Agent skill

Audit Env Variables

by qdhenry in qdhenry/Claude-Command-Suite

Analyze environment variables in JavaScript/TypeScript projects.

No licenceAuto-check: notesDevOps & Cloud

Install Audit Env Variables

skills CLI
$ npx skills add qdhenry/Claude-Command-Suite --skill audit-env-variables -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install qdhenry/Claude-Command-Suite audit-env-variables --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/qdhenry/Claude-Command-Suite.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/audit-env-variables .claude/skills/audit-env-variables && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-env-variables
GitHub stars
1.3k
Token cost
~2.8k tokens
SKILL.md length
828 words
Files
3 (incl. references)
Skills in repo
9
Repo updated
First seen
Licence
None found

At a glance

Analyze environment variables in JavaScript/TypeScript projects.

  • Works in 9 steps: Discover Environment Files → Extract Declared Variables → Find Code References → …
  • Auditing .env files
  • SKILL.md covers Step 1: Discover Environment…, Step 2: Extract Declared…, Step 3: Find Code References and Step 4: Cross-Reference Usage, plus 5 more sections
  • Calls npm and git; needs OLD_API_KEY and API_KEY

What it does

Audit Env Variables is an agent skill from qdhenry/Claude-Command-Suite. Analyze environment variables in JavaScript/TypeScript projects. Identifies unused variables, infers permission scopes, detects specific services (Stripe, AWS, Supabase), and documents code paths. Includes optional cleanup of unused variables with regression detection. Use when auditing .env files, reviewing security, or documenting project configuration.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/service-patterns.md` and `templates/env-audit-report.md`).

It sits in DevOps & Cloud, covering Secrets management. It works with Amazon Web Services, Supabase, Stripe and JavaScript. The repository describes itself as: Professional slash commands for Claude Code that provide structured workflows for software development tasks including code review, feature creation, security auditing, and…

When your agent uses it

  • Auditing .env files
  • Reviewing security
  • Documenting project configuration

Example prompts

  • “/audit-env-variables”

Requirements

  • A credential in API_KEY
  • A credential in STRIPE_SECRET_KEY
  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash, Write, Edit, AskUserQuestion

Workflow steps

9 steps, taken from the step headings in SKILL.md.

  1. Discover Environment Files
  2. Extract Declared Variables
  3. Find Code References
  4. Cross-Reference Usage
  5. Detect Services and Infer Permissions
  6. Map Code Paths
  7. Generate Report
  8. Cleanup Unused Variables (Optional)
  9. Regression Prevention

What it can do on your machine

Read from SKILL.md and the folder at commit e89b2f0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash
    • Write
    • Edit
    • AskUserQuestion

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OLD_API_KEY
    • API_KEY
    • STRIPE_SECRET_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Env Variables loads about 2.8k tokens when it runs, and up to ~4.8k if it reads all its reference files. Until then it costs about 94 tokens; SKILL.md has 828 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:3
    regression detection. Use when auditing .env files, reviewing security, or documenting project configuration.
  • NoteMentions a .env fileSKILL.md:22
    1. Scan for `.env*` files in project root
  • NoteMentions a .env fileSKILL.md:41
    find . -maxdepth 2 -name ".env*" -o -name "env.d.ts" | grep -v node_modules
  • NoteMentions a .env fileSKILL.md:45
    - `.env` - Local development
  • NoteMentions a .env fileSKILL.md:46
    - `.env.local` - Local overrides
  • NoteMentions a .env fileSKILL.md:47
    - `.env.development` / `.env.production` - Environment-specific
  • NoteMentions a .env fileSKILL.md:100
    - Variables only in .env but not .env.example (documentation gap)
  • NoteMentions a .env fileSKILL.md:152
    1. OLD_API_KEY (.env, .env.local)
  • NoteMentions a .env fileSKILL.md:156
    2. DEPRECATED_SERVICE_URL (.env)
  • NoteMentions a .env fileSKILL.md:190
    [ ] OLD_API_KEY - Remove from .env, .env.local

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 828 words (~2,807 tokens).

“Perform a comprehensive audit of environment variables in a JS/TS project:”

— opening of SKILL.md by qdhenry
name
audit-env-variables
allowed-tools
Read, Grep, Glob, Bash, Write, Edit, AskUserQuestion
argument-hint
[output-path] [--cleanup]

Read the full SKILL.md on GitHub

Files

SKILL.md and 2 other files (references) in .claude/skills/audit-env-variables of qdhenry/Claude-Command-Suite.

  • SKILL.md
  • references/service-patterns.md
  • templates/env-audit-report.md

Open the folder on GitHubat commit e89b2f0

Compare with similar skills

Audit Env Variables next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Env Variables compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Env Variables this skillqdhenry/Claude-Command-Suite1.3k—~2.8kAutomated safety check: NotesNone
Azure Appconfiguration TSmicrosoft/skills3.1k5 repos~2.2kAutomated safety check: PassMIT
Scanning For Hardcoded Secretsjeremylongshore/tons-of-skills-marketplace2.8k—~2.1kAutomated safety check: NotesMIT
Supabase Install Authjeremylongshore/tons-of-skills-marketplace2.8k—~1.8kAutomated safety check: NotesMIT
Security SecretsIgorWarzocha/Opencode-Workflows122—~1.2kAutomated safety check: NotesNone
Supercov Securitysupercorp-ai/supercov1501 repos~236Automated safety check: PassMIT

Similar skills

  • Official

    Build applications using Azure App Configuration SDK for JavaScript (@azure/app-configuration).

