Env Secrets Manager
alirezarezvani/claude-skills
Manage environment-variable hygiene and secrets safety across local development and production.
Never read .env files or write secrets to .squad/ committed files
$ npx skills add microsoft/waza --skill secret-handling -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install microsoft/waza secret-handling --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/microsoft/waza.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.copilot/skills/secret-handling .claude/skills/secret-handling && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "secret-handling" agent skill from https://github.com/microsoft/waza/tree/main/.copilot/skills/secret-handling into .claude/skills/secret-handling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secret-handling", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/microsoft/waza/tree/main/.copilot/skills/secret-handlingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add microsoft/waza --skill secret-handling -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install microsoft/waza secret-handling --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/waza.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.copilot/skills/secret-handling .agents/skills/secret-handling && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "secret-handling" agent skill from https://github.com/microsoft/waza/tree/main/.copilot/skills/secret-handling into .agents/skills/secret-handling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secret-handling", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft/waza --skill secret-handling -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install microsoft/waza secret-handling --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/waza.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.copilot/skills/secret-handling .cursor/skills/secret-handling && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "secret-handling" agent skill from https://github.com/microsoft/waza/tree/main/.copilot/skills/secret-handling into .cursor/skills/secret-handling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secret-handling", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/microsoft/waza.git --path .copilot/skills/secret-handling--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add microsoft/waza --skill secret-handling -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install microsoft/waza secret-handling --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/waza.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.copilot/skills/secret-handling .gemini/skills/secret-handling && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "secret-handling" agent skill from https://github.com/microsoft/waza/tree/main/.copilot/skills/secret-handling into .gemini/skills/secret-handling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secret-handling", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install microsoft/waza secret-handlingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add microsoft/waza --skill secret-handling -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/microsoft/waza.git skills-src && mkdir -p .github/skills && cp -r skills-src/.copilot/skills/secret-handling .github/skills/secret-handling && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "secret-handling" agent skill from https://github.com/microsoft/waza/tree/main/.copilot/skills/secret-handling into .github/skills/secret-handling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secret-handling", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add microsoft/waza --skill secret-handling -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install microsoft/waza secret-handling --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/microsoft/waza.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.copilot/skills/secret-handling .opencode/skills/secret-handling && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "secret-handling" agent skill from https://github.com/microsoft/waza/tree/main/.copilot/skills/secret-handling into .opencode/skills/secret-handling/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secret-handling", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
secret-handlingNever read .env files or write secrets to .squad/ committed files
Secret Handling is an agent skill from microsoft/waza, published by the product's own GitHub organization. Never read .env files or write secrets to .squad/ committed files
Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
The repository describes itself as: CLI / Framework for Agent Skills - create, test, measure and improve skill quality and effectiveness. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 774df00. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
OPENAI_API_KEYGITHUB_TOKENDB_PASSWORDAPI_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Secret Handling loads about 1.9k tokens when it runs. Until then it costs about 20 tokens; SKILL.md has 549 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
description: Never read .env files or write secrets to .squad/ committed filesess to the entire repository, including `.env` files containing live credentials. If an agent reads secrets and writes t- `.env` (production secrets)- `.env.local` (local dev secrets)- `.env.production` (production environment)- `.env.development` (development environment)- `.env.staging` (staging environment)- `.env.test` (test environment with real credentials)- Any file matching `.env.*` UNLESS explicitly allowed (see below)**NEVER assume you can "just peek at .env to understand the schema."** Use `.env.example` or ask.Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from microsoft/waza at commit 774df00, republished under its MIT licence (© microsoft). 549 words, ~1,868 tokens.
.claude/skills/secret-handling/SKILL.md (or your agent's skills folder).Spawned agents have read access to the entire repository, including .env files containing live credentials. If an agent reads secrets and writes them to .squad/ files (decisions, logs, history), Scribe auto-commits them to git, exposing them in remote history. This skill codifies absolute prohibitions and safe alternatives.
NEVER read these files:
.env (production secrets).env.local (local dev secrets).env.production (production environment).env.development (development environment).env.staging (staging environment).env.test (test environment with real credentials).env.* UNLESS explicitly allowed (see below)Allowed alternatives:
.env.example (safe — contains placeholder values, no real secrets).env.sample (safe — documentation template).env.template (safe — schema/structure reference)If you need config info:
.env.example — shows structure without exposing secretsREADME.md, docs/, config guidesNEVER assume you can "just peek at .env to understand the schema." Use .env.example or ask.
