Private Secret Scanning
jamditis/claude-skills-journalism
Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports.
How this repo manages API secrets and the four local-run environments (local/dev/staging/prod).
$ npx skills add kortix-ai/suna --skill dotenvx-secrets -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install kortix-ai/suna dotenvx-secrets --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/kortix-ai/suna.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dotenvx-secrets .claude/skills/dotenvx-secrets && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "dotenvx-secrets" agent skill from https://github.com/kortix-ai/suna/tree/dev/.agents/skills/dotenvx-secrets into .claude/skills/dotenvx-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dotenvx-secrets", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/kortix-ai/suna/tree/dev/.agents/skills/dotenvx-secretsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add kortix-ai/suna --skill dotenvx-secrets -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install kortix-ai/suna dotenvx-secrets --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kortix-ai/suna.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/dotenvx-secrets .agents/skills/dotenvx-secrets && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "dotenvx-secrets" agent skill from https://github.com/kortix-ai/suna/tree/dev/.agents/skills/dotenvx-secrets into .agents/skills/dotenvx-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dotenvx-secrets", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kortix-ai/suna --skill dotenvx-secrets -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install kortix-ai/suna dotenvx-secrets --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kortix-ai/suna.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/dotenvx-secrets .cursor/skills/dotenvx-secrets && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "dotenvx-secrets" agent skill from https://github.com/kortix-ai/suna/tree/dev/.agents/skills/dotenvx-secrets into .cursor/skills/dotenvx-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dotenvx-secrets", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/kortix-ai/suna.git --path .agents/skills/dotenvx-secrets--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add kortix-ai/suna --skill dotenvx-secrets -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install kortix-ai/suna dotenvx-secrets --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kortix-ai/suna.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/dotenvx-secrets .gemini/skills/dotenvx-secrets && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "dotenvx-secrets" agent skill from https://github.com/kortix-ai/suna/tree/dev/.agents/skills/dotenvx-secrets into .gemini/skills/dotenvx-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dotenvx-secrets", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install kortix-ai/suna dotenvx-secretsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add kortix-ai/suna --skill dotenvx-secrets -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/kortix-ai/suna.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/dotenvx-secrets .github/skills/dotenvx-secrets && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "dotenvx-secrets" agent skill from https://github.com/kortix-ai/suna/tree/dev/.agents/skills/dotenvx-secrets into .github/skills/dotenvx-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dotenvx-secrets", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kortix-ai/suna --skill dotenvx-secrets -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install kortix-ai/suna dotenvx-secrets --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kortix-ai/suna.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/dotenvx-secrets .opencode/skills/dotenvx-secrets && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "dotenvx-secrets" agent skill from https://github.com/kortix-ai/suna/tree/dev/.agents/skills/dotenvx-secrets into .opencode/skills/dotenvx-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "dotenvx-secrets", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
dotenvx-secretsHow this repo manages API secrets and the four local-run environments (local/dev/staging/prod).
Dotenvx Secrets is an agent skill from kortix-ai/suna. How this repo manages API secrets and the four local-run environments (local/dev/staging/prod). They are dotenvx-ENCRYPTED in git and the keys live in Dotenv Armor. Load this WHENEVER you touch a secret, API key, token, credential, or any apps/api/.env file; whenever the user pastes a key/token/secret to store or use; whenever choosing/switching which environment to run; and whenever adding, reading, rotating, or sharing a secret.
Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Secrets management. It works with Git and pnpm. The repository describes itself as: The open-source AI Operating System.
Read from SKILL.md and the folder at commit 0d853bd. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
pnpmawspython3gitFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
armor.dotenvx.comAlso links to:
dotenvx.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
INTERNAL_SERVICE_KEYDOTENV_PRIVATE_KEYAPI_KEY_SECRETGATEWAY_INTERNAL_TOKENTUNNEL_SIGNING_SECRETDOTENVX_ARMOR_TOKENDOTENV_PUBLIC_KEYVERCEL_API_TOKENDOTENV_ARMOR_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Dotenvx Secrets loads about 4.2k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 1,864 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
key, token, credential, or any apps/api/.env* file; whenever the user pastes a key/token/secret to store or use; whenevplan; one armored key == one `.env*` file). Since 2026-08-26 the two PROD keys(`apps/api/.env.prod`, `apps/web/.env.prod`) are granted to the **owner only**.r member (admin or member role) has all `.env`, `.env.dev`, and`.env.staging` keys. Armor refuses a non-owner `dotenvx run -f .env.prod`private key already pulled into a local `.env.keys` — rotate the| private key in `.env.keys` |v` | **local** | `apps/api/.env` | 100% local stack (local Supabase in Docker, test Stripe) + runsv:dev-env` | **dev** | `apps/api/.env.dev` | the **dev** stack — dev Supabase DB, **test** Stripe, dev keysv:staging-env` | **staging** | `apps/api/.env.staging` | the **staging** stack — staging Supabase DB, test Stripe, stagiAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 1,864 words (~4,244 tokens).
