Audit Env Variables
qdhenry/Claude-Command-Suite
Analyze environment variables in JavaScript/TypeScript projects.
How to load secrets and environment variables from 1Password programmatically using the official @1password/sdk (JavaScript/TypeScript).
$ npx skills add MadAppGang/claudish --skill 1password-sdk -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install MadAppGang/claudish 1password-sdk --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/MadAppGang/claudish.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/1password-sdk .claude/skills/1password-sdk && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "1password-sdk" agent skill from https://github.com/MadAppGang/claudish/tree/main/.claude/skills/1password-sdk into .claude/skills/1password-sdk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "1password-sdk", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/MadAppGang/claudish/tree/main/.claude/skills/1password-sdkType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add MadAppGang/claudish --skill 1password-sdk -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install MadAppGang/claudish 1password-sdk --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MadAppGang/claudish.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/1password-sdk .agents/skills/1password-sdk && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "1password-sdk" agent skill from https://github.com/MadAppGang/claudish/tree/main/.claude/skills/1password-sdk into .agents/skills/1password-sdk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "1password-sdk", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add MadAppGang/claudish --skill 1password-sdk -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install MadAppGang/claudish 1password-sdk --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MadAppGang/claudish.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/1password-sdk .cursor/skills/1password-sdk && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "1password-sdk" agent skill from https://github.com/MadAppGang/claudish/tree/main/.claude/skills/1password-sdk into .cursor/skills/1password-sdk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "1password-sdk", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/MadAppGang/claudish.git --path .claude/skills/1password-sdk--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add MadAppGang/claudish --skill 1password-sdk -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install MadAppGang/claudish 1password-sdk --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MadAppGang/claudish.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/1password-sdk .gemini/skills/1password-sdk && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "1password-sdk" agent skill from https://github.com/MadAppGang/claudish/tree/main/.claude/skills/1password-sdk into .gemini/skills/1password-sdk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "1password-sdk", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install MadAppGang/claudish 1password-sdkInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add MadAppGang/claudish --skill 1password-sdk -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/MadAppGang/claudish.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/1password-sdk .github/skills/1password-sdk && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "1password-sdk" agent skill from https://github.com/MadAppGang/claudish/tree/main/.claude/skills/1password-sdk into .github/skills/1password-sdk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "1password-sdk", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add MadAppGang/claudish --skill 1password-sdk -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install MadAppGang/claudish 1password-sdk --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/MadAppGang/claudish.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/1password-sdk .opencode/skills/1password-sdk && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "1password-sdk" agent skill from https://github.com/MadAppGang/claudish/tree/main/.claude/skills/1password-sdk into .opencode/skills/1password-sdk/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "1password-sdk", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
1password-sdkHow to load secrets and environment variables from 1Password programmatically using the official @1password/sdk (JavaScript/TypeScript).
1password SDK is an agent skill from MadAppGang/claudish. How to load secrets and environment variables from 1Password programmatically using the official @1password/sdk (JavaScript/TypeScript). Use this skill whenever code needs to read a 1Password secret, resolve an op:// reference, fetch many secrets at once, discover the fields/sections of a 1Password item (e.g. to import API keys), or read a 1Password Environment — even if the user doesn't name the SDK explicitly. Triggers on: "@1password/sdk", "op://", "OPSERVICEACCOUNTTOKEN", "DesktopAuth", "resolve a secret from…
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/environments.md`, `references/glob-discovery.md` and `references/other-languages.md`).
It works with TypeScript and JavaScript. The repository describes itself as: Claude Code. Any Model. The most powerful AI coding agent now speaks every language.
Read from SKILL.md and the folder at commit 2e4ac24. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
bunFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
OP_SERVICE_ACCOUNT_TOKENOPENAI_API_KEYANTHROPIC_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
1password SDK loads about 1.6k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 207 tokens; SKILL.md has 490 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
Without a licence we can't republish the file, so here is its outline and opening line. It has 490 words (~1,614 tokens).
“The official @1password/sdk reads secrets from 1Password in-process — no op CLI subprocess, no op signin. It authenticates directly (service-account token or desktop biometric) and resolves op://vault/item/field references to their values. Use it whenever an app needs to pull credentials…”
SKILL.md and 4 other files (references) in .claude/skills/1password-sdk of MadAppGang/claudish.
