Official agent skill

Secret Handling

by microsoft in microsoft/waza

Never read .env files or write secrets to .squad/ committed files

OfficialMITAuto-check: notes

Install Secret Handling

skills CLI
$ npx skills add microsoft/waza --skill secret-handling -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/waza secret-handling --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/waza.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.copilot/skills/secret-handling .claude/skills/secret-handling && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secret-handling
GitHub stars
1.4k
Used in
4 other repos
Token cost
~1.9k tokens
SKILL.md length
549 words
Files
1
Skills in repo
16
Repo updated
First seen
Licence
MIT

At a glance

Never read .env files or write secrets to .squad/ committed files

  • Works in 3 steps: Ask the user directly — "What's the… → Read .env.example — shows structure… → Read documentation — check README.md,…
  • SKILL.md covers Context, Patterns, Examples and Anti-Patterns
  • Calls git; needs OPENAI_API_KEY and GITHUB_TOKEN

What it does

Secret Handling is an agent skill from microsoft/waza, published by the product's own GitHub organization. Never read .env files or write secrets to .squad/ committed files

Its SKILL.md is about 1.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

The repository describes itself as: CLI / Framework for Agent Skills - create, test, measure and improve skill quality and effectiveness. The licence is MIT.

Example prompts

  • “/secret-handling”

Requirements

  • A credential in OPENAI_API_KEY
  • A credential in GITHUB_TOKEN

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Ask the user directly — "What's the database connection string?"
  2. Read .env.example — shows structure without exposing secrets
  3. Read documentation — check README.md, docs/, config guides

What it can do on your machine

Read from SKILL.md and the folder at commit 774df00. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENAI_API_KEY
    • GITHUB_TOKEN
    • DB_PASSWORD
    • API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secret Handling loads about 1.9k tokens when it runs. Until then it costs about 20 tokens; SKILL.md has 549 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~20
When it runs · the whole SKILL.md, loaded when a task matches
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:3
    description: Never read .env files or write secrets to .squad/ committed files
  • NoteMentions a .env fileSKILL.md:11
    ess to the entire repository, including `.env` files containing live credentials. If an agent reads secrets and writes t
  • NoteMentions a .env fileSKILL.md:18
    - `.env` (production secrets)
  • NoteMentions a .env fileSKILL.md:19
    - `.env.local` (local dev secrets)
  • NoteMentions a .env fileSKILL.md:20
    - `.env.production` (production environment)
  • NoteMentions a .env fileSKILL.md:21
    - `.env.development` (development environment)
  • NoteMentions a .env fileSKILL.md:22
    - `.env.staging` (staging environment)
  • NoteMentions a .env fileSKILL.md:23
    - `.env.test` (test environment with real credentials)
  • NoteMentions a .env fileSKILL.md:24
    - Any file matching `.env.*` UNLESS explicitly allowed (see below)
  • NoteMentions a .env fileSKILL.md:36
    **NEVER assume you can "just peek at .env to understand the schema."** Use `.env.example` or ask.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/waza at commit 774df00, republished under its MIT licence (© microsoft). 549 words, ~1,868 tokens.

Download SKILL.mdSave it as .claude/skills/secret-handling/SKILL.md (or your agent's skills folder).
name
secret-handling
description
Never read .env files or write secrets to .squad/ committed files
domain
security, file-operations, team-collaboration
confidence
high
source
earned (issue

Context

Spawned agents have read access to the entire repository, including .env files containing live credentials. If an agent reads secrets and writes them to .squad/ files (decisions, logs, history), Scribe auto-commits them to git, exposing them in remote history. This skill codifies absolute prohibitions and safe alternatives.

