Set up op CLI, sign in, and read or inject secrets. An agent skill from Luciole-Studio/Misaka-Agent.

MITAuto-check: notes

Install 1password

skills CLI
$ npx skills add Luciole-Studio/Misaka-Agent --skill 1password -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Luciole-Studio/Misaka-Agent 1password --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Luciole-Studio/Misaka-Agent.git skills-src && mkdir -p .claude/skills && cp -r skills-src/misaka/core/skills/assets/optional/security/1password .claude/skills/1password && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
1password
GitHub stars
158
Used in
1 other repo
Token cost
~1.2k tokens
SKILL.md length
315 words
Files
3 (incl. references)
Skills in repo
77
Repo updated
First seen
Licence
MIT

At a glance

Set up op CLI, sign in, and read or inject secrets. An agent skill from Luciole-Studio/Misaka-Agent.

  • Works in 3 steps: Enable in 1Password desktop app:… → Ensure app is unlocked → Run op signin and approve the biometric…
  • SKILL.md covers Requirements, When to Use, Authentication Methods and Setup, plus 5 more sections
  • Calls brew and winget; needs OP_SERVICE_ACCOUNT_TOKEN and DB_PASSWORD

What it does

1password is an agent skill from Luciole-Studio/Misaka-Agent. Set up op CLI, sign in, and read or inject secrets.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/cli-examples.md` and `references/get-started.md`).

It works with tmux. The repository describes itself as: A multi-agent research system for the humanities and social sciences. The licence is MIT.

Example prompts

  • “/1password”

Requirements

  • A credential in OP_SERVICE_ACCOUNT_TOKEN
  • A credential in OP_CONNECT_TOKEN

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Enable in 1Password desktop app: Settings → Developer → Integrate with 1Password CLI
  2. Ensure app is unlocked
  3. Run op signin and approve the biometric prompt

What it can do on your machine

Read from SKILL.md and the folder at commit 3bcf7a3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • brew
    • winget

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • developer.1password.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OP_SERVICE_ACCOUNT_TOKEN
    • DB_PASSWORD
    • OP_CONNECT_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

1password loads about 1.2k tokens when it runs, and up to ~1.4k if it reads all its reference files. Until then it costs about 15 tokens; SKILL.md has 315 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~15
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:44
    UNT_TOKEN` in `${HERMES_HOME:-~/.hermes}/.env` (the skill will prompt for this on first load).

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Luciole-Studio/Misaka-Agent at commit 3bcf7a3, republished under its MIT licence (© Luciole-Studio). 315 words, ~1,160 tokens.

Download SKILL.mdSave it as .claude/skills/1password/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
1password
description
Set up op CLI, sign in, and read or inject secrets.
version
1.0.0
author
arceus77-7, enhanced by Hermes Agent
license
MIT
platforms
linux, macos, windows
setup.help
Create a service account at https://my.1password.com → Settings → Service Accounts

1Password CLI

Use this skill when the user wants secrets managed through 1Password instead of plaintext env vars or files.

Requirements

  • 1Password account
  • 1Password CLI (op) installed
  • One of: desktop app integration, service account token (OP_SERVICE_ACCOUNT_TOKEN), or Connect server
  • tmux available for stable authenticated sessions during Hermes terminal calls (desktop app flow only)

When to Use

  • Install or configure 1Password CLI
  • Sign in with op signin
  • Read secret references like op://Vault/Item/field
  • Inject secrets into config/templates using op inject
  • Run commands with secret env vars via op run

Authentication Methods

Set OP_SERVICE_ACCOUNT_TOKEN in ${HERMES_HOME:-~/.hermes}/.env (the skill will prompt for this on first load). No desktop app needed. Supports op read, op inject, op run.

bash
export OP_SERVICE_ACCOUNT_TOKEN="your-token-here"
op whoami  # verify — should show Type: SERVICE_ACCOUNT
Desktop App Integration (interactive)
  1. Enable in 1Password desktop app: Settings → Developer → Integrate with 1Password CLI
  2. Ensure app is unlocked
  3. Run op signin and approve the biometric prompt
Connect Server (self-hosted)
bash
export OP_CONNECT_HOST="http://localhost:8080"
export OP_CONNECT_TOKEN="your-connect-token"

Setup

  1. Install CLI:
bash
# macOS
brew install 1password-cli

# Linux (official package/install docs)
# See references/get-started.md for distro-specific links.

# Windows (winget)
winget install AgileBits.1Password.CLI
  1. Verify:
bash
op --version
  1. Choose an auth method above and configure it.

