Agent skill

SDK Implementation Guide

by macalbert in macalbert/envilder

Operational guide for implementing a new Envilder runtime SDK.

MITAuto-check passedProductivity & Automation

Install SDK Implementation Guide

skills CLI
$ npx skills add macalbert/envilder --skill sdk-implementation-guide -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install macalbert/envilder sdk-implementation-guide --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/macalbert/envilder.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/sdk-implementation-guide .claude/skills/sdk-implementation-guide && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sdk-implementation-guide
GitHub stars
138
Token cost
~1.9k tokens
SKILL.md length
597 words
Files
1
Skills in repo
30
Repo updated
First seen
Licence
MIT

At a glance

Operational guide for implementing a new Envilder runtime SDK.

  • Works in 9 steps: Folder Structure → Mandatory API Surface → Provider Contract → …
  • Tasks that involve File organization
  • SKILL.md covers When to Use, Prerequisites, 1. Folder Structure and 2. Mandatory API Surface, plus 7 more sections
  • Reaches envilder.com and vault.azure.net

What it does

SDK Implementation Guide is an agent skill from macalbert/envilder. Operational guide for implementing a new Envilder runtime SDK. Covers folder structure, API surface (Tier 1 + Tier 2), provider contract, naming conventions, sync/async model, internal vs public separation, vanity imports, and testing skeleton. Use when creating Go, Java, PHP, Rust, or any future SDK.

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Productivity & Automation, covering File organization and AI interpretability. It works with Rust, PHP, Java and Amazon Web Services. The repository describes itself as: One secret mapping for local dev, CI/CD, and runtime. Envilder resolves cloud secrets from your own vaults without SaaS middlemen, duplicated config, or .env drift. The licence is MIT.

When your agent uses it

  • Tasks that involve File organization
  • Tasks that involve AI interpretability

Example prompts

  • “/sdk-implementation-guide”

Requirements

  • Python 3
  • Node.js
  • Docker

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Folder Structure
  2. Mandatory API Surface
  3. Provider Contract
  4. Internal vs Public Separation
  5. Naming Conventions
  6. Vanity Imports (Go)
  7. Testing Skeleton
  8. Implementation Order (per SDK)
  9. Checklist Before Submitting PR

What it can do on your machine

Read from SKILL.md and the folder at commit b6a0327. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are html).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • envilder.com
    • vault.azure.net

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

SDK Implementation Guide loads about 1.9k tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 597 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from macalbert/envilder at commit b6a0327, republished under its MIT licence (© macalbert). 597 words, ~1,947 tokens.

Download SKILL.mdSave it as .claude/skills/sdk-implementation-guide/SKILL.md (or your agent's skills folder).
name
sdk-implementation-guide
description
Operational guide for implementing a new Envilder runtime SDK. Covers folder structure, API surface (Tier 1 + Tier 2), provider contract, naming conventions, sync/async model, internal vs public separation, vanity imports, and testing skeleton. Use when creating Go, Java, PHP, Rust, or any future SDK.

SDK Implementation Guide

Step-by-step guide for building a new Envilder runtime SDK. Complements ADR-0003 (architecture pattern) and ADR-0005 (integration tiers). For website wiring and publishing, see the sdk-release-checklist skill.

When to Use

  • Implementing a new runtime SDK (Go, Java, PHP, Rust, etc.)
  • Reviewing an SDK PR for pattern compliance
  • Onboarding a contributor to SDK development

Prerequisites

Before starting, read:

1. Folder Structure

txt
src/sdks/{runtime}/
├── domain/
│   ├── ISecretProvider          ← Port interface/protocol
│   ├── MapFileConfig            ← Config parsed from $config
│   ├── EnvilderOptions          ← Runtime overrides
│   ├── ParsedMapFile            ← Config + variable mappings
│   └── SecretProviderType       ← Enum (aws, azure)
├── application/
│   ├── Envilder                 ← Public facade (Tier 1 + Tier 2)
│   ├── EnvilderClient           ← Core resolver
│   ├── MapFileParser            ← JSON parsing logic
│   └── SecretValidation         ← Opt-in validate function
├── infrastructure/
│   ├── SecretProviderFactory    ← Internal, not exported
│   ├── aws/
│   │   └── AwsSsmSecretProvider
│   └── azure/
│       └── AzureKeyVaultSecretProvider
└── integrations/                ← Tier 3 (future, community-driven)
    └── {framework}/

Tests mirror the structure under tests/sdks/{runtime}/.