Patterns

Prohibited File Reads

NEVER read these files:

  • .env (production secrets)
  • .env.local (local dev secrets)
  • .env.production (production environment)
  • .env.development (development environment)
  • .env.staging (staging environment)
  • .env.test (test environment with real credentials)
  • Any file matching .env.* UNLESS explicitly allowed (see below)

Allowed alternatives:

  • .env.example (safe — contains placeholder values, no real secrets)
  • .env.sample (safe — documentation template)
  • .env.template (safe — schema/structure reference)

If you need config info:

  1. Ask the user directly — "What's the database connection string?"
  2. Read .env.example — shows structure without exposing secrets
  3. Read documentation — check README.md, docs/, config guides

NEVER assume you can "just peek at .env to understand the schema." Use .env.example or ask.

Prohibited Output Patterns

NEVER write these to .squad/ files:

Pattern TypeExamplesRegex Pattern (for scanning)
API KeysOPENAI_API_KEY=sk-proj-..., GITHUB_TOKEN=ghp_...`[A-Z_]+(?:KEY
PasswordsDB_PASSWORD=super_secret_123, password: "..."`(?:PASSWORD
Connection Stringspostgres://user:pass@host:5432/db, Server=...;Password=...`(?:postgres
JWT TokenseyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...eyJ[A-Za-z0-9_-]+\.eyJ[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+
Private Keys-----BEGIN PRIVATE KEY-----, -----BEGIN RSA PRIVATE KEY----------BEGIN [A-Z ]+PRIVATE KEY-----
AWS CredentialsAKIA..., aws_secret_access_key=...`AKIA[0-9A-Z]{16}
Email Addressesuser@example.com (PII violation per team decision)[a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}

What to write instead:

  • Placeholder values: DATABASE_URL=<set in .env>
  • Redacted references: API key configured (see .env.example)
  • Architecture notes: "App uses JWT auth — token stored in session"
  • Schema documentation: "Requires OPENAI_API_KEY, GITHUB_TOKEN (see .env.example for format)"
Scribe Pre-Commit Validation

Before committing .squad/ changes, Scribe MUST:

  1. Scan all staged files for secret patterns (use regex table above)

  2. Check for prohibited file names (don't commit .env even if manually staged)

  3. If secrets detected:

    • STOP the commit (do NOT proceed)
    • Remove the file from staging: git reset HEAD <file>
    • Report to user:
      🚨 SECRET DETECTED — commit blocked
      
      File: .squad/decisions/inbox/river-db-config.md
      Pattern: DATABASE_URL=postgres://user:password@localhost:5432/prod
      
      This file contains credentials and MUST NOT be committed.
      Please remove the secret, replace with placeholder, and try again.
    • Exit with error (never silently skip)
  4. If no secrets detected:

    • Proceed with commit as normal

Implementation note for Scribe:

  • Run validation AFTER staging files, BEFORE calling git commit
  • Use PowerShell Select-String or git diff --cached to scan staged content
  • Fail loud — secret leaks are unacceptable, blocking the commit is correct behavior
Show full SKILL.md (220 more words)Show less
Remediation — If a Secret Was Already Committed

If you discover a secret in git history:

  1. STOP immediately — do not make more commits
  2. Alert the user:
    🚨 CREDENTIAL LEAK DETECTED
    
    A secret was found in git history:
    Commit: abc1234
    File: .squad/decisions/inbox/agent-config.md
    Pattern: API_KEY=sk-proj-...
    
    This requires immediate remediation:
    1. Revoke the exposed credential (regenerate API key, rotate password)
    2. Remove from git history (git filter-repo or BFG)
    3. Force-push the cleaned history
    
    Do NOT proceed with new work until this is resolved.
  3. Do NOT attempt to fix it yourself — secret removal requires specialized tools
  4. Wait for user confirmation before resuming work

Examples

✓ Correct: Reading Config Schema

Agent needs to know what environment variables are required:

Agent: "What environment variables does this app need?"
→ Reads `.env.example`:
    OPENAI_API_KEY=sk-...
    DATABASE_URL=postgres://user:pass@localhost:5432/db
    REDIS_URL=redis://localhost:6379