Hermes Execution Pattern (desktop app flow)

Hermes terminal commands are non-interactive by default and can lose auth context between calls. For reliable op use with desktop app integration, run sign-in and secret operations inside a dedicated tmux session.

Note: This is NOT needed when using OP_SERVICE_ACCOUNT_TOKEN — the token persists across terminal calls automatically.

bash
SOCKET_DIR="${TMPDIR:-/tmp}/hermes-tmux-sockets"
mkdir -p "$SOCKET_DIR"
SOCKET="$SOCKET_DIR/hermes-op.sock"
SESSION="op-auth-$(date +%Y%m%d-%H%M%S)"

tmux -S "$SOCKET" new -d -s "$SESSION" -n shell

# Sign in (approve in desktop app when prompted)
tmux -S "$SOCKET" send-keys -t "$SESSION":0.0 -- "eval \"\$(op signin --account my.1password.com)\"" Enter

# Verify auth
tmux -S "$SOCKET" send-keys -t "$SESSION":0.0 -- "op whoami" Enter

# Example read
tmux -S "$SOCKET" send-keys -t "$SESSION":0.0 -- "op read 'op://Private/Npmjs/one-time password?attribute=otp'" Enter

# Capture output when needed
tmux -S "$SOCKET" capture-pane -p -J -t "$SESSION":0.0 -S -200

# Cleanup
tmux -S "$SOCKET" kill-session -t "$SESSION"

Common Operations

Read a secret
bash
op read "op://app-prod/db/password"
Get OTP
bash
op read "op://app-prod/npm/one-time password?attribute=otp"
Inject into template
bash
echo "db_password: {{ op://app-prod/db/password }}" | op inject
Run a command with secret env var
bash
export DB_PASSWORD="op://app-prod/db/password"  # example op:// reference, resolved by `op run`
op run -- sh -c '[ -n "$DB_PASSWORD" ] && echo "DB_PASSWORD is set" || echo "DB_PASSWORD missing"'

Guardrails

  • Never print raw secrets back to user unless they explicitly request the value.
  • Prefer op run / op inject instead of writing secrets into files.
  • If command fails with "account is not signed in", run op signin again in the same tmux session.
  • If desktop app integration is unavailable (headless/CI), use service account token flow.

CI / Headless note

For non-interactive use, authenticate with OP_SERVICE_ACCOUNT_TOKEN and avoid interactive op signin. Service accounts require CLI v2.18.0+.

References

© Luciole-Studio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in misaka/core/skills/assets/optional/security/1password of Luciole-Studio/Misaka-Agent.

  • SKILL.md
  • references/cli-examples.md
  • references/get-started.md

Open the folder on GitHubat commit 3bcf7a3

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Luciole-Studio/Misaka-Agent, which our catalogue first saw on October 7, 2026.

Compare with similar skills

1password next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

1password compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
1password this skillLuciole-Studio/Misaka-Agent1581 repos~1.2kAutomated safety check: NotesMIT
1passwordtrpc-group/trpc-agent-go1.9k14 repos~656Automated safety check: PassApache-2.0
CodeGraph Agent Evalcolbymchenry/codegraph74k—~950Automated safety check: PassMIT
Tmuxtrpc-group/trpc-agent-go1.9k23 repos~868Automated safety check: PassApache-2.0
CodexBar Live QAsteipete/CodexBar22k—~1.2kAutomated safety check: PassMIT
Tmuxopenclaw/openclaw392k1 repos~640Automated safety check: PassMIT

Similar skills

  • 1password

    trpc-group/trpc-agent-go

    Set up and use 1Password CLI (op). An agent skill from trpc-group/trpc-agent-go.

    1.9k GitHub starsUsed in 14 repos~656 tokens
    AI & LLM EngineeringAuto-check passed
  • CodeGraph Agent Eval

    colbymchenry/codegraph

    Benchmarks how much CodeGraph helps a coding agent on a real repository, comparing runs with and without it for a chosen local or published version.

    74k GitHub stars~950 tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • Tmux

    trpc-group/trpc-agent-go

    Remote-control tmux sessions for interactive CLIs by sending keystrokes and scraping pane output.

    1.9k GitHub starsUsed in 23 repos~868 tokens
    Data & AnalyticsAuto-check passed
  • CodexBar Live QA

    steipete/CodexBar

    Runs live QA for the CodexBar app: provider usage matrix checks through its packaged CLI, config validation and menu checks, with 1Password-backed credentials handled safely.

