Monitor CI
nrwl/nx
Monitor Nx Cloud CI pipeline and handle self-healing fixes. An agent skill from nrwl/nx.
How an AI agent should safely drive the pass-cli password manager (this repo's binary).
$ npx skills add reyamira/pass-cli --skill pass-cli -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install reyamira/pass-cli pass-cli --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/reyamira/pass-cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/pass-cli .claude/skills/pass-cli && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "pass-cli" agent skill from https://github.com/reyamira/pass-cli/tree/main/.claude/skills/pass-cli into .claude/skills/pass-cli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pass-cli", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/reyamira/pass-cli/tree/main/.claude/skills/pass-cliType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add reyamira/pass-cli --skill pass-cli -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install reyamira/pass-cli pass-cli --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/reyamira/pass-cli.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/pass-cli .agents/skills/pass-cli && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "pass-cli" agent skill from https://github.com/reyamira/pass-cli/tree/main/.claude/skills/pass-cli into .agents/skills/pass-cli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pass-cli", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add reyamira/pass-cli --skill pass-cli -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install reyamira/pass-cli pass-cli --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/reyamira/pass-cli.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/pass-cli .cursor/skills/pass-cli && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "pass-cli" agent skill from https://github.com/reyamira/pass-cli/tree/main/.claude/skills/pass-cli into .cursor/skills/pass-cli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pass-cli", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/reyamira/pass-cli.git --path .claude/skills/pass-cli--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add reyamira/pass-cli --skill pass-cli -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install reyamira/pass-cli pass-cli --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/reyamira/pass-cli.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/pass-cli .gemini/skills/pass-cli && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "pass-cli" agent skill from https://github.com/reyamira/pass-cli/tree/main/.claude/skills/pass-cli into .gemini/skills/pass-cli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pass-cli", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install reyamira/pass-cli pass-cliInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add reyamira/pass-cli --skill pass-cli -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/reyamira/pass-cli.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/pass-cli .github/skills/pass-cli && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "pass-cli" agent skill from https://github.com/reyamira/pass-cli/tree/main/.claude/skills/pass-cli into .github/skills/pass-cli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pass-cli", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add reyamira/pass-cli --skill pass-cli -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install reyamira/pass-cli pass-cli --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/reyamira/pass-cli.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/pass-cli .opencode/skills/pass-cli && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "pass-cli" agent skill from https://github.com/reyamira/pass-cli/tree/main/.claude/skills/pass-cli into .opencode/skills/pass-cli/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "pass-cli", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
pass-cliHow an AI agent should safely drive the pass-cli password manager (this repo's binary).
Pass CLI is an agent skill from reyamira/pass-cli. How an AI agent should safely drive the pass-cli password manager (this repo's binary). Use whenever a task needs a stored secret/credential to run a command, when reading from or listing a pass-cli vault, or when you're about to capture a secret with get/command substitution — there is a safer path. Covers exec (hand a secret to a child process without it ever touching stdout), the safe-by-default list, and the leak traps to avoid.
Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud. The repository describes itself as: A secure, cross-platform, always-free, and open-source alternative to 1password, bitwarden, etc., Password and API key manager for folks who live in the command line. (CLI + TUI). The licence is Apache-2.0.
Read from SKILL.md and the folder at commit f42ade3. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
curlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
GITHUB_TOKENAWS_ACCESS_KEY_IDAWS_SECRET_ACCESS_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Pass CLI loads about 1.5k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 609 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- Am I writing the secret into a `.env*` or any file a tool watches? → the harness echoes file changes; don't.Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from reyamira/pass-cli at commit f42ade3, republished under its Apache-2.0 licence (© reyamira). 609 words, ~1,493 tokens.
.claude/skills/pass-cli/SKILL.md (or your agent's skills folder).pass-cli is a local, offline-first password manager. Its vault is a single AES-GCM-encrypted file. As an agent you will mostly need it to give a stored secret to a command you're about to run — and the cardinal rule is:
Never let a secret value land in the transcript, a log, CI output, or any file a tool watches. Once a secret is in the conversation log on disk it is compromised and must be rotated.
The whole point of the commands below is to move a secret from the vault into a
child process without it passing through stdout, the clipboard, your shell
history, or a set -x trace.
| You need to… | Use | Why |
|---|---|---|
| Run a command that reads the secret from its environment | pass-cli exec | Secret goes straight into the child's env; never on stdout |
| Know which services exist | pass-cli list -q | Bare service names; usernames hidden by default |
| Capture a value into a variable (last resort) | pass-cli get … --quiet --no-clipboard | Only if exec truly can't express it; see the trap below |
Default to exec. Reach for get only when nothing else works.
pass-cli exec — the safe way to hand a secret to a commandRuns a child command with credentials injected as environment variables. The value is passed only through the child's environment — never a file, the clipboard, or shell history. pass-cli writes nothing of its own to stdout, and the child's exit code is propagated unchanged.