→ Writes to .squad/decisions/inbox/river-env-setup.md:
    "App requires three environment variables:
    - OPENAI_API_KEY (OpenAI API key, format: sk-...)
    - DATABASE_URL (Postgres connection string)
    - REDIS_URL (Redis connection string)
    See .env.example for full schema."
✗ Incorrect: Reading Live Credentials

Agent needs to know database schema:

Agent: (reads .env)
    DATABASE_URL=postgres://admin:super_secret_pw@prod.example.com:5432/appdb

→ Writes to .squad/decisions/inbox/river-db-schema.md:
    "Database connection: postgres://admin:super_secret_pw@prod.example.com:5432/appdb"
    
🚨 VIOLATION: Live credential written to committed file

Correct approach:

Agent: (reads .env.example OR asks user)
User: "It's a Postgres database, schema is in migrations/"

→ Writes to .squad/decisions/inbox/river-db-schema.md:
    "Database: Postgres (connection configured in .env). Schema defined in db/migrations/."
✓ Correct: Scribe Pre-Commit Validation

Scribe is about to commit:

powershell
# Stage files
git add .squad/

# Scan staged content for secrets
$stagedContent = git diff --cached
$secretPatterns = @(
    '[A-Z_]+(?:KEY|TOKEN|SECRET)=[^\s]+',
    '(?:PASSWORD|PASS|PWD)[:=]\s*["'']?[^\s"'']+',
    'eyJ[A-Za-z0-9_-]+\.eyJ[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+'
)

$detected = $false
foreach ($pattern in $secretPatterns) {
    if ($stagedContent -match $pattern) {
        $detected = $true
        Write-Host "🚨 SECRET DETECTED: $($matches[0])"
        break
    }
}

if ($detected) {
    # Remove from staging, report, exit
    git reset HEAD .squad/
    Write-Error "Commit blocked — secret detected in staged files"
    exit 1
}

# Safe to commit
git commit -F $msgFile

Anti-Patterns

  • ❌ Reading .env "just to check the schema" — use .env.example instead
  • ❌ Writing "sanitized" connection strings that still contain credentials
  • ❌ Assuming "it's just a dev environment" makes secrets safe to commit
  • ❌ Committing first, scanning later — validation MUST happen before commit
  • ❌ Silently skipping secret detection — fail loud, never silent
  • ❌ Trusting agents to "know better" — enforce at multiple layers (prompt, hook, architecture)
  • ❌ Writing secrets to "temporary" files in .squad/ — Scribe commits ALL .squad/ changes
  • ❌ Extracting "just the host" from a connection string — still leaks infrastructure topology

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .copilot/skills/secret-handling of microsoft/waza.

Open the folder on GitHubat commit 774df00

Used in 4 other repositories

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 4 other GitHub owners. This page covers the copy in microsoft/waza, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Secret Handling next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secret Handling compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secret Handling this skillmicrosoft/waza1.4k4 repos~1.9kAutomated safety check: NotesMIT
Env Secrets Manageralirezarezvani/claude-skills28k—~2.7kAutomated safety check: NotesMIT
Env Secret Detectorjeremylongshore/tons-of-skills-marketplace2.8k—~576Automated safety check: PassMIT
Env Secrets Managerborghei/Claude-Skills881—~1.6kAutomated safety check: NotesMIT
Openclaw Secret Scanning Maintaineropenclaw/openclaw392k—~2.5kAutomated safety check: PassMIT
Secret Scanninggithub/awesome-copilot40k1 repos~2.4kAutomated safety check: PassMIT

Similar skills

  • Env Secrets Manager

    alirezarezvani/claude-skills

    Manage environment-variable hygiene and secrets safety across local development and production.

    28k GitHub stars~2.7k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check: notes
  • Env Secret Detector

    jeremylongshore/tons-of-skills-marketplace

    Detect env secret detector operations. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~576 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Env Secrets Manager

    borghei/Claude-Skills

    Environment and secrets management lifecycle: .env scaffolding, validation, leak detection, and rotation across Vault, AWS SSM, 1Password, and Doppler.