Note: This is the logical structure. Each runtime adapts to its own conventions (e.g., Node.js uses src/ subfolder, Python uses package name as root directory).

2. Mandatory API Surface

Tier 1: Static Facade (one-liner)
txt
Envilder.load("map.json")              → injects into process env
Envilder.resolveFile("map.json")       → returns resolved key-value pairs
Tier 2: Fluent Builder
txt
Envilder.fromMapFile("map.json")
  .withProvider("azure")
  .withVaultUrl("https://vault.azure.net")
  .withProfile("my-profile")           // AWS only
  .inject()                            // injects into env
  // OR
  .resolve()                           // returns key-value pairs
Environment Routing (both tiers)
txt
Envilder.load("production", {
  "production": "prod-map.json",
  "staging": "stg-map.json"
})

3. Provider Contract

AspectDecision
Missing secretsReturn null/None/nil (Option<T> in Rust) or omit from result collection: never throw
ValidationOpt-in validateSecrets() post-resolution
Cross-provider validationprofile + Azure → error; vaultUrl + AWS → error
Options override configRuntime EnvilderOptions > $config from map file
Pull-onlySDKs do not support push mode
Sync vs Async per Runtime
RuntimeModelRationale
.NETBoth (sync + async methods)IConfigurationBuilder needs sync
PythonSync onlyboto3 is natively synchronous
Node.jsAsync onlyAWS SDK v3 is async, natural fit
GoSync (with context.Context and goroutines for batch)Idiomatic Go
Java/KotlinBoth (sync + async/CompletableFuture)Spring uses both patterns
PHPSync onlyPHP is single-threaded by default
RustAsync (tokio)AWS SDK for Rust is async
Batch vs Individual
RuntimeStrategyRationale
Node.jsBatch (GetParameters, max 10)Avoids waterfall awaits
.NETIndividual (GetParameter)Simpler error handling per secret
PythonIndividual (get_parameter)Matches boto3 API
GoBatch preferredReduce round trips
JavaBatch preferredAWS SDK supports batch
PHPIndividualSimpler for first iteration
RustBatch preferredAsync batch is natural

4. Internal vs Public Separation

The SecretProviderFactory is always internal (not part of public API):

RuntimeMechanism
.NETinternal keyword + InternalsVisibleTo for tests
Python_ prefix (_SecretProviderFactory) + __all__ whitelist
Node.jsNot re-exported from barrel index.ts
GoUnexported (secretProviderFactory, lowercase)
Java/KotlinPackage-private or internal (Kotlin)
PHPPrefixed _ or #[Internal] attribute / @internal docblock
Rustpub(crate) visibility

5. Naming Conventions

Show full SKILL.md (254 more words)Show less
Package/Module Names
RuntimePackage nameImport
.NETEnvilder (NuGet)using Envilder;
Pythonenvilder (PyPI)from envilder import Envilder
Node.js@envilder/sdk (npm)import { Envilder } from '@envilder/sdk'
Goenvilder.com/go (vanity)import "envilder.com/go"
Java/Kotlincom.envilder:envilder (Maven)import com.envilder.Envilder;
PHPenvilder/envilder (Packagist)use Envilder\Envilder;
Rustenvilder (crates.io)use envilder::Envilder;
Class/Struct Naming
  • Facade class is always Envilder (consistent cross-SDK brand)
  • Client class is always EnvilderClient
  • Provider interface: ISecretProvider (or language equivalent: Protocol, trait, interface)

6. Vanity Imports (Go)

Go module path is envilder.com/go. This requires a vanity import HTML at https://envilder.com/go?go-get=1:

html
<meta name="go-import" content="envilder.com/go git https://github.com/macalbert/envilder">
<meta name="go-source" content="envilder.com/go https://github.com/macalbert/envilder https://github.com/macalbert/envilder/tree/main/src/sdks/go{/dir} https://github.com/macalbert/envilder/tree/main/src/sdks/go{/dir}/{file}#L{line}">

Serve from the Envilder website (src/website/public/go/index.html).