Open the folder on GitHubat commit 2e4ac24
1password SDK next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| 1password SDK this skillMadAppGang/claudish | 1k | — | ~1.6k | Automated safety check: Pass | None | |
| Audit Env Variablesqdhenry/Claude-Command-Suite | 1.3k | — | ~2.8k | Automated safety check: Notes | None | |
| Supercov Securitysupercorp-ai/supercov | 152 | 1 repos | ~236 | Automated safety check: Pass | MIT | |
| Git HooksProrise-cool/Claude-Code-Multi-Agent | 306 | — | ~3.6k | Automated safety check: Notes | None | |
| Azure Appconfiguration TSmicrosoft/skills | 3.1k | 5 repos | ~2.2k | Automated safety check: Pass | MIT | |
| Code Review ChecklistshareAI-lab/learn-claude-code | 78k | 4 repos | ~1.1k | Automated safety check: Pass | MIT |
qdhenry/Claude-Command-Suite
Analyze environment variables in JavaScript/TypeScript projects.
supercorp-ai/supercov
Scans a repository's source for security vulnerabilities with the supercov CLI, pointing to the line of each finding and mapping it to CWE classes.
Prorise-cool/Claude-Code-Multi-Agent
Central authority on git hook implementations, modern best practices, and tooling for .NET/C, JavaScript/TypeScript, Python, and polyglot repositories.
microsoft/skills
Build applications using Azure App Configuration SDK for JavaScript (@azure/app-configuration).
shareAI-lab/learn-claude-code
Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.
trycompai/crm
Install and configure the anti-slop Oxlint plugin in a local TypeScript or JavaScript repository.
MadAppGang/claudish
Write GitHub PR comments in Jack's voice. An agent skill from MadAppGang/claudish.
MadAppGang/claudish
CRITICAL - Guide for using Claudish CLI ONLY through sub-agents to run Claude Code with any AI model (OpenRouter, Gemini, OpenAI, local models).
Works with
How to load secrets and environment variables from 1Password programmatically using the official @1password/sdk (JavaScript/TypeScript). 1password SDK is an agent skill from MadAppGang/claudish. How to load secrets and environment variables from 1Password programmatically using the official @1password/sdk (JavaScript/TypeScript).
1password SDK fits situations like: code needs to read a 1Password secret; resolve an op:// reference; fetch many secrets at once; discover the fields/sections of a 1Password item (e.g.
Run `npx skills add MadAppGang/claudish --skill 1password-sdk -a claude-code`. Or copy the skill folder (.claude/skills/1password-sdk in MadAppGang/claudish) into .claude/skills/1password-sdk in your project. Claude Code loads it when a task matches its description.
Run `npx skills add MadAppGang/claudish --skill 1password-sdk -a codex`. Or copy the skill folder (.claude/skills/1password-sdk in MadAppGang/claudish) into .agents/skills/1password-sdk in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MadAppGang/claudish --skill 1password-sdk -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/1password-sdk, .gemini/skills/1password-sdk, .github/skills/1password-sdk and .opencode/skills/1password-sdk in your project.
Going by SKILL.md and its folder, 1password SDK needs the command-line tools its instructions call (bun) and credentials named OP_SERVICE_ACCOUNT_TOKEN, OPENAI_API_KEY and ANTHROPIC_API_KEY. Our summary lists: Python 3; Node.js; A credential in OP_SERVICE_ACCOUNT_TOKEN; A credential in OPENAI_API_KEY.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
No licence was found for 1password SDK or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.
About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with 1password SDK: Audit Env Variables (qdhenry/Claude-Command-Suite, 1.3k stars), Supercov Security (supercorp-ai/supercov, 152 stars), Git Hooks (Prorise-cool/Claude-Code-Multi-Agent, 306 stars) and Azure Appconfiguration TS (microsoft/skills, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
MadAppGang (a GitHub organization) maintains it in MadAppGang/claudish, which has 1,004 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 7, 2026.
Source: MadAppGang/claudish on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.