“环境变量管理器:扫描、校验、同步 .env 文件,生成安全配置模板”

— description from SKILL.md by laolaoshiren
MITAuto-check: notesDevOps & Cloud

Install Env Manager

skills CLI
$ npx skills add laolaoshiren/claude-code-skills-zh --skill env-manager -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install laolaoshiren/claude-code-skills-zh env-manager --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/laolaoshiren/claude-code-skills-zh.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/env-manager .claude/skills/env-manager && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
env-manager
GitHub stars
880
Token cost
~608 tokens
SKILL.md length
148 words
Files
1
Skills in repo
19
Repo updated
First seen
Licence
MIT

At a glance

  • Works in 4 steps: 扫描项目 → 校验分析 → 生成/修复 → …
  • SKILL.md covers 触发条件, 工作流程, 输出格式 and 安全检查清单, plus 3 more sections
  • Needs JWT_SECRET and OLD_API_KEY

About this skill

Env Manager is a skill in laolaoshiren/claude-code-skills-zh (880 stars). Its SKILL.md is about 608 tokens. Licence: MIT.

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. 扫描项目
  2. 校验分析
  3. 生成/修复
  4. 同步

What it can do on your machine

Read from SKILL.md and the folder at commit 633f21c. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • JWT_SECRET
    • OLD_API_KEY
    • SENDGRID_API_KEY
    • ENCRYPTION_KEY
    • DB_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Env Manager loads about 608 tokens when it runs. Until then it costs about 11 tokens; SKILL.md has 148 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~11
When it runs · the whole SKILL.md, loaded when a task matches
~608

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:3
    description: 环境变量管理器:扫描、校验、同步 .env 文件,生成安全配置模板
  • NoteMentions a .env fileSKILL.md:14
    - 检测所有 `.env*` 文件(.env / .env.local / .env.development / .env.production)
  • NoteMentions a .env fileSKILL.md:24
    - 对比 .env.example 与实际 .env 文件的差异
  • NoteMentions a .env fileSKILL.md:28
    - 生成 `.env.schema.json`(结构化校验规则)
  • NoteMentions a .env fileSKILL.md:70
    2. 在 .env 中添加 SENDGRID_API_KEY
  • NoteMentions a .env fileSKILL.md:76
    - [ ] `.env` 已添加到 `.gitignore`
  • NoteMentions a .env fileSKILL.md:85
    - 不要自动删除或改写真实 `.env`;先展示差异并取得用户确认。
  • NoteMentions a .env fileSKILL.md:92
    - **Create React App**:`.env` 中的变量必须以 `REACT_APP_` 开头才会被注入
  • NoteMentions a .env fileSKILL.md:94
    - **monorepo**:根目录的 `.env` 不会自动被子包读取,需要显式配置
  • NoteMentions a .env fileSKILL.md:100
    | Next.js | NEXT_PUBLIC_ | .env.local | 自动 |

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from laolaoshiren/claude-code-skills-zh at commit 633f21c, republished under its MIT licence (© laolaoshiren). 148 words, ~608 tokens.

Download SKILL.mdSave it as .claude/skills/env-manager/SKILL.md (or your agent's skills folder).
name
env-manager
description
环境变量管理器:扫描、校验、同步 .env 文件,生成安全配置模板

环境变量管理器

触发条件

当用户要求管理环境变量、.env 文件、配置同步、Secrets 检查时激活。

工作流程

1. 扫描项目
  • 检测所有 .env* 文件(.env / .env.local / .env.development / .env.production)
  • 默认只提取变量名、来源文件和是否为空;真实值必须脱敏,不写入报告或终端输出
  • 扫描代码中引用的环境变量(process.env.XXX / os.environ['XXX'] / os.getenv('XXX'))
  • 识别静态扫描中未发现引用的变量(仅作为待人工确认候选)
  • 识别已使用但未定义的变量(缺失配置)
2. 校验分析
  • 检查必填变量是否有默认值
  • 验证 URL 格式、端口号范围、布尔值格式
  • 检测硬编码的敏感信息(API Key / Token / Password)
  • 对比 .env.example 与实际 .env 文件的差异
3. 生成/修复
  • 生成 .env.example 模板(仅包含变量名和说明,不含真实值)
  • 生成 .env.schema.json(结构化校验规则)
  • 检测到硬编码密钥时,建议迁移到环境变量
  • 生成 dotenv 加载配置(针对不同框架)
4. 同步
  • 在 monorepo 中同步共享环境变量
  • 生成 Docker Compose 的 env_file 配置
  • 生成 CI/CD 的 Secrets 配置清单

输出格式

.env.example 示例
bash
# 应用配置
APP_NAME=my-app
APP_ENV=development          # development | staging | production
APP_PORT=3000                # 服务端口 (1-65535)
APP_DEBUG=true               # 调试模式