“API secrets are encrypted in git with dotenvx; the decryption keys live off-device in Dotenv Armor. This is mandatory — a plaintext secret never belongs in a tracked file.”
Just SKILL.md in .agents/skills/dotenvx-secrets of kortix-ai/suna.
Open the folder on GitHubat commit 0d853bd
Dotenvx Secrets next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Dotenvx Secrets this skillkortix-ai/suna | 20k | — | ~4.2k | Automated safety check: Notes | Custom licence | |
| Private Secret Scanningjamditis/claude-skills-journalism | 417 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Toolchain Commandslatitude-dev/latitude-llm | 4.7k | — | ~1.4k | Automated safety check: Notes | MIT | |
| Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~818 | Automated safety check: Pass | Apache-2.0 | |
| Leaked Secretsthedaviddias/Front-End-Checklist | 74k | — | ~596 | Automated safety check: Notes | MIT | |
| Secrets Auditbriiirussell/cybersecurity-skills | 413 | — | ~2.6k | Automated safety check: Notes | MIT |
jamditis/claude-skills-journalism
Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports.
latitude-dev/latitude-llm
Installing dependencies, running dev/build/test/lint, filtering packages, single-test runs, git hooks, preparing a clone (.env.development / .env.test), or Docker-backed local services and dev…
mukul975/Anthropic-Cybersecurity-Skills
Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…
thedaviddias/Front-End-Checklist
A skill your agent uses when reviewing client-side JavaScript, HTML source, or git history for exposed credentials, API keys, or tokens.
briiirussell/cybersecurity-skills
Find leaked secrets in source code, Git history, build artifacts, and infrastructure — and audit the secrets-management posture preventing future leaks.
OpenHands/extensions
Interact with GitLab repositories, merge requests, and APIs using the GITLABTOKEN environment variable.
kortix-ai/suna
Code review focused exclusively on over-engineering. An agent skill from kortix-ai/suna.
kortix-ai/suna
Load FIRST for anything that carries the Kortix look or voice: product or mobile UI, copy of any kind, decks, social, images, email, CLI output, anything with the logo, and reviews of these.
kortix-ai/suna
A skill your agent uses for every Kortix test task, behavior change, bug fix, refactor, API route change, CLI change, SDK change, browser journey, test failure, coverage question, local benchmark…
kortix-ai/suna
The pull request loop for this repo: branch → commit → verify in your own box (local tests + local stack) → PR into main → demo video recorded with agent-browser on the local stack → gh --attach →…
kortix-ai/suna
Drive Anthropic's Claude Code CLI (claude -p) as a non-interactive coding sub-agent from inside Codex.
kortix-ai/suna
The project's episodic memory: a timestamped ledger of rules paid for with real outages and near-misses, one entry per incident.
Categories
How this repo manages API secrets and the four local-run environments (local/dev/staging/prod). Dotenvx Secrets is an agent skill from kortix-ai/suna. How this repo manages API secrets and the four local-run environments (local/dev/staging/prod).
Dotenvx Secrets fits situations like: pastes a key/token/secret to store; whenever choosing/switching which environment to run; whenever adding; sharing a secret.
Run `npx skills add kortix-ai/suna --skill dotenvx-secrets -a claude-code`. Or copy the skill folder (.agents/skills/dotenvx-secrets in kortix-ai/suna) into .claude/skills/dotenvx-secrets in your project. Claude Code loads it when a task matches its description.
Run `npx skills add kortix-ai/suna --skill dotenvx-secrets -a codex`. Or copy the skill folder (.agents/skills/dotenvx-secrets in kortix-ai/suna) into .agents/skills/dotenvx-secrets in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kortix-ai/suna --skill dotenvx-secrets -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dotenvx-secrets, .gemini/skills/dotenvx-secrets, .github/skills/dotenvx-secrets and .opencode/skills/dotenvx-secrets in your project.
Going by SKILL.md and its folder, Dotenvx Secrets needs the command-line tools its instructions call (pnpm, aws, python3 and git) and credentials named INTERNAL_SERVICE_KEY, DOTENV_PRIVATE_KEY, API_KEY_SECRET and GATEWAY_INTERNAL_TOKEN. Our summary lists: Python 3; Docker; A credential in DOTENV_PRIVATE_KEY; A credential in INTERNAL_SERVICE_KEY.
SKILL.md names 2 domains. In commands or code: armor.dotenvx.com; the agent is likely to contact it when it follows the instructions. As links in the text: dotenvx.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Dotenvx Secrets has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.
About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Dotenvx Secrets: Private Secret Scanning (jamditis/claude-skills-journalism, 417 stars), Toolchain Commands (latitude-dev/latitude-llm, 4.7k stars), Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Leaked Secrets (thedaviddias/Front-End-Checklist, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
kortix-ai (a GitHub organization) maintains it in kortix-ai/suna, which has 20,263 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 9, 2026.
Source: kortix-ai/suna on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.