILL.md:36
    h one prompt. Never loop over `read`. A `.env.tpl` that holds only `op://` references is safe to inspect; a resolved `.e

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kitlangton/2password at commit e011177, republished under its MIT licence (© kitlangton). 746 words, ~1,702 tokens.

Download SKILL.mdSave it as .claude/skills/2password/SKILL.md (or your agent's skills folder).
name
2password
description
Use for any password, API key, token, credential, secret, or 1Password task, including finding credentials, injecting them into commands or env files, saving new API keys, checking or updating login passwords, auditing vaults, and setting up unattended access. Prefer the 2password CLI over raw op whenever it covers the task.

2password

2password wraps the 1Password CLI (op) so you can work with secrets without seeing them, and with as few 1Password prompts as possible. All output is JSON.

Rules

  • Never print, log, summarize, or repeat secret values. Pass op:// references around instead.
  • Any 1Password call may show the user an approval prompt, and each new shell you open can need a fresh approval. Batch a task's work into as few commands as possible: many queries in one find, many references in one env file run with env run.
  • Never run op whoami or any other preflight check. Just run the command; the desktop app authorizes it when needed.
  • Never retry a write that failed or reported "unverified". Run find first to check whether it already happened.

Find credentials

bash
2password find openai anthropic "github actions"   # many queries, one prompt
2password find stripe --vault Work --account my.1password.com

Each match appears once as { ref, title, kind }, with queries when you asked several. A query that matches nothing returns suggestions with close titles (typos included) from the same lookup. Use those rather than searching again or listing whole vaults. It never returns values.

Use credentials

bash
2password run --env "OPENAI_API_KEY=op://Personal/OpenAI API Key/credential" -- bun run dev
2password env write .env.tpl "OPENAI_API_KEY=op://Personal/OpenAI API Key/credential" "STRIPE_KEY=op://Work/Stripe API Key/credential"
2password env run .env.tpl -- bun run dev       # preferred: no plaintext on disk
2password env resolve .env.tpl --output .env    # only when a real file is required (mode 0600)
2password read "op://Personal/OpenAI API Key/credential"   # last resort: prints the value

All references in a template resolve with one prompt. Never loop over read. A .env.tpl that holds only op:// references is safe to inspect; a resolved .env is plaintext.

run and env run keep the secret out of argv, the template, and 2password's own output, but the selected child process receives plaintext in its environment. Treat that child as a trusted secret consumer: do not inject credentials into environment-dump/debug commands or helpers whose purpose is to reveal the value.

Save a new API key

bash
2password create api-credential --title "OpenAI API Key" --vault Personal --clipboard
some-command-that-prints-a-key | 2password create api-credential --title "OpenAI API Key" --vault Personal --stdin
  • --vault is required. Use the vault the user names, or their documented default; ask if neither exists.
  • Never put the value in an argument, a command substitution, or a temporary file, and never read the clipboard into the conversation first.
  • Optional --url, --notes, and --account take non-secret metadata only.
  • Success means exit 0 and "verified": true. Reuse the returned ref; don't read it to double-check.
  • Duplicate titles in the vault are refused, and nothing is ever overwritten.

Check or update a login password

bash
2password password "Example Airline" --vault Personal --clipboard           # compare only
2password password "Example Airline" --vault Personal --clipboard --apply   # update, then verify

The command refuses logins that have passkeys or unnamed imported fields. Use --repair-imported-fields only after the user approves it.

Audit a vault

bash
2password inventory --vault Work   # item and field metadata, never values or URL query strings
2password audit --vault Personal   # duplicate titles, untagged machine credentials, old logins, transient URLs

Treat findings as candidates for review. Propose renames or changes, and only make them after the user approves.

Show full SKILL.md (365 more words)Show less

No prompts: service account (macOS, Windows)

If the user is tired of approval prompts, suggest a service account. Only set one up when the user asks.

bash
2password service-account setup --vault Automation --create-vault --write --save-vault Personal

After setup, every command authenticates silently with a token stored in macOS Keychain (on Windows, a DPAPI-encrypted file under %LOCALAPPDATA%), but it can only reach the Automation vault. On Windows, any process running as the user can decrypt that file, so the vault's narrow scope is the real boundary. Keep the credentials agents use in that vault.

  • 2password --desktop <command> uses the normal desktop login, for example to reach other vaults.
  • service-account status | connect --clipboard | recover | forget. forget removes only this Mac's copy; it doesn't revoke the account.
  • If setup fails partway, don't rerun it. Run 2password service-account status.
  • OP_SERVICE_ACCOUNT_TOKEN in the environment overrides the saved account (Linux, CI).
  • run and env run remove the service-account token from the child process's environment.

Item conventions

  • API keys use the API Credential category, the built-in credential field, and a title like <Provider> API Key or <Provider> <Purpose> API Key.
  • Logins use the built-in password field and a title like <Provider> or <Provider> <Account>.
  • The vault shows who owns the item, so don't repeat the vault name in the title. Keep one current secret per item.

