Agent skill

1password SDK

by MadAppGang in MadAppGang/claudish

How to load secrets and environment variables from 1Password programmatically using the official @1password/sdk (JavaScript/TypeScript).

No licenceAuto-check passed

Install 1password SDK

skills CLI
$ npx skills add MadAppGang/claudish --skill 1password-sdk -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install MadAppGang/claudish 1password-sdk --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/MadAppGang/claudish.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/1password-sdk .claude/skills/1password-sdk && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
1password-sdk
GitHub stars
1k
Token cost
~1.6k tokens
SKILL.md length
490 words
Files
5 (incl. references)
Skills in repo
3
Repo updated
First seen
Licence
None found

At a glance

How to load secrets and environment variables from 1Password programmatically using the official @1password/sdk (JavaScript/TypeScript).

  • Code needs to read a 1Password secret
  • SKILL.md covers Install, Authenticate — create the…, Resolve secrets — the core… and Read a 1Password Environment…, plus 3 more sections
  • Calls bun; needs OP_SERVICE_ACCOUNT_TOKEN and OPENAI_API_KEY
  • Resolve an op:// reference

What it does

1password SDK is an agent skill from MadAppGang/claudish. How to load secrets and environment variables from 1Password programmatically using the official @1password/sdk (JavaScript/TypeScript). Use this skill whenever code needs to read a 1Password secret, resolve an op:// reference, fetch many secrets at once, discover the fields/sections of a 1Password item (e.g. to import API keys), or read a 1Password Environment — even if the user doesn't name the SDK explicitly. Triggers on: "@1password/sdk", "op://", "OPSERVICEACCOUNTTOKEN", "DesktopAuth", "resolve a secret from…

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/environments.md`, `references/glob-discovery.md` and `references/other-languages.md`).

It works with TypeScript and JavaScript. The repository describes itself as: Claude Code. Any Model. The most powerful AI coding agent now speaks every language.

When your agent uses it

  • Code needs to read a 1Password secret
  • Resolve an op:// reference
  • Fetch many secrets at once
  • Discover the fields/sections of a 1Password item (e.g

Example prompts

  • “t name the SDK explicitly. Triggers on:”
  • “OPSERVICEACCOUNTTOKEN”
  • “DesktopAuth”
  • “/1password-sdk”

Requirements

  • Python 3
  • Node.js
  • A credential in OP_SERVICE_ACCOUNT_TOKEN
  • A credential in OPENAI_API_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 2e4ac24. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • bun

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OP_SERVICE_ACCOUNT_TOKEN
    • OPENAI_API_KEY
    • ANTHROPIC_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

1password SDK loads about 1.6k tokens when it runs, and up to ~4.9k if it reads all its reference files. Until then it costs about 207 tokens; SKILL.md has 490 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~207
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 490 words (~1,614 tokens).

“The official @1password/sdk reads secrets from 1Password in-process — no op CLI subprocess, no op signin. It authenticates directly (service-account token or desktop biometric) and resolves op://vault/item/field references to their values. Use it whenever an app needs to pull credentials…”

— opening of SKILL.md by MadAppGang
name
1password-sdk

Read the full SKILL.md on GitHub

Files

SKILL.md and 4 other files (references) in .claude/skills/1password-sdk of MadAppGang/claudish.

  • SKILL.md
  • references/environments.md
  • references/glob-discovery.md
  • references/other-languages.md
  • references/resolve-secrets.md

Open the folder on GitHubat commit 2e4ac24

Compare with similar skills

1password SDK next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

1password SDK compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
1password SDK this skillMadAppGang/claudish1k—~1.6kAutomated safety check: PassNone
Audit Env Variablesqdhenry/Claude-Command-Suite1.3k—~2.8kAutomated safety check: NotesNone
Supercov Securitysupercorp-ai/supercov1521 repos~236Automated safety check: PassMIT
Git HooksProrise-cool/Claude-Code-Multi-Agent306—~3.6kAutomated safety check: NotesNone
Azure Appconfiguration TSmicrosoft/skills3.1k5 repos~2.2kAutomated safety check: PassMIT
Code Review ChecklistshareAI-lab/learn-claude-code78k4 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Audit Env Variables

    qdhenry/Claude-Command-Suite

    Analyze environment variables in JavaScript/TypeScript projects.