NEVER write these to .squad/ files:
| Pattern Type | Examples | Regex Pattern (for scanning) |
|---|---|---|
| API Keys | OPENAI_API_KEY=sk-proj-..., GITHUB_TOKEN=ghp_... | `[A-Z_]+(?:KEY |
| Passwords | DB_PASSWORD=super_secret_123, password: "..." | `(?:PASSWORD |
| Connection Strings | postgres://user:pass@host:5432/db, Server=...;Password=... | `(?:postgres |
| JWT Tokens | eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9... | eyJ[A-Za-z0-9_-]+\.eyJ[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+ |
| Private Keys | -----BEGIN PRIVATE KEY-----, -----BEGIN RSA PRIVATE KEY----- | -----BEGIN [A-Z ]+PRIVATE KEY----- |
| AWS Credentials | AKIA..., aws_secret_access_key=... | `AKIA[0-9A-Z]{16} |
| Email Addresses | user@example.com (PII violation per team decision) | [a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,} |
What to write instead:
DATABASE_URL=<set in .env>API key configured (see .env.example)Before committing .squad/ changes, Scribe MUST:
Scan all staged files for secret patterns (use regex table above)
Check for prohibited file names (don't commit .env even if manually staged)
If secrets detected:
git reset HEAD <file>🚨 SECRET DETECTED — commit blocked
File: .squad/decisions/inbox/river-db-config.md
Pattern: DATABASE_URL=postgres://user:password@localhost:5432/prod
This file contains credentials and MUST NOT be committed.
Please remove the secret, replace with placeholder, and try again.If no secrets detected:
Implementation note for Scribe:
git commitSelect-String or git diff --cached to scan staged contentIf you discover a secret in git history:
🚨 CREDENTIAL LEAK DETECTED
A secret was found in git history:
Commit: abc1234
File: .squad/decisions/inbox/agent-config.md
Pattern: API_KEY=sk-proj-...
This requires immediate remediation:
1. Revoke the exposed credential (regenerate API key, rotate password)
2. Remove from git history (git filter-repo or BFG)
3. Force-push the cleaned history
Do NOT proceed with new work until this is resolved.Agent needs to know what environment variables are required:
Agent: "What environment variables does this app need?"
→ Reads `.env.example`:
OPENAI_API_KEY=sk-...
DATABASE_URL=postgres://user:pass@localhost:5432/db
REDIS_URL=redis://localhost:6379
→ Writes to .squad/decisions/inbox/river-env-setup.md:
"App requires three environment variables:
- OPENAI_API_KEY (OpenAI API key, format: sk-...)
- DATABASE_URL (Postgres connection string)
- REDIS_URL (Redis connection string)
See .env.example for full schema."Agent needs to know database schema:
Agent: (reads .env)
DATABASE_URL=postgres://admin:super_secret_pw@prod.example.com:5432/appdb
→ Writes to .squad/decisions/inbox/river-db-schema.md:
"Database connection: postgres://admin:super_secret_pw@prod.example.com:5432/appdb"
🚨 VIOLATION: Live credential written to committed fileCorrect approach:
Agent: (reads .env.example OR asks user)
User: "It's a Postgres database, schema is in migrations/"
→ Writes to .squad/decisions/inbox/river-db-schema.md:
"Database: Postgres (connection configured in .env). Schema defined in db/migrations/."Scribe is about to commit:
# Stage files
git add .squad/
# Scan staged content for secrets
$stagedContent = git diff --cached
$secretPatterns = @(
'[A-Z_]+(?:KEY|TOKEN|SECRET)=[^\s]+',
'(?:PASSWORD|PASS|PWD)[:=]\s*["'']?[^\s"'']+',
'eyJ[A-Za-z0-9_-]+\.eyJ[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+'
)
$detected = $false
foreach ($pattern in $secretPatterns) {
if ($stagedContent -match $pattern) {
$detected = $true
Write-Host "🚨 SECRET DETECTED: $($matches[0])"
break
}
}
if ($detected) {
# Remove from staging, report, exit
git reset HEAD .squad/
Write-Error "Commit blocked — secret detected in staged files"
exit 1
}
# Safe to commit
git commit -F $msgFile.env "just to check the schema" — use .env.example instead.squad/ — Scribe commits ALL .squad/ changes© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .copilot/skills/secret-handling of microsoft/waza.
