Agent skill

Dotenvx Secrets

by kortix-ai in kortix-ai/suna

How this repo manages API secrets and the four local-run environments (local/dev/staging/prod).

Custom licenceAuto-check: notesDevOps & Cloud

Install Dotenvx Secrets

skills CLI
$ npx skills add kortix-ai/suna --skill dotenvx-secrets -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kortix-ai/suna dotenvx-secrets --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kortix-ai/suna.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/dotenvx-secrets .claude/skills/dotenvx-secrets && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dotenvx-secrets
GitHub stars
20k
Token cost
~4.2k tokens
SKILL.md length
1,864 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
Custom licence

At a glance

How this repo manages API secrets and the four local-run environments (local/dev/staging/prod).

  • Pastes a key/token/secret to store
  • SKILL.md covers Armor organization and…, The four environments…, The one rule (non-negotiable) and How it works, plus 7 more sections
  • Calls pnpm, aws and python3; reaches armor.dotenvx.com; needs INTERNAL_SERVICE_KEY and DOTENV_PRIVATE_KEY
  • Whenever choosing/switching which environment to run

What it does

Dotenvx Secrets is an agent skill from kortix-ai/suna. How this repo manages API secrets and the four local-run environments (local/dev/staging/prod). They are dotenvx-ENCRYPTED in git and the keys live in Dotenv Armor. Load this WHENEVER you touch a secret, API key, token, credential, or any apps/api/.env file; whenever the user pastes a key/token/secret to store or use; whenever choosing/switching which environment to run; and whenever adding, reading, rotating, or sharing a secret.

Its SKILL.md is about 4.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Secrets management. It works with Git and pnpm. The repository describes itself as: The open-source AI Operating System.

When your agent uses it

  • Pastes a key/token/secret to store
  • Whenever choosing/switching which environment to run
  • Whenever adding
  • Sharing a secret

Example prompts

  • “/dotenvx-secrets”

Requirements

  • Python 3
  • Docker
  • A credential in DOTENV_PRIVATE_KEY
  • A credential in INTERNAL_SERVICE_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 0d853bd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • pnpm
    • aws
    • python3
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • armor.dotenvx.com

    Also links to:

    • dotenvx.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • INTERNAL_SERVICE_KEY
    • DOTENV_PRIVATE_KEY
    • API_KEY_SECRET
    • GATEWAY_INTERNAL_TOKEN
    • TUNNEL_SIGNING_SECRET
    • DOTENVX_ARMOR_TOKEN
    • DOTENV_PUBLIC_KEY
    • VERCEL_API_TOKEN
    • DOTENV_ARMOR_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dotenvx Secrets loads about 4.2k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 1,864 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~4.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:3
    key, token, credential, or any apps/api/.env* file; whenever the user pastes a key/token/secret to store or use; whenev
  • NoteMentions a .env fileSKILL.md:17
    plan; one armored key == one `.env*` file). Since 2026-08-26 the two PROD keys
  • NoteMentions a .env fileSKILL.md:18
    (`apps/api/.env.prod`, `apps/web/.env.prod`) are granted to the **owner only**.
  • NoteMentions a .env fileSKILL.md:19
    r member (admin or member role) has all `.env`, `.env.dev`, and
  • NoteMentions a .env fileSKILL.md:20
    `.env.staging` keys. Armor refuses a non-owner `dotenvx run -f .env.prod`
  • NoteMentions a .env fileSKILL.md:38
    private key already pulled into a local `.env.keys` — rotate the
  • NoteMentions a .env fileSKILL.md:45
    | private key in `.env.keys`   |
  • NoteMentions a .env fileSKILL.md:47
    v`             | **local**   | `apps/api/.env`         | 100% local stack (local Supabase in Docker, test Stripe) + runs
  • NoteMentions a .env fileSKILL.md:48
    v:dev-env`     | **dev**     | `apps/api/.env.dev`     | the **dev** stack — dev Supabase DB, **test** Stripe, dev keys
  • NoteMentions a .env fileSKILL.md:49
    v:staging-env` | **staging** | `apps/api/.env.staging` | the **staging** stack — staging Supabase DB, test Stripe, stagi

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 1,864 words (~4,244 tokens).

“API secrets are encrypted in git with dotenvx; the decryption keys live off-device in Dotenv Armor. This is mandatory — a plaintext secret never belongs in a tracked file.”

— opening of SKILL.md by kortix-ai, Custom licence
name
dotenvx-secrets

Read the full SKILL.md on GitHub

Files

Just SKILL.md in .agents/skills/dotenvx-secrets of kortix-ai/suna.

Open the folder on GitHubat commit 0d853bd

Compare with similar skills

Dotenvx Secrets next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dotenvx Secrets compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dotenvx Secrets this skillkortix-ai/suna20k—~4.2kAutomated safety check: NotesCustom licence
Private Secret Scanningjamditis/claude-skills-journalism417—~1.8kAutomated safety check: PassMIT
Toolchain Commandslatitude-dev/latitude-llm4.7k—~1.4kAutomated safety check: NotesMIT
Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.0
Leaked Secretsthedaviddias/Front-End-Checklist74k—~596Automated safety check: NotesMIT
Secrets Auditbriiirussell/cybersecurity-skills413—~2.6kAutomated safety check: NotesMIT

Similar skills

  • Private Secret Scanning

    jamditis/claude-skills-journalism

    Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports.

