OPS on-demand: This skill should be used when the user asks to "doppler github secrets", "secret…

MITAuto-check: notes

Install Ops Secret Sync

skills CLI
$ npx skills add Lifecycle-Innovations-Limited/claude-ops --skill ops-secret-sync -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Lifecycle-Innovations-Limited/claude-ops ops-secret-sync --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Lifecycle-Innovations-Limited/claude-ops.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude-ops/skills/ops-secret-sync .claude/skills/ops-secret-sync && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ops-secret-sync
GitHub stars
542
Token cost
~1.8k tokens
SKILL.md length
541 words
Files
1
Skills in repo
67
Repo updated
First seen
Licence
MIT

At a glance

OPS on-demand: This skill should be used when the user asks to "doppler github secrets", "secret…

  • Works in 6 steps: Resolve arguments → Fetch secret inventories → Drift detection → …
  • Asks to doppler github secrets
  • SKILL.md covers CLI/API Reference, Phase 1 — Resolve arguments, Phase 2 — Fetch secret… and Phase 3 — Drift detection, plus 6 more sections
  • Calls gh and jq; needs INNGEST_SIGNING_KEY and CEREBRAS_API_KEY

What it does

Ops Secret Sync is an agent skill from Lifecycle-Innovations-Limited/claude-ops. OPS on-demand: This skill should be used when the user asks to "doppler github secrets", "secret…

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with GitHub. The repository describes itself as: Business operating system for Claude Code — 57 skills, 21 agents, smart daemon. Unified inbox (WhatsApp/Email/Slack/Telegram), autonomous PR merge, full-AWS monitoring, revenue… The licence is MIT.

When your agent uses it

  • Asks to doppler github secrets

Example prompts

  • “doppler github secrets”
  • “/ops-secret-sync”

Requirements

  • A credential in INNGEST_SIGNING_KEY
  • A credential in SOME_KEY
  • Pre-approved tools (allowed-tools): Bash, AskUserQuestion

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Resolve arguments
  2. Fetch secret inventories
  3. Drift detection
  4. Confirm before syncing (REQUIRED — never skip)
  5. Sync confirmed secrets
  6. Summary

What it can do on your machine

Read from SKILL.md and the folder at commit ee9c784. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • AskUserQuestion

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use gh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • INNGEST_SIGNING_KEY
    • CEREBRAS_API_KEY
    • OPENROUTER_API_KEY
    • SOME_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ops Secret Sync loads about 1.8k tokens when it runs. Until then it costs about 28 tokens; SKILL.md has 541 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~28
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, AskUserQuestion

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Lifecycle-Innovations-Limited/claude-ops at commit ee9c784, republished under its MIT licence (© Lifecycle-Innovations-Limited). 541 words, ~1,840 tokens.

Download SKILL.mdSave it as .claude/skills/ops-secret-sync/SKILL.md (or your agent's skills folder).
name
ops-secret-sync
description
OPS on-demand: This skill should be used when the user asks to "doppler github secrets", "secret…
allowed-tools
Bash, AskUserQuestion
argument-hint
[--repo <owner/repo>] [--project <doppler-proj>] [--config <doppler-env>] [--dry-run]
effort
medium
maxTurns
20

OPS ► SECRET-SYNC

Load ops-rules before acting. Public repo (no personal data). Outbound: one draft → one approval → one send. If AskUserQuestion / Workflow are missing, follow Rule 10 in ops-rules (Hermes: numbered options / two-turn Telegram card; delegate_task).

Detect GitHub secrets that are stale relative to Doppler. Confirm before syncing.