7. Testing Skeleton

Every SDK must have:

  • Unit tests for MapFileParser
  • Unit tests for EnvilderClient (mock ISecretProvider)
  • Unit tests for Envilder facade (mock client/provider)
  • Unit tests for SecretValidation
  • Unit tests for cross-provider validation
  • Acceptance tests with LocalStack (AWS SSM)
  • Acceptance tests with Lowkey Vault (Azure Key Vault)

Follow sdk-acceptance-testing skill for container wrapper patterns.

8. Implementation Order (per SDK)

  1. Domain types (MapFileConfig, EnvilderOptions, SecretProviderType, ISecretProvider)
  2. MapFileParser + tests
  3. EnvilderClient + tests
  4. AwsSsmSecretProvider + acceptance tests
  5. AzureKeyVaultSecretProvider + acceptance tests
  6. Envilder facade (Tier 1 + Tier 2) + tests
  7. SecretValidation + tests
  8. Cross-provider validation + tests
  9. README, changelog, website wiring (→ sdk-release-checklist skill)

9. Checklist Before Submitting PR

  • All unit tests pass
  • All acceptance tests pass (Docker required)
  • SecretProviderFactory is not publicly exported
  • Tier 1 (load) and Tier 2 (fromMapFile().inject()) work end-to-end
  • Missing secrets silently omitted (no exceptions from provider)
  • validateSecrets() throws on empty/missing values
  • Cross-provider errors: profile+Azure→error, vaultUrl+AWS→error
  • Options override $config values
  • Environment routing works
  • Follows language-idiomatic conventions (naming, async model, visibility)

© macalbert, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/sdk-implementation-guide of macalbert/envilder.

Open the folder on GitHubat commit b6a0327

Compare with similar skills

SDK Implementation Guide next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

SDK Implementation Guide compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
SDK Implementation Guide this skillmacalbert/envilder138—~1.9kAutomated safety check: PassMIT
Dt Obs ServicesDynatrace/dynatrace-for-ai161—~3.3kAutomated safety check: PassApache-2.0
Dbgtheodo-group/debug-that158—~1.9kAutomated safety check: PassMIT
Writing Dockerfilesancoleman/ai-design-components526—~3.2kAutomated safety check: NotesMIT
Rds Sqlserveraws/agent-toolkit-for-aws2.8k—~6.3kAutomated safety check: PassApache-2.0
Check Toolsoaustegard/claude-skills150—~641Automated safety check: PassMIT

Similar skills

  • Dt Obs Services

    Dynatrace/dynatrace-for-ai

    Service performance monitoring with RED metrics (Rate, Errors, Duration) and runtime-specific telemetry for Java, .NET, Node.js, Python, PHP, and Go.

    161 GitHub stars~3.3k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • Dbg

    theodo-group/debug-that

    Debug applications using the dbg CLI debugger. An agent skill from theodo-group/debug-that.

    158 GitHub stars~1.9k tokensUpdated 4 mo ago
    DevelopmentAuto-check passed
  • Writing Dockerfiles

    ancoleman/ai-design-components

    Writing optimized, secure, multi-stage Dockerfiles with language-specific patterns (Python, Node.js, Go, Rust), BuildKit features, and distroless images.

    526 GitHub stars~3.2k tokensUpdated 10 mo ago
    DevOps & CloudAuto-check: notes
  • Rds Sqlserver

    aws/agent-toolkit-for-aws

    Official

    Provides connectivity, authentication, and troubleshooting guidance for Amazon RDS for SQL Server.

    2.8k GitHub stars~6.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • Check Tools

    oaustegard/claude-skills

    Validates development tool installations across Python, Node.js, Java, Go, Rust, C/C++, Git, and system utilities.