# 数据库
DB_HOST=localhost
DB_PORT=5432
DB_NAME=mydb
DB_USER=                     # 必填
DB_PASSWORD=                 # 必填,生产环境请使用 Secrets

# 第三方服务
REDIS_URL=                   # 必填,格式:redis://host:port
JWT_SECRET=                  # 必填,至少 32 位随机字符串
校验报告示例
📋 环境变量分析报告
==================
✅ 定义且使用: 12 个
⚠️  定义未使用: 2 个(S3_BUCKET, OLD_API_KEY)
❌ 使用未定义: 1 个(SENDGRID_API_KEY)
🔒 硬编码敏感信息: 1 处(src/auth.js:23)

建议:
1. 人工确认 S3_BUCKET 和 OLD_API_KEY 是否被 CI、部署脚本或动态代码引用,再决定是否删除
2. 在 .env 中添加 SENDGRID_API_KEY
3. 将 src/auth.js:23 的硬编码 token 迁移到环境变量

安全检查清单

  • 扫描和报告只展示变量名及脱敏状态,不回显真实 Secret
  • .env 已添加到 .gitignore
  • .env.example 存在且与代码同步
  • 无硬编码的 API Key / Token / Password
  • 生产环境使用 Secrets 管理(GitHub Secrets / AWS SSM / Vault)
  • JWT_SECRET / ENCRYPTION_KEY 足够随机(32+ 字符)
  • 数据库密码不在日志中输出

修改边界

  • 不要自动删除或改写真实 .env;先展示差异并取得用户确认。
  • “未使用”只代表静态扫描没有发现,仍需检查 CI、容器、部署平台和动态变量访问。
  • 不把生产 Secret 复制到 .env.example、Schema、日志、Issue 或聊天输出中。

常见陷阱

  • Next.js:只有 NEXT_PUBLIC_ 前缀的变量会暴露给客户端,后端专用变量不要加此前缀
  • Docker:构建时的 ARG 和运行时的 ENV 是不同的,不要混淆
  • Create React App:.env 中的变量必须以 REACT_APP_ 开头才会被注入
  • Vite:使用 VITE_ 前缀暴露变量给客户端
  • monorepo:根目录的 .env 不会自动被子包读取,需要显式配置

框架适配

框架客户端前缀配置文件加载方式
Next.jsNEXT_PUBLIC_.env.local自动
ViteVITE_.env自动
CRAREACT_APP_.env自动
NuxtNUXT_PUBLIC_.env自动
Vue CLIVUE_APP_.env自动

© laolaoshiren, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/env-manager of laolaoshiren/claude-code-skills-zh.

Open the folder on GitHubat commit 633f21c

Compare with similar skills

Env Manager next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Env Manager compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Env Manager this skilllaolaoshiren/claude-code-skills-zh880—~608Automated safety check: NotesMIT
Convex Self Hostingwaynesutton/markdown-site627—~1.4kAutomated safety check: PassMIT
Add React Analyticsgotempsh/temps831—~2.7kAutomated safety check: PassApache-2.0
Env Managerbobmatnyc/claude-mpm156—~3.9kAutomated safety check: NotesCustom licence
AWS Blocksaws/agent-toolkit-for-aws2.8k—~1.2kAutomated safety check: NotesApache-2.0
Datadog Appdatadog-labs/agent-skills177—~744Automated safety check: PassMIT

Similar skills

  • Convex Self Hosting

    waynesutton/markdown-site

    Integrate Convex static self hosting into existing apps using the latest upstream instructions from get-convex/self-hosting every time.

    627 GitHub stars~1.4k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed
  • Add React Analytics

    gotempsh/temps

    Add Temps analytics to React applications with comprehensive tracking capabilities including page views, custom events, scroll tracking, engagement monitoring, session recording, and Web Vitals…

    831 GitHub stars~2.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Env Manager

    bobmatnyc/claude-mpm

    Environment variable validation, security scanning, and management for Next.js, Vite, React, and Node.js applications

    156 GitHub stars~3.9k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • AWS Blocks

    aws/agent-toolkit-for-aws

    Official

    Guides building full-stack applications with AWS Blocks — an Infrastructure-from-Code framework.

    2.8k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Datadog App

    datadog-labs/agent-skills

    Guides developers building Datadog Apps with TypeScript, React, the @datadog/apps scaffolder, and @datadog/vite-plugin.