CLI/API Reference

CommandPurpose
gh secret list --repo <owner/repo> --json name,updatedAtList GH repo secrets with timestamps
doppler secrets --project <proj> --config <env> --jsonList Doppler secrets with metadata
doppler secrets get <NAME> --project <proj> --config <env> --plainFetch raw value for sync
gh secret set <NAME> --repo <owner/repo>Write secret to GH (reads stdin)

Phase 1 — Resolve arguments

Parse $ARGUMENTS:

  • --repo <owner/repo> → target GitHub repo (required unless registry provides default)
  • --project <proj> → Doppler project name (required)
  • --config <env> → Doppler config/environment, e.g. prd, stg (default: prd)
  • --dry-run → report drift only, never write

If --repo is missing, load ${CLAUDE_PLUGIN_DATA_DIR:-$HOME/.claude/plugins/data/ops-ops-marketplace}/registry.json and let the user pick via AskUserQuestion (max 4 at a time).

If --project is missing, run:

bash
doppler projects --json 2>/dev/null | jq -r '.[].slug'

and let the user pick via AskUserQuestion (max 4 at a time).


Phase 2 — Fetch secret inventories

Run in parallel (background both, then collect):

bash
# GH secrets (names + last-updated timestamps, ISO-8601)
gh secret list --repo <owner/repo> --json name,updatedAt 2>/dev/null
bash
# Doppler secrets (names + metadata including updated_at)
doppler secrets --project <proj> --config <env> --json 2>/dev/null

Parse outputs:

GH format (array):

json
[{"name": "INNGEST_SIGNING_KEY", "updatedAt": "2026-04-23T09:12:00Z"}, ...]

Doppler format (object keyed by name):

json
{
  "INNGEST_SIGNING_KEY": {"computed": "...", "note": "", "rawValue": "...", "updatedAt": "2026-04-23T10:00:00Z"},
  ...
}

Note: Doppler's --json flag returns computed values inline. Use doppler secrets get <NAME> --plain only at sync time to avoid holding all values in memory.


Phase 3 — Drift detection

For each secret in Doppler:

  1. Check if a GH secret with the same name exists.
  2. If yes: compute delta = doppler_updated_at - gh_updated_at (seconds).
  3. If delta > 86400 (24 hours): mark as DRIFTED.
  4. If GH secret does NOT exist: mark as GH_MISSING (flag but do not auto-create — requires explicit user confirm).

Build drift report:

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
 OPS ► SECRET-SYNC — <repo> / <proj>/<config>
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

 Doppler secrets : <N>
 GH repo secrets : <M>
 Matched         : <K>
 DRIFTED (>24h)  : <D>
 GH missing      : <G>

 DRIFTED SECRETS
   <NAME>  Doppler: <date>  GH: <date>  delta: <Nd>
   ...

 GH MISSING (in Doppler but absent from GH)
   <NAME>
   ...

 IN SYNC (no action needed)
   <NAME>  last-synced: <date>
   ...
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

If --dry-run is set or no drift found: stop here and display report.


Phase 4 — Confirm before syncing (REQUIRED — never skip)

Rule 5 compliance: every secret write requires per-action confirmation.

If drift was found, ask:

AskUserQuestion({
  title: "Sync stale GH secrets from Doppler?",
  question: "Found <D> drifted + <G> missing secrets for <repo>.\n\nSync all, pick specific ones, or skip?",
  options: [
    { value: "all",    label: "Sync all drifted + missing" },
    { value: "pick",   label: "Pick which secrets to sync" },
    { value: "drifted", label: "Sync drifted only (skip missing)" },
    { value: "skip",   label: "Skip — report only" }
  ]
})

On "Pick": present drifted secrets 4-at-a-time via AskUserQuestion checkboxes. Collect user selections. Proceed only with confirmed names.

On "Skip": stop. Print report path.


Show full SKILL.md (202 more words)Show less

Phase 5 — Sync confirmed secrets

For each confirmed secret name:

bash
doppler secrets get <NAME> --project <proj> --config <env> --plain 2>/dev/null \
  | gh secret set <NAME> --repo <owner/repo>

After each write, verify:

bash
gh secret list --repo <owner/repo> --json name,updatedAt \
  | jq -r '.[] | select(.name == "<NAME>") | .updatedAt'

Confirm the updatedAt advanced. If it did not advance: report failure for that secret and continue with the rest.