Report anything that goes poorly

2password is built for agents, so your experience is how it improves. Speak up if a command fails unexpectedly or you had to work around it. The same goes for more approval prompts than expected, output that's awkward or too verbose, or anything in this skill that's unclear or wrong. Tell the user, and offer to open an issue. It posts publicly from their GitHub account, so get their okay first.

bash
gh issue list --repo kitlangton/2password --state all --search "<keywords>"   # add to an existing issue instead of duplicating it
gh issue create --repo kitlangton/2password --title "<what went wrong>" --body "<details>"

Include the output of 2password doctor (versions and setup; it never prompts and is safe to share), the command you ran, and what you expected versus what happened. Never include secret values, item titles, vault or account names, or op:// references. Replace them with placeholders.

Everything else

Use raw op for other item categories, editing, moving, sharing, deleting, and vault management. Pass plaintext through JSON templates on stdin, never in arguments. After discovery, refer to items and vaults by ID.

© kitlangton, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/2password of kitlangton/2password.

Open the folder on GitHubat commit e011177

Compare with similar skills

2password next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

2password compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
2password this skillkitlangton/2password276—~1.7kAutomated safety check: NotesMIT
Openclaw Secret Scanning Maintaineropenclaw/openclaw392k—~2.5kAutomated safety check: PassMIT
Secret Scanninggithub/awesome-copilot40k1 repos~2.4kAutomated safety check: PassMIT
Leaked Secretsthedaviddias/Front-End-Checklist74k—~596Automated safety check: NotesMIT
Secrets Managementdavila7/claude-code-templates32k12 repos~2kAutomated safety check: PassMIT
Implementing Hashicorp Vault Dynamic Secretsmukul975/Anthropic-Cybersecurity-Skills34k—~5.2kAutomated safety check: PassApache-2.0

Similar skills

  • Triage, redact, clean up, and resolve OpenClaw GitHub Secret Scanning alerts in issues or PRs.

    392k GitHub stars~2.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Secret Scanning

    github/awesome-copilot

    Official

    Guide for configuring and managing GitHub secret scanning, push protection, custom patterns, and secret alert remediation.

    40k GitHub starsUsed in 1 repo~2.4k tokens
    DevOps & CloudAuto-check passed
  • Leaked Secrets

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing client-side JavaScript, HTML source, or git history for exposed credentials, API keys, or tokens.

    74k GitHub stars~596 tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Secrets Management

    davila7/claude-code-templates

    Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools.

    32k GitHub starsUsed in 12 repos~2k tokens
    DevOps & CloudAuto-check passed
  • Implementing Hashicorp Vault Dynamic Secrets

    mukul975/Anthropic-Cybersecurity-Skills

    Configures HashiCorp Vault dynamic secrets engines for database credentials, AWS IAM keys, and PKI certificates, with automatic generation, lease management, and rotation to eliminate static secrets…

    34k GitHub stars~5.2k tokensUpdated 1 mo ago
    Legal & ComplianceAuto-check passed
  • Secrets Vault Manager

    alirezarezvani/claude-skills

    A skill your agent uses when the user asks to set up secret management infrastructure, integrate HashiCorp Vault, configure cloud secret stores (AWS Secrets Manager, Azure Key Vault, GCP Secret…

    28k GitHub starsUsed in 1 repo~3.6k tokens
    DevOps & CloudAuto-check: notes

Questions about 2password

What does 2password do?

A skill your agent uses for any password, API key, token, credential, secret, or 1Password task, including finding credentials, injecting them into commands or env files, saving new API keys…. 2password is an agent skill from kitlangton/2password. Use for any password, API key, token, credential, secret, or 1Password task, including finding credentials, injecting them into commands or env files, saving new API keys, checking or updating login passwords, auditing vaults, and setting up unattended access.

When should I use 2password?

2password fits situations like: including finding credentials; injecting them into commands; saving new API keys; updating login passwords.

How do I install 2password in Claude Code?

Run `npx skills add kitlangton/2password --skill 2password -a claude-code`. Or copy the skill folder (skills/2password in kitlangton/2password) into .claude/skills/2password in your project. Claude Code loads it when a task matches its description.

How do I install 2password in Codex?

Run `npx skills add kitlangton/2password --skill 2password -a codex`. Or copy the skill folder (skills/2password in kitlangton/2password) into .agents/skills/2password in your project. Codex loads it when a task matches its description.

Can I use 2password in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kitlangton/2password --skill 2password -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/2password, .gemini/skills/2password, .github/skills/2password and .opencode/skills/2password in your project.

What does 2password need to run?

Going by SKILL.md and its folder, 2password needs the command-line tools its instructions call (gh) and credentials named OP_SERVICE_ACCOUNT_TOKEN, OPENAI_API_KEY and STRIPE_KEY. Our summary lists: A credential in OPENAI_API_KEY; A credential in STRIPE_KEY.

Does 2password access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is 2password safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does 2password use?

2password is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does 2password use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to 2password?

Skills that share tags, products or a category with 2password: Openclaw Secret Scanning Maintainer (openclaw/openclaw, 392k stars), Secret Scanning (github/awesome-copilot, 40k stars), Leaked Secrets (thedaviddias/Front-End-Checklist, 74k stars) and Secrets Management (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains 2password?

kitlangton (a GitHub user) maintains it in kitlangton/2password, which has 276 GitHub stars. The repository was last updated on October 4, 2026.

Source: kitlangton/2password on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.