    881 GitHub stars~1.6k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Triage, redact, clean up, and resolve OpenClaw GitHub Secret Scanning alerts in issues or PRs.

    392k GitHub stars~2.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Secret Scanning

    github/awesome-copilot

    Official

    Guide for configuring and managing GitHub secret scanning, push protection, custom patterns, and secret alert remediation.

    40k GitHub starsUsed in 1 repo~2.4k tokens
    DevOps & CloudAuto-check passed
  • Secrets Management

    davila7/claude-code-templates

    Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools.

    32k GitHub starsUsed in 12 repos~2k tokens
    DevOps & CloudAuto-check passed

More from microsoft/waza

All 16 skills in this repo
  • Squad Commands Menu

    microsoft/waza

    Official

    Shows a categorized, interactive menu of common Squad operations, such as install, upgrade and team management, and collects arguments before running anything.

    1.4k GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check passed
  • Official

    Shared collaboration rules for a team of squad agents covering worktree awareness, writing decisions to an inbox, cross-agent requests and reviewer lockout.

    1.4k GitHub starsUsed in 4 repos~500 tokens
    Auto-check passed
  • Official

    Walks through releasing a new version of the waza azd extension: changelog from commits, semver bump with your confirmation, and a release PR.

    1.4k GitHub stars~1.5k tokensUpdated 2 days ago
    Auto-check passed
  • Official

    Dev-first branching model for the Squad project: feature work branches from dev, issue branches follow a naming rule and parallel issues use git worktrees.

    1.4k GitHub starsUsed in 4 repos~1.5k tokens
    Auto-check passed
  • Waza Skill Evaluator

    microsoft/waza

    Official

    Evaluates agent skills with a Go CLI that runs YAML-defined benchmarks, compares runs and scores the quality of SKILL.md frontmatter.

    1.4k GitHub stars~2k tokensUpdated 2 days ago
    Auto-check passed
  • Reviewer Protocol

    microsoft/waza

    Official

    Reviewer rejection workflow and strict lockout semantics. An agent skill from microsoft/waza.

    1.4k GitHub starsUsed in 4 repos~1.1k tokens
    Auto-check passed

Questions about Secret Handling

What does Secret Handling do?

Never read .env files or write secrets to .squad/ committed files. Secret Handling is an agent skill from microsoft/waza, published by the product's own GitHub organization.

How do I install Secret Handling in Claude Code?

Run `npx skills add microsoft/waza --skill secret-handling -a claude-code`. Or copy the skill folder (.copilot/skills/secret-handling in microsoft/waza) into .claude/skills/secret-handling in your project. Claude Code loads it when a task matches its description.

How do I install Secret Handling in Codex?

Run `npx skills add microsoft/waza --skill secret-handling -a codex`. Or copy the skill folder (.copilot/skills/secret-handling in microsoft/waza) into .agents/skills/secret-handling in your project. Codex loads it when a task matches its description.

Can I use Secret Handling in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/waza --skill secret-handling -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secret-handling, .gemini/skills/secret-handling, .github/skills/secret-handling and .opencode/skills/secret-handling in your project.

What does Secret Handling need to run?

Going by SKILL.md and its folder, Secret Handling needs the command-line tools its instructions call (git) and credentials named OPENAI_API_KEY, GITHUB_TOKEN, DB_PASSWORD and API_KEY. Our summary lists: A credential in OPENAI_API_KEY; A credential in GITHUB_TOKEN.

Does Secret Handling access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Secret Handling safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Secret Handling use?

Secret Handling is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Secret Handling use?

About 1.9k tokens (SKILL.md is roughly 7.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Secret Handling?

Skills that share tags, products or a category with Secret Handling: Env Secrets Manager (alirezarezvani/claude-skills, 28k stars), Env Secret Detector (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Env Secrets Manager (borghei/Claude-Skills, 881 stars) and Openclaw Secret Scanning Maintainer (openclaw/openclaw, 392k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secret Handling?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/waza, which has 1,403 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 6, 2026.

Source: microsoft/waza on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.