Print per-secret outcome:

  synced : INNGEST_SIGNING_KEY  (Doppler 2026-04-23 → GH updated)
  FAILED : SOME_KEY             (gh secret set exited non-zero)

Phase 6 — Summary

━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
 SYNC COMPLETE — <repo>
 Synced  : <S> secrets
 Failed  : <F> secrets
 Skipped : <K> secrets
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━

If failures > 0: suggest doppler run --project <proj> --config <env> -- gh secret set <NAME> --repo <repo> as a manual fallback.


Example: recurring drift pattern

This skill exists because of a common drift pattern:

ProjectSecretSituation
<your-api>INNGEST_SIGNING_KEYRotated in Doppler — GH secret was 24 days stale, CI failures started after the grace period
<your-service>CEREBRAS_API_KEYAdded to Doppler, never propagated to GH secrets — CI gate failed
<your-service>OPENROUTER_API_KEYSame pattern — GH missing, Doppler current

Running /ops:secret-sync --repo <your-org>/<your-api> --project <your-api> --config prd would have surfaced INNGEST_SIGNING_KEY as DRIFTED before CI failed.


Safety rules

  • Never read or print raw secret values in the summary or logs.
  • Never sync without user confirmation (Rule 5).
  • Doppler values flow directly from doppler secrets get --plain into gh secret set via a pipe — they are never stored in shell variables, temp files, or command substitution.
  • --dry-run always safe: no writes, report only.

Mobile / SSH (Rule 7)

When $SSH_CONNECTION / $OPS_MOBILE=1 / $COLUMNS < 80: skip the banner, emit compact lines:

repo: your-org/example-project-api  project: example-project-api/prd
drifted: 2  missing: 1
INNGEST_SIGNING_KEY  doppler: 2026-04-23  gh: 2026-03-30  (24d stale)
CEREBRAS_API_KEY     gh: MISSING

© Lifecycle-Innovations-Limited, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in claude-ops/skills/ops-secret-sync of Lifecycle-Innovations-Limited/claude-ops.

Open the folder on GitHubat commit ee9c784

Compare with similar skills

Ops Secret Sync next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ops Secret Sync compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ops Secret Sync this skillLifecycle-Innovations-Limited/claude-ops542—~1.8kAutomated safety check: NotesMIT
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Greplooponyx-dot-app/onyx32k4 repos~3.3kAutomated safety check: PassMIT
GitHub Deep Researchbytedance/deer-flow84k4 repos~1.3kAutomated safety check: PassMIT
Diagnosing Superpowers Sessionsobra/superpowers297k3 repos~1.7kAutomated safety check: PassMIT
Update V8 Versionopeninterpreter/openinterpreter69k2 repos~845Automated safety check: PassApache-2.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed
  • GitHub Deep Research

    bytedance/deer-flow

    Researches a GitHub repository over four rounds using the GitHub API and web search, then writes a structured markdown report with timeline, metrics and Mermaid diagrams.

    84k GitHub starsUsed in 4 repos~1.3k tokens
    Research & ScienceAuto-check passed
  • Investigates a session where Superpowers went wrong, reads the transcripts on disk and produces an evidence-cited report, optionally prepared as a bug report for the maintainers.

    297k GitHub starsUsed in 3 repos~1.7k tokens
    Agent WorkflowsAuto-check passed
  • Update V8 Version

    openinterpreter/openinterpreter

    Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.

    69k GitHub starsUsed in 2 repos~845 tokens
    DevOps & CloudAuto-check passed
  • Last30days

    mvanhorn/last30days-skill

    Research what people actually say about any topic in the last 30 days.