Open the folder on GitHubat commit 774df00
We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 4 other GitHub owners. This page covers the copy in microsoft/waza, which our catalogue first saw on October 7, 2026.
Secret Handling next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Secret Handling this skillmicrosoft/waza | 1.4k | 4 repos | ~1.9k | Automated safety check: Notes | MIT | |
| Env Secrets Manageralirezarezvani/claude-skills | 28k | — | ~2.7k | Automated safety check: Notes | MIT | |
| Env Secret Detectorjeremylongshore/tons-of-skills-marketplace | 2.8k | — | ~576 | Automated safety check: Pass | MIT | |
| Env Secrets Managerborghei/Claude-Skills | 881 | — | ~1.6k | Automated safety check: Notes | MIT | |
| Openclaw Secret Scanning Maintaineropenclaw/openclaw | 392k | — | ~2.5k | Automated safety check: Pass | MIT | |
| Secret Scanninggithub/awesome-copilot | 40k | 1 repos | ~2.4k | Automated safety check: Pass | MIT |
alirezarezvani/claude-skills
Manage environment-variable hygiene and secrets safety across local development and production.
jeremylongshore/tons-of-skills-marketplace
Detect env secret detector operations. An agent skill from jeremylongshore/tons-of-skills-marketplace.
borghei/Claude-Skills
Environment and secrets management lifecycle: .env scaffolding, validation, leak detection, and rotation across Vault, AWS SSM, 1Password, and Doppler.
openclaw/openclaw
Triage, redact, clean up, and resolve OpenClaw GitHub Secret Scanning alerts in issues or PRs.
github/awesome-copilot
Guide for configuring and managing GitHub secret scanning, push protection, custom patterns, and secret alert remediation.
davila7/claude-code-templates
Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools.
microsoft/waza
Shows a categorized, interactive menu of common Squad operations, such as install, upgrade and team management, and collects arguments before running anything.
microsoft/waza
Shared collaboration rules for a team of squad agents covering worktree awareness, writing decisions to an inbox, cross-agent requests and reviewer lockout.
microsoft/waza
Walks through releasing a new version of the waza azd extension: changelog from commits, semver bump with your confirmation, and a release PR.
microsoft/waza
Dev-first branching model for the Squad project: feature work branches from dev, issue branches follow a naming rule and parallel issues use git worktrees.
microsoft/waza
Evaluates agent skills with a Go CLI that runs YAML-defined benchmarks, compares runs and scores the quality of SKILL.md frontmatter.
microsoft/waza
Reviewer rejection workflow and strict lockout semantics. An agent skill from microsoft/waza.
Never read .env files or write secrets to .squad/ committed files. Secret Handling is an agent skill from microsoft/waza, published by the product's own GitHub organization.
Run `npx skills add microsoft/waza --skill secret-handling -a claude-code`. Or copy the skill folder (.copilot/skills/secret-handling in microsoft/waza) into .claude/skills/secret-handling in your project. Claude Code loads it when a task matches its description.
Run `npx skills add microsoft/waza --skill secret-handling -a codex`. Or copy the skill folder (.copilot/skills/secret-handling in microsoft/waza) into .agents/skills/secret-handling in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/waza --skill secret-handling -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secret-handling, .gemini/skills/secret-handling, .github/skills/secret-handling and .opencode/skills/secret-handling in your project.
Going by SKILL.md and its folder, Secret Handling needs the command-line tools its instructions call (git) and credentials named OPENAI_API_KEY, GITHUB_TOKEN, DB_PASSWORD and API_KEY. Our summary lists: A credential in OPENAI_API_KEY; A credential in GITHUB_TOKEN.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Secret Handling is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Secret Handling: Env Secrets Manager (alirezarezvani/claude-skills, 28k stars), Env Secret Detector (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Env Secrets Manager (borghei/Claude-Skills, 881 stars) and Openclaw Secret Scanning Maintainer (openclaw/openclaw, 392k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
microsoft (a GitHub organization, an official publisher) maintains it in microsoft/waza, which has 1,403 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 6, 2026.
Source: microsoft/waza on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.