# Explicit mapping (repeatable): --set ENV_NAME=service
pass-cli exec --set GITHUB_TOKEN=github -- gh repo list
# Multiple credentials at once
pass-cli exec --set AWS_ACCESS_KEY_ID=aws-id --set AWS_SECRET_ACCESS_KEY=aws-secret -- aws s3 ls
# Pick a non-password field for ALL mappings with -f/--field
pass-cli exec --set DB_USER=postgres --field username -- ./run-migration.sh
# Per-mapping field with service:field (overrides -f for that one entry)
pass-cli exec --set DB_USER=postgres:username --set DB_PASS=postgres -- ./run-migration.sh
# Convenience form: derive ENV name from the service (openai-api -> OPENAI_API)
pass-cli exec openai-api -- python train.pyKey facts:
-- separates pass-cli's flags from the child command. Everything after
-- is the child's argv. Omitting it is an error ("no command to run").-f/--field (default password) selects the field for all --set
mappings; valid fields: username, password, category, url, notes, service.service:field in a --set overrides -f for that single mapping.pass-cli exec … -- sh -c 'exit 7' exits 7. Safe
to use in &&/|| chains and CI gates.exec is read-only: it does NOT record field-access usage and does NOT
trigger a sync push, so calling it in a hot loop won't mutate the vault or
hit the network on every run./proc/<pid>/environ by the same user and inherited by descendants. This is
the same model as op run / aws-vault exec: far safer than files,
clipboards, or history, but it is not process isolation.pass-cli list — listing is the safe steppass-cli list # default table: NO username column (usernames can be sensitive)
pass-cli list -q # bare service names, one per line — ideal for agents/scripts
pass-cli list --show-usernames # opt the username column back in (only if you need it)
pass-cli list --format json # full metadata incl. usernames — explicit, structured opt-inUsernames are hidden by default because that field often holds sensitive
values (card/account/routing numbers stored as an entry's "username"). Use
pass-cli list -q to discover service names without dumping anything sensitive.
pass-cli get — last resort, and the trappass-cli get github --quiet --no-clipboard --field password--quiet prints only the field value to stdout; --no-clipboard skips the
clipboard. But this still puts the secret on stdout — and the trap is what you
do with it next:
# ❌ NEVER — the value is now in the transcript / log
echo "$(pass-cli get github --quiet --no-clipboard)"
TOKEN=$(pass-cli get github --quiet --no-clipboard); curl -H "Authorization: $TOKEN" ...
# ^ if any layer runs `set -x`, or a file-watcher captures the command, the token leaks
# ✅ Prefer exec — the value never becomes a shell variable or a transcript line
pass-cli exec --set TOKEN=github -- curl -H 'Authorization: Bearer '"$TOKEN" ...
# (the child reads $TOKEN from its own env; pass-cli printed nothing)If you genuinely must capture into a variable (a tool with no env-var path),
pipe it directly into the consumer in the same command, never echo it, and
never enable shell tracing in that shell.
echo/print a secret, or interpolate it into a logged command? → use exec.set -x / xtrace active in this shell? → a get/substitution will dump the value. Disable it or use exec..env* or any file a tool watches? → the harness echoes file changes; don't.pass-cli list -q (names only).If a secret value ever does reach the transcript: tell the user immediately so they can rotate it. The leak cannot be undone.
© reyamira, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/pass-cli of reyamira/pass-cli.
Open the folder on GitHubat commit f42ade3
Pass CLI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Pass CLI this skillreyamira/pass-cli | 114 | — | ~1.5k | Automated safety check: Notes | Apache-2.0 | |
| Monitor CInrwl/nx | 29k | 6 repos | ~4.7k | Automated safety check: Pass | MIT | |
| Terraform and OpenTofu Guideagentscope-ai/QwenPaw | 36k | 6 repos | ~4.2k | Automated safety check: Pass | Apache-2.0 | |
| Vercel Optimize Auditvercel-labs/agent-skills | 32k | 8 repos | ~4.3k | Automated safety check: Pass | None | |
| Analyze GitHub Action Logswithastro/astro | 63k | 1 repos | ~1.3k | Automated safety check: Pass | Custom licence | |
| Openclaw Live Updateropenclaw/openclaw | 392k | — | ~3.7k | Automated safety check: Pass | MIT |
nrwl/nx
Monitor Nx Cloud CI pipeline and handle self-healing fixes. An agent skill from nrwl/nx.
agentscope-ai/QwenPaw
Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.
vercel-labs/agent-skills
Runs a metrics-first audit of a deployed Vercel project, gating investigations on real signals to produce ranked, citation-backed cost and performance recommendations.
withastro/astro
Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.
openclaw/openclaw
Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.
netdata/netdata
Use only when the user explicitly asks to build, run, preview, inspect, or validate learn.netdata.cloud locally using the contents of a PR or documentation branch before merge.
Categories
How an AI agent should safely drive the pass-cli password manager (this repo's binary). Pass CLI is an agent skill from reyamira/pass-cli. How an AI agent should safely drive the pass-cli password manager (this repo's binary).
Pass CLI fits situations like: A task needs a stored secret/credential to run a command; listing a pass-cli vault; youre about to capture a secret with get/command substitution — there is a safer path.
Run `npx skills add reyamira/pass-cli --skill pass-cli -a claude-code`. Or copy the skill folder (.claude/skills/pass-cli in reyamira/pass-cli) into .claude/skills/pass-cli in your project. Claude Code loads it when a task matches its description.
Run `npx skills add reyamira/pass-cli --skill pass-cli -a codex`. Or copy the skill folder (.claude/skills/pass-cli in reyamira/pass-cli) into .agents/skills/pass-cli in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add reyamira/pass-cli --skill pass-cli -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pass-cli, .gemini/skills/pass-cli, .github/skills/pass-cli and .opencode/skills/pass-cli in your project.
Going by SKILL.md and its folder, Pass CLI needs the command-line tools its instructions call (curl) and credentials named GITHUB_TOKEN, AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY. Our summary lists: Python 3; A credential in GITHUB_TOKEN; A credential in AWS_SECRET_ACCESS_KEY.
SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Pass CLI is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Pass CLI: Monitor CI (nrwl/nx, 29k stars), Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 36k stars), Vercel Optimize Audit (vercel-labs/agent-skills, 32k stars) and Analyze GitHub Action Logs (withastro/astro, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
reyamira (a GitHub organization) maintains it in reyamira/pass-cli, which has 114 GitHub stars. The repository was last updated on July 15, 2026.
Source: reyamira/pass-cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.