    64k GitHub stars~7.9k tokensUpdated yesterday
    Research & ScienceAuto-check: notes

More from Lifecycle-Innovations-Limited/claude-ops

All 67 skills in this repo
  • Ops Dash

    Lifecycle-Innovations-Limited/claude-ops

    OPS on-demand: This skill should be used when the user asks to "ops dashboard", "pixel HQ", or…

    542 GitHub stars~4.7k tokensUpdated yesterday
    Auto-check: notes
  • Ops Gtm

    Lifecycle-Innovations-Limited/claude-ops

    OPS on-demand: This skill should be used when the user asks to "go to market", "GTM plan", or…

    542 GitHub stars~3.7k tokensUpdated yesterday
    Auto-check: notes
  • Ops Marketing

    Lifecycle-Innovations-Limited/claude-ops

    OPS on-demand: This skill should be used when the user asks to "klaviyo", "ads spend", or…

    542 GitHub stars~3.5k tokensUpdated yesterday
    Auto-check: notes
  • Ops Socials

    Lifecycle-Innovations-Limited/claude-ops

    OPS on-demand: This skill should be used when the user asks to "tweet", "post to linkedin", or…

    542 GitHub stars~3.6k tokensUpdated yesterday
    Auto-check: notes
  • Ops Yolo

    Lifecycle-Innovations-Limited/claude-ops

    OPS on-demand: This skill should be used when the user asks to "yolo mode", "run the business today"…

    542 GitHub stars~4k tokensUpdated yesterday
    Auto-check: notes
  • Ops Monitor

    Lifecycle-Innovations-Limited/claude-ops

    OPS on-demand: This skill should be used when the user asks to "datadog", "APM alerts", or…

    542 GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check: notes

Works with

Questions about Ops Secret Sync

What does Ops Secret Sync do?

OPS on-demand: This skill should be used when the user asks to "doppler github secrets", "secret…. Ops Secret Sync is an agent skill from Lifecycle-Innovations-Limited/claude-ops.

When should I use Ops Secret Sync?

Ops Secret Sync fits situations like: asks to doppler github secrets.

How do I install Ops Secret Sync in Claude Code?

Run `npx skills add Lifecycle-Innovations-Limited/claude-ops --skill ops-secret-sync -a claude-code`. Or copy the skill folder (claude-ops/skills/ops-secret-sync in Lifecycle-Innovations-Limited/claude-ops) into .claude/skills/ops-secret-sync in your project. Claude Code loads it when a task matches its description.

How do I install Ops Secret Sync in Codex?

Run `npx skills add Lifecycle-Innovations-Limited/claude-ops --skill ops-secret-sync -a codex`. Or copy the skill folder (claude-ops/skills/ops-secret-sync in Lifecycle-Innovations-Limited/claude-ops) into .agents/skills/ops-secret-sync in your project. Codex loads it when a task matches its description.

Can I use Ops Secret Sync in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Lifecycle-Innovations-Limited/claude-ops --skill ops-secret-sync -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ops-secret-sync, .gemini/skills/ops-secret-sync, .github/skills/ops-secret-sync and .opencode/skills/ops-secret-sync in your project.

What does Ops Secret Sync need to run?

Going by SKILL.md and its folder, Ops Secret Sync needs the command-line tools its instructions call (gh and jq) and credentials named INNGEST_SIGNING_KEY, CEREBRAS_API_KEY, OPENROUTER_API_KEY and SOME_KEY. Our summary lists: A credential in INNGEST_SIGNING_KEY; A credential in SOME_KEY. Its frontmatter pre-approves these tools: Bash, AskUserQuestion.

Does Ops Secret Sync access the network?

SKILL.md contains no URLs. Its commands use gh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Ops Secret Sync safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Ops Secret Sync use?

Ops Secret Sync is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ops Secret Sync use?

About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ops Secret Sync?

Skills that share tags, products or a category with Ops Secret Sync: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Greploop (onyx-dot-app/onyx, 32k stars), GitHub Deep Research (bytedance/deer-flow, 84k stars) and Diagnosing Superpowers Sessions (obra/superpowers, 297k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ops Secret Sync?

Lifecycle-Innovations-Limited (a GitHub organization) maintains it in Lifecycle-Innovations-Limited/claude-ops, which has 542 GitHub stars. The repository holds 67 skills in this directory. The repository was last updated on October 10, 2026.

Source: Lifecycle-Innovations-Limited/claude-ops on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.