    417 GitHub stars~1.8k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Toolchain Commands

    latitude-dev/latitude-llm

    Installing dependencies, running dev/build/test/lint, filtering packages, single-test runs, git hooks, preparing a clone (.env.development / .env.test), or Docker-backed local services and dev…

    4.7k GitHub stars~1.4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Leaked Secrets

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing client-side JavaScript, HTML source, or git history for exposed credentials, API keys, or tokens.

    74k GitHub stars~596 tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes
  • Secrets Audit

    briiirussell/cybersecurity-skills

    Find leaked secrets in source code, Git history, build artifacts, and infrastructure — and audit the secrets-management posture preventing future leaks.

    413 GitHub stars~2.6k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check: notes
  • GitLab

    OpenHands/extensions

    Interact with GitLab repositories, merge requests, and APIs using the GITLABTOKEN environment variable.

    161 GitHub stars~629 tokensUpdated today
    DevOps & CloudAuto-check passed

More from kortix-ai/suna

All 19 skills in this repo
  • Ponytail Review

    kortix-ai/suna

    Code review focused exclusively on over-engineering. An agent skill from kortix-ai/suna.

    20k GitHub starsUsed in 4 repos~593 tokens
    Auto-check passed
  • Kortix Brand

    kortix-ai/suna

    Load FIRST for anything that carries the Kortix look or voice: product or mobile UI, copy of any kind, decks, social, images, email, CLI output, anything with the logo, and reviews of these.

    20k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • Testing

    kortix-ai/suna

    A skill your agent uses for every Kortix test task, behavior change, bug fix, refactor, API route change, CLI change, SDK change, browser journey, test failure, coverage question, local benchmark…

    20k GitHub stars~3.6k tokensUpdated today
    Auto-check: notes
  • Contributing

    kortix-ai/suna

    The pull request loop for this repo: branch → commit → verify in your own box (local tests + local stack) → PR into main → demo video recorded with agent-browser on the local stack → gh --attach →…

    20k GitHub stars~3k tokensUpdated today
    Auto-check: warnings
  • Claude Code

    kortix-ai/suna

    Drive Anthropic's Claude Code CLI (claude -p) as a non-interactive coding sub-agent from inside Codex.

    20k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Learnings

    kortix-ai/suna

    The project's episodic memory: a timestamped ledger of rules paid for with real outages and near-misses, one entry per incident.

    20k GitHub stars~1.1k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Dotenvx Secrets

What does Dotenvx Secrets do?

How this repo manages API secrets and the four local-run environments (local/dev/staging/prod). Dotenvx Secrets is an agent skill from kortix-ai/suna. How this repo manages API secrets and the four local-run environments (local/dev/staging/prod).

When should I use Dotenvx Secrets?

Dotenvx Secrets fits situations like: pastes a key/token/secret to store; whenever choosing/switching which environment to run; whenever adding; sharing a secret.

How do I install Dotenvx Secrets in Claude Code?

Run `npx skills add kortix-ai/suna --skill dotenvx-secrets -a claude-code`. Or copy the skill folder (.agents/skills/dotenvx-secrets in kortix-ai/suna) into .claude/skills/dotenvx-secrets in your project. Claude Code loads it when a task matches its description.

How do I install Dotenvx Secrets in Codex?

Run `npx skills add kortix-ai/suna --skill dotenvx-secrets -a codex`. Or copy the skill folder (.agents/skills/dotenvx-secrets in kortix-ai/suna) into .agents/skills/dotenvx-secrets in your project. Codex loads it when a task matches its description.

Can I use Dotenvx Secrets in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kortix-ai/suna --skill dotenvx-secrets -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dotenvx-secrets, .gemini/skills/dotenvx-secrets, .github/skills/dotenvx-secrets and .opencode/skills/dotenvx-secrets in your project.

What does Dotenvx Secrets need to run?

Going by SKILL.md and its folder, Dotenvx Secrets needs the command-line tools its instructions call (pnpm, aws, python3 and git) and credentials named INTERNAL_SERVICE_KEY, DOTENV_PRIVATE_KEY, API_KEY_SECRET and GATEWAY_INTERNAL_TOKEN. Our summary lists: Python 3; Docker; A credential in DOTENV_PRIVATE_KEY; A credential in INTERNAL_SERVICE_KEY.

Does Dotenvx Secrets access the network?

SKILL.md names 2 domains. In commands or code: armor.dotenvx.com; the agent is likely to contact it when it follows the instructions. As links in the text: dotenvx.com. This is read from the text; nothing was executed.

Is Dotenvx Secrets safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Dotenvx Secrets use?

Dotenvx Secrets has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Dotenvx Secrets use?

About 4.2k tokens (SKILL.md is roughly 17k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dotenvx Secrets?

Skills that share tags, products or a category with Dotenvx Secrets: Private Secret Scanning (jamditis/claude-skills-journalism, 417 stars), Toolchain Commands (latitude-dev/latitude-llm, 4.7k stars), Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars) and Leaked Secrets (thedaviddias/Front-End-Checklist, 74k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dotenvx Secrets?

kortix-ai (a GitHub organization) maintains it in kortix-ai/suna, which has 20,263 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 9, 2026.

Source: kortix-ai/suna on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.