    177 GitHub stars~744 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Frontend Build Timing Audit

    openops-cloud/openops

    Detects and diagnoses chunk-evaluation timing bugs in the Vite/rolldown production build of react-ui (works-in-dev / broken-in-build i18n regressions, missing UI labels, module-scope t()…

    1.1k GitHub stars~2.3k tokensUpdated yesterday
    Frontend & DesignAuto-check passed

More from laolaoshiren/claude-code-skills-zh

All 19 skills in this repo
  • API Tester

    laolaoshiren/claude-code-skills-zh

    依据真实 OpenAPI、路由实现和现有测试生成并验证 API 测试。用于用户要求测试接口、补集成测试、验证 API 契约、生成回归用例或排查接口兼容性时;区分“生成测试”和“执行请求”的授权,不猜测状态码、响应结构或 SLA,不在未确认环境中发送写请求。

    880 GitHub stars~614 tokensUpdated 5 days ago
    Auto-check passed
  • Dep Auditor

    laolaoshiren/claude-code-skills-zh

    审计 Node.js、Python、Go、Rust、JVM、Ruby 项目的依赖漏洞、版本健康度与许可证事实;当用户要求检查 package.json、lockfile、requirements、go.mod、Cargo.toml、pom.xml、Gemfile.lock,或生成不改依赖的中文审计报告时使用

    880 GitHub stars~895 tokensUpdated 5 days ago
    Auto-check passed
  • Eslint Fix

    laolaoshiren/claude-code-skills-zh

    安全诊断并修复 ESLint error、warning 和配置兼容问题。用于用户要求运行 lint、解释 ESLint 报错、限定范围自动修复或迁移 ESLint 配置时;优先使用项目锁定的包管理器与版本,先预检再修改,不自动下载最新版或批量改写无关源码。

    880 GitHub stars~436 tokensUpdated 5 days ago
    Auto-check passed
  • Git Workflow

    laolaoshiren/claude-code-skills-zh

    安全处理 Git 状态检查、提交信息、commit、分支、push、PR 和 rebase。用于用户要求检查改动、生成或创建提交、管理分支、推送、发起 PR 或整理历史时;严格区分每个动作的授权,并保护工作树中已有和无关的修改。

    880 GitHub stars~513 tokensUpdated 5 days ago
    Auto-check passed
  • GitHub Actions Gen

    laolaoshiren/claude-code-skills-zh

    分析真实项目并生成或修订安全、可验证的 GitHub Actions workflow;当用户要求创建 CI、测试矩阵、构建、Release、部署、缓存、Secrets、OIDC、PR 自动化或排查 workflow 配置时使用

    880 GitHub stars~1.1k tokensUpdated 5 days ago
    Auto-check: notes
  • Skill Curator

    laolaoshiren/claude-code-skills-zh

    中文 Skill 收录评估器。用于核验 GitHub 上的 Claude Code、Codex、Agent Skills、Plugin、MCP、CLI 或 Agent 工作流是否值得加入精选列表;检查真实资产、安装方式、活跃度、重复项和安全边界,并生成分类、中文描述与可追溯证据。

    880 GitHub stars~756 tokensUpdated 5 days ago
    Auto-check passed

Works with

Categories

Questions about Env Manager

How do I install Env Manager in Claude Code?

Run `npx skills add laolaoshiren/claude-code-skills-zh --skill env-manager -a claude-code`. Or copy the skill folder (skills/env-manager in laolaoshiren/claude-code-skills-zh) into .claude/skills/env-manager in your project. Claude Code loads it when a task matches its description.

How do I install Env Manager in Codex?

Run `npx skills add laolaoshiren/claude-code-skills-zh --skill env-manager -a codex`. Or copy the skill folder (skills/env-manager in laolaoshiren/claude-code-skills-zh) into .agents/skills/env-manager in your project. Codex loads it when a task matches its description.

Can I use Env Manager in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add laolaoshiren/claude-code-skills-zh --skill env-manager -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/env-manager, .gemini/skills/env-manager, .github/skills/env-manager and .opencode/skills/env-manager in your project.

What does Env Manager need to run?

Going by SKILL.md and its folder, Env Manager needs credentials named JWT_SECRET, OLD_API_KEY, SENDGRID_API_KEY and ENCRYPTION_KEY.

Does Env Manager access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Env Manager safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Env Manager use?

Env Manager is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Env Manager use?

About 608 tokens (SKILL.md is roughly 2.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Env Manager?

Skills that share tags, products or a category with Env Manager: Convex Self Hosting (waynesutton/markdown-site, 627 stars), Add React Analytics (gotempsh/temps, 831 stars), Env Manager (bobmatnyc/claude-mpm, 156 stars) and AWS Blocks (aws/agent-toolkit-for-aws, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Env Manager?

laolaoshiren (a GitHub user) maintains it in laolaoshiren/claude-code-skills-zh, which has 880 GitHub stars. The repository holds 19 skills in this directory. The repository was last updated on October 5, 2026.

Source: laolaoshiren/claude-code-skills-zh on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.