    22k GitHub stars~1.2k tokensUpdated today
    Testing & QAAuto-check passed
  • Tmux

    openclaw/openclaw

    Control tmux sessions/panes for interactive CLIs: list, capture output, send keys, paste text, monitor prompts.

    392k GitHub starsUsed in 1 repo~640 tokens
    Auto-check passed
  • Reproduces a feature from Codex or Claude Code in Qwen Code by running the reference agent under capture, reading the traces, then implementing matching behavior.

    28k GitHub stars~1.5k tokensUpdated today
    DevelopmentAuto-check passed

More from Luciole-Studio/Misaka-Agent

All 77 skills in this repo
  • Kanban Video Orchestrator

    Luciole-Studio/Misaka-Agent

    Plan and run multi-agent video production pipelines. An agent skill from Luciole-Studio/Misaka-Agent.

    158 GitHub starsUsed in 2 repos~2.4k tokens
    Auto-check: notes
  • Ast Grep

    Luciole-Studio/Misaka-Agent

    AST-aware structural code search and rewrite via ast-grep. An agent skill from Luciole-Studio/Misaka-Agent.

    158 GitHub starsUsed in 1 repo~3.2k tokens
    Auto-check passed
  • Drug Discovery

    Luciole-Studio/Misaka-Agent

    Drug discovery: ChEMBL search, drug-likeness, interactions. An agent skill from Luciole-Studio/Misaka-Agent.

    158 GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed
  • Fitness Nutrition

    Luciole-Studio/Misaka-Agent

    Workout planning, macros, and body metrics via wger/USDA. An agent skill from Luciole-Studio/Misaka-Agent.

    158 GitHub starsUsed in 1 repo~2.4k tokens
    Auto-check passed
  • Hyperframes

    Luciole-Studio/Misaka-Agent

    Render MP4/WebM videos from HTML compositions. An agent skill from Luciole-Studio/Misaka-Agent.

    158 GitHub starsUsed in 1 repo~3.9k tokens
    Auto-check passed
  • Osint Investigation

    Luciole-Studio/Misaka-Agent

    Follow the money via public records and sanctions data. An agent skill from Luciole-Studio/Misaka-Agent.

    158 GitHub starsUsed in 1 repo~2.9k tokens
    Auto-check passed

Works with

Questions about 1password

What does 1password do?

Set up op CLI, sign in, and read or inject secrets. An agent skill from Luciole-Studio/Misaka-Agent. 1password is an agent skill from Luciole-Studio/Misaka-Agent. Set up op CLI, sign in, and read or inject secrets.

How do I install 1password in Claude Code?

Run `npx skills add Luciole-Studio/Misaka-Agent --skill 1password -a claude-code`. Or copy the skill folder (misaka/core/skills/assets/optional/security/1password in Luciole-Studio/Misaka-Agent) into .claude/skills/1password in your project. Claude Code loads it when a task matches its description.

How do I install 1password in Codex?

Run `npx skills add Luciole-Studio/Misaka-Agent --skill 1password -a codex`. Or copy the skill folder (misaka/core/skills/assets/optional/security/1password in Luciole-Studio/Misaka-Agent) into .agents/skills/1password in your project. Codex loads it when a task matches its description.

Can I use 1password in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Luciole-Studio/Misaka-Agent --skill 1password -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/1password, .gemini/skills/1password, .github/skills/1password and .opencode/skills/1password in your project.

What does 1password need to run?

Going by SKILL.md and its folder, 1password needs the command-line tools its instructions call (brew and winget) and credentials named OP_SERVICE_ACCOUNT_TOKEN, DB_PASSWORD and OP_CONNECT_TOKEN. Our summary lists: A credential in OP_SERVICE_ACCOUNT_TOKEN; A credential in OP_CONNECT_TOKEN.

Does 1password access the network?

SKILL.md names 1 domain. As links in the text: developer.1password.com. This is read from the text; nothing was executed.

Is 1password safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does 1password use?

1password is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does 1password use?

About 1.2k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 282 tokens, read only when the agent opens those files.

What are the alternatives to 1password?

Skills that share tags, products or a category with 1password: 1password (trpc-group/trpc-agent-go, 1.9k stars), CodeGraph Agent Eval (colbymchenry/codegraph, 74k stars), Tmux (trpc-group/trpc-agent-go, 1.9k stars) and CodexBar Live QA (steipete/CodexBar, 22k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains 1password?

Luciole-Studio (a GitHub organization) maintains it in Luciole-Studio/Misaka-Agent, which has 158 GitHub stars. The repository holds 77 skills in this directory. The repository was last updated on October 8, 2026.

Source: Luciole-Studio/Misaka-Agent on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.