    150 GitHub stars~641 tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Validation

    josstei/maestro-orchestrate

    Cross-cutting validation methodology for verifying phase outputs and project integrity

    465 GitHub stars~2.3k tokensUpdated today
    Testing & QAAuto-check passed

More from macalbert/envilder

All 30 skills in this repo
  • Code Review Perspectives

    macalbert/envilder

    Five independent analysis perspectives for code review: correctness, architecture, security, conventions, and complexity.

    138 GitHub stars~1k tokensUpdated 2 days ago
    Auto-check passed
  • Index of Architecture Decision Records (ADRs) for cross-cutting technical decisions.

    138 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed
  • Common Git

    macalbert/envilder

    Git commit messages, PR workflow, and branching strategy using Conventional Commits and Semantic Versioning.

    138 GitHub stars~991 tokensUpdated 2 days ago
    Auto-check passed
  • Common Testing Conventions

    macalbert/envilder

    Mandatory testing conventions including the narrow diagnostic exception for testing test-only code, AAA pattern, test naming, and assertions across all stacks (.NET, TypeScript, Python).

    138 GitHub stars~1.9k tokensUpdated 2 days ago
    Auto-check passed
  • Doc Maintenance

    macalbert/envilder

    Workflow for maintaining changelogs, READMEs, and documentation files.

    138 GitHub stars~904 tokensUpdated 2 days ago
    Auto-check passed
  • Doc Sync

    macalbert/envilder

    Audit and synchronize documentation across website, READMEs, and docs/.

    138 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check passed

Questions about SDK Implementation Guide

What does SDK Implementation Guide do?

Operational guide for implementing a new Envilder runtime SDK. SDK Implementation Guide is an agent skill from macalbert/envilder. Operational guide for implementing a new Envilder runtime SDK.

When should I use SDK Implementation Guide?

SDK Implementation Guide fits situations like: tasks that involve File organization; tasks that involve AI interpretability.

How do I install SDK Implementation Guide in Claude Code?

Run `npx skills add macalbert/envilder --skill sdk-implementation-guide -a claude-code`. Or copy the skill folder (.github/skills/sdk-implementation-guide in macalbert/envilder) into .claude/skills/sdk-implementation-guide in your project. Claude Code loads it when a task matches its description.

How do I install SDK Implementation Guide in Codex?

Run `npx skills add macalbert/envilder --skill sdk-implementation-guide -a codex`. Or copy the skill folder (.github/skills/sdk-implementation-guide in macalbert/envilder) into .agents/skills/sdk-implementation-guide in your project. Codex loads it when a task matches its description.

Can I use SDK Implementation Guide in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add macalbert/envilder --skill sdk-implementation-guide -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sdk-implementation-guide, .gemini/skills/sdk-implementation-guide, .github/skills/sdk-implementation-guide and .opencode/skills/sdk-implementation-guide in your project.

What does SDK Implementation Guide need to run?

SKILL.md names no scripts, command-line tools or credentials: SDK Implementation Guide is instructions for the agent only. Our summary lists: Python 3; Node.js; Docker.

Does SDK Implementation Guide access the network?

SKILL.md names 2 domains. In commands or code: envilder.com and vault.azure.net; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is SDK Implementation Guide safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does SDK Implementation Guide use?

SDK Implementation Guide is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does SDK Implementation Guide use?

About 1.9k tokens (SKILL.md is roughly 7.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to SDK Implementation Guide?

Skills that share tags, products or a category with SDK Implementation Guide: Dt Obs Services (Dynatrace/dynatrace-for-ai, 161 stars), Dbg (theodo-group/debug-that, 158 stars), Writing Dockerfiles (ancoleman/ai-design-components, 526 stars) and Rds Sqlserver (aws/agent-toolkit-for-aws, 2.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains SDK Implementation Guide?

macalbert (a GitHub user) maintains it in macalbert/envilder, which has 138 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on October 5, 2026.

Source: macalbert/envilder on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.