    1.3k GitHub stars~2.8k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check: notes
  • Supercov Security

    supercorp-ai/supercov

    Scans a repository's source for security vulnerabilities with the supercov CLI, pointing to the line of each finding and mapping it to CWE classes.

    152 GitHub starsUsed in 1 repo~236 tokens
    Testing & QAAuto-check passed
  • Git Hooks

    Prorise-cool/Claude-Code-Multi-Agent

    Central authority on git hook implementations, modern best practices, and tooling for .NET/C, JavaScript/TypeScript, Python, and polyglot repositories.

    306 GitHub stars~3.6k tokensUpdated 25 days ago
    DevelopmentAuto-check: notes
  • Official

    Build applications using Azure App Configuration SDK for JavaScript (@azure/app-configuration).

    3.1k GitHub starsUsed in 5 repos~2.2k tokens
    DevOps & CloudAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 4 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Install Anti Slop

    trycompai/crm

    Install and configure the anti-slop Oxlint plugin in a local TypeScript or JavaScript repository.

    11k GitHub starsUsed in 1 repo~881 tokens
    Writing & ContentAuto-check passed

More from MadAppGang/claudish

  • PR Comment

    MadAppGang/claudish

    Write GitHub PR comments in Jack's voice. An agent skill from MadAppGang/claudish.

    1k GitHub stars~3k tokensUpdated 4 days ago
    Auto-check passed
  • Claudish Usage

    MadAppGang/claudish

    CRITICAL - Guide for using Claudish CLI ONLY through sub-agents to run Claude Code with any AI model (OpenRouter, Gemini, OpenAI, local models).

    1k GitHub stars~9k tokensUpdated 4 days ago
    Auto-check passed

Questions about 1password SDK

What does 1password SDK do?

How to load secrets and environment variables from 1Password programmatically using the official @1password/sdk (JavaScript/TypeScript). 1password SDK is an agent skill from MadAppGang/claudish. How to load secrets and environment variables from 1Password programmatically using the official @1password/sdk (JavaScript/TypeScript).

When should I use 1password SDK?

1password SDK fits situations like: code needs to read a 1Password secret; resolve an op:// reference; fetch many secrets at once; discover the fields/sections of a 1Password item (e.g.

How do I install 1password SDK in Claude Code?

Run `npx skills add MadAppGang/claudish --skill 1password-sdk -a claude-code`. Or copy the skill folder (.claude/skills/1password-sdk in MadAppGang/claudish) into .claude/skills/1password-sdk in your project. Claude Code loads it when a task matches its description.

How do I install 1password SDK in Codex?

Run `npx skills add MadAppGang/claudish --skill 1password-sdk -a codex`. Or copy the skill folder (.claude/skills/1password-sdk in MadAppGang/claudish) into .agents/skills/1password-sdk in your project. Codex loads it when a task matches its description.

Can I use 1password SDK in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MadAppGang/claudish --skill 1password-sdk -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/1password-sdk, .gemini/skills/1password-sdk, .github/skills/1password-sdk and .opencode/skills/1password-sdk in your project.

What does 1password SDK need to run?

Going by SKILL.md and its folder, 1password SDK needs the command-line tools its instructions call (bun) and credentials named OP_SERVICE_ACCOUNT_TOKEN, OPENAI_API_KEY and ANTHROPIC_API_KEY. Our summary lists: Python 3; Node.js; A credential in OP_SERVICE_ACCOUNT_TOKEN; A credential in OPENAI_API_KEY.

Does 1password SDK access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is 1password SDK safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does 1password SDK use?

No licence was found for 1password SDK or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does 1password SDK use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.3k tokens, read only when the agent opens those files.

What are the alternatives to 1password SDK?

Skills that share tags, products or a category with 1password SDK: Audit Env Variables (qdhenry/Claude-Command-Suite, 1.3k stars), Supercov Security (supercorp-ai/supercov, 152 stars), Git Hooks (Prorise-cool/Claude-Code-Multi-Agent, 306 stars) and Azure Appconfiguration TS (microsoft/skills, 3.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains 1password SDK?

MadAppGang (a GitHub organization) maintains it in MadAppGang/claudish, which has 1,004 GitHub stars. The repository holds 3 skills in this directory. The repository was last updated on October 7, 2026.

Source: MadAppGang/claudish on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.