    3.1k GitHub starsUsed in 5 repos~2.2k tokens
    DevOps & CloudAuto-check passed
  • Scanning For Hardcoded Secrets

    jeremylongshore/tons-of-skills-marketplace

    Scan a source-code tree for hardcoded credentials embedded in source files: AWS access keys, GitHub tokens, Stripe keys, Slack tokens, Anthropic API keys, OpenAI keys, JWT signing secrets, generic…

    2.8k GitHub stars~2.1k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Supabase Install Auth

    jeremylongshore/tons-of-skills-marketplace

    Install and configure Supabase SDK, CLI, and project authentication.

    2.8k GitHub stars~1.8k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Security Secrets

    IgorWarzocha/Opencode-Workflows

    Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows.

    122 GitHub stars~1.2k tokensUpdated 8 mo ago
    SecurityAuto-check: notes
  • Supercov Security

    supercorp-ai/supercov

    Scans a repository's source for security vulnerabilities with the supercov CLI, pointing to the line of each finding and mapping it to CWE classes.

    150 GitHub starsUsed in 1 repo~236 tokens
    Testing & QAAuto-check passed
  • Git Hooks

    Prorise-cool/Claude-Code-Multi-Agent

    Central authority on git hook implementations, modern best practices, and tooling for .NET/C, JavaScript/TypeScript, Python, and polyglot repositories.

    305 GitHub stars~3.6k tokensUpdated 23 days ago
    DevelopmentAuto-check: notes

More from qdhenry/Claude-Command-Suite

All 9 skills in this repo
  • Elevenlabs Transcribe

    qdhenry/Claude-Command-Suite

    Transcribes audio/video files using ElevenLabs Scribe v2 API.

    1.3k GitHub stars~1.5k tokensUpdated 7 mo ago
    Auto-check: notes
  • Extract Video Frames

    qdhenry/Claude-Command-Suite

    Extracts frames and timestamped audio segments from video files (GIF, MP4, MOV) at configurable intervals and stores them in a directory with a manifest file.

    1.3k GitHub stars~1.6k tokensUpdated 7 mo ago
    Auto-check passed
  • Bigcommerce API

    qdhenry/Claude-Command-Suite

    BigCommerce API expert for building integrations, apps, headless storefronts, and automations.

    1.3k GitHub stars~1.5k tokensUpdated 7 mo ago
    Auto-check passed
  • File Watcher

    qdhenry/Claude-Command-Suite

    Chokidar-based file watcher that triggers claude -p on changes.

    1.3k GitHub stars~808 tokensUpdated 7 mo ago
    Auto-check passed
  • Setup Agent Tail

    qdhenry/Claude-Command-Suite

    Configure agent-tail log aggregation for the current project.

    1.3k GitHub stars~1.8k tokensUpdated 7 mo ago
    Auto-check passed
  • Setup Portless

    qdhenry/Claude-Command-Suite

    Sets up Portless for a project to replace port numbers with stable named .localhost URLs.

    1.3k GitHub stars~1.2k tokensUpdated 7 mo ago
    Auto-check: notes

Categories

Questions about Audit Env Variables

What does Audit Env Variables do?

Analyze environment variables in JavaScript/TypeScript projects. Audit Env Variables is an agent skill from qdhenry/Claude-Command-Suite. Analyze environment variables in JavaScript/TypeScript projects.

When should I use Audit Env Variables?

Audit Env Variables fits situations like: auditing .env files; reviewing security; documenting project configuration.

How do I install Audit Env Variables in Claude Code?

Run `npx skills add qdhenry/Claude-Command-Suite --skill audit-env-variables -a claude-code`. Or copy the skill folder (.claude/skills/audit-env-variables in qdhenry/Claude-Command-Suite) into .claude/skills/audit-env-variables in your project. Claude Code loads it when a task matches its description.

How do I install Audit Env Variables in Codex?

Run `npx skills add qdhenry/Claude-Command-Suite --skill audit-env-variables -a codex`. Or copy the skill folder (.claude/skills/audit-env-variables in qdhenry/Claude-Command-Suite) into .agents/skills/audit-env-variables in your project. Codex loads it when a task matches its description.

Can I use Audit Env Variables in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add qdhenry/Claude-Command-Suite --skill audit-env-variables -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-env-variables, .gemini/skills/audit-env-variables, .github/skills/audit-env-variables and .opencode/skills/audit-env-variables in your project.

What does Audit Env Variables need to run?

Going by SKILL.md and its folder, Audit Env Variables needs the command-line tools its instructions call (npm and git) and credentials named OLD_API_KEY, API_KEY and STRIPE_SECRET_KEY. Our summary lists: A credential in API_KEY; A credential in STRIPE_SECRET_KEY. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, Write, Edit, AskUserQuestion.

Does Audit Env Variables access the network?

SKILL.md contains no URLs. Its commands use npm and git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Audit Env Variables safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Audit Env Variables use?

No licence was found for Audit Env Variables or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Audit Env Variables use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2k tokens, read only when the agent opens those files.

What are the alternatives to Audit Env Variables?

Skills that share tags, products or a category with Audit Env Variables: Azure Appconfiguration TS (microsoft/skills, 3.1k stars), Scanning For Hardcoded Secrets (jeremylongshore/tons-of-skills-marketplace, 2.8k stars), Supabase Install Auth (jeremylongshore/tons-of-skills-marketplace, 2.8k stars) and Security Secrets (IgorWarzocha/Opencode-Workflows, 122 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Env Variables?

qdhenry (a GitHub user) maintains it in qdhenry/Claude-Command-Suite, which has 1,342 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on March 1, 2026.

Source: qdhenry/Claude-Command-Suite on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.