Agent skill

Pass CLI

by reyamira in reyamira/pass-cli

How an AI agent should safely drive the pass-cli password manager (this repo's binary).

Apache-2.0Auto-check: notesDevOps & Cloud

Install Pass CLI

skills CLI
$ npx skills add reyamira/pass-cli --skill pass-cli -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install reyamira/pass-cli pass-cli --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/reyamira/pass-cli.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/pass-cli .claude/skills/pass-cli && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
pass-cli
GitHub stars
114
Token cost
~1.5k tokens
SKILL.md length
609 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
Apache-2.0

At a glance

How an AI agent should safely drive the pass-cli password manager (this repo's binary).

  • A task needs a stored secret/credential to run a command
  • SKILL.md covers The decision: how do you need…, pass-cli exec — the safe way…, pass-cli list — listing is the… and pass-cli get — last resort,…, plus 1 more section
  • Calls curl; needs GITHUB_TOKEN and AWS_ACCESS_KEY_ID
  • Listing a pass-cli vault

What it does

Pass CLI is an agent skill from reyamira/pass-cli. How an AI agent should safely drive the pass-cli password manager (this repo's binary). Use whenever a task needs a stored secret/credential to run a command, when reading from or listing a pass-cli vault, or when you're about to capture a secret with get/command substitution — there is a safer path. Covers exec (hand a secret to a child process without it ever touching stdout), the safe-by-default list, and the leak traps to avoid.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. The repository describes itself as: A secure, cross-platform, always-free, and open-source alternative to 1password, bitwarden, etc., Password and API key manager for folks who live in the command line. (CLI + TUI). The licence is Apache-2.0.

When your agent uses it

  • A task needs a stored secret/credential to run a command
  • Listing a pass-cli vault
  • Youre about to capture a secret with get/command substitution — there is a safer path

Example prompts

  • “/pass-cli”

Requirements

  • Python 3
  • A credential in GITHUB_TOKEN
  • A credential in AWS_SECRET_ACCESS_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit f42ade3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN
    • AWS_ACCESS_KEY_ID
    • AWS_SECRET_ACCESS_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Pass CLI loads about 1.5k tokens when it runs. Until then it costs about 113 tokens; SKILL.md has 609 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:112
    - Am I writing the secret into a `.env*` or any file a tool watches? → the harness echoes file changes; don't.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from reyamira/pass-cli at commit f42ade3, republished under its Apache-2.0 licence (© reyamira). 609 words, ~1,493 tokens.

Download SKILL.mdSave it as .claude/skills/pass-cli/SKILL.md (or your agent's skills folder).
name
pass-cli
description
How an AI agent should safely drive the pass-cli password manager (this repo's binary). Use whenever a task needs a stored secret/credential to run a command, when reading from or listing a pass-cli vault, or when you're about to capture a secret with `get`/command substitution — there is a safer path. Covers `exec` (hand a secret to a child process without it ever touching stdout), the safe-by-default `list`, and the leak traps to avoid.

Using pass-cli safely as an agent

pass-cli is a local, offline-first password manager. Its vault is a single AES-GCM-encrypted file. As an agent you will mostly need it to give a stored secret to a command you're about to run — and the cardinal rule is:

Never let a secret value land in the transcript, a log, CI output, or any file a tool watches. Once a secret is in the conversation log on disk it is compromised and must be rotated.

The whole point of the commands below is to move a secret from the vault into a child process without it passing through stdout, the clipboard, your shell history, or a set -x trace.

The decision: how do you need the secret?

You need to…UseWhy
Run a command that reads the secret from its environmentpass-cli execSecret goes straight into the child's env; never on stdout
Know which services existpass-cli list -qBare service names; usernames hidden by default
Capture a value into a variable (last resort)pass-cli get … --quiet --no-clipboardOnly if exec truly can't express it; see the trap below

Default to exec. Reach for get only when nothing else works.

pass-cli exec — the safe way to hand a secret to a command

Runs a child command with credentials injected as environment variables. The value is passed only through the child's environment — never a file, the clipboard, or shell history. pass-cli writes nothing of its own to stdout, and the child's exit code is propagated unchanged.

bash
# Explicit mapping (repeatable): --set ENV_NAME=service
pass-cli exec --set GITHUB_TOKEN=github -- gh repo list

# Multiple credentials at once
pass-cli exec --set AWS_ACCESS_KEY_ID=aws-id --set AWS_SECRET_ACCESS_KEY=aws-secret -- aws s3 ls

# Pick a non-password field for ALL mappings with -f/--field
pass-cli exec --set DB_USER=postgres --field username -- ./run-migration.sh

# Per-mapping field with service:field (overrides -f for that one entry)
pass-cli exec --set DB_USER=postgres:username --set DB_PASS=postgres -- ./run-migration.sh

# Convenience form: derive ENV name from the service (openai-api -> OPENAI_API)
pass-cli exec openai-api -- python train.py

Key facts:

  • -- separates pass-cli's flags from the child command. Everything after -- is the child's argv. Omitting it is an error ("no command to run").
  • -f/--field (default password) selects the field for all --set mappings; valid fields: username, password, category, url, notes, service.
  • service:field in a --set overrides -f for that single mapping.
  • Exit code is propagated — pass-cli exec … -- sh -c 'exit 7' exits 7. Safe to use in &&/|| chains and CI gates.
  • exec is read-only: it does NOT record field-access usage and does NOT trigger a sync push, so calling it in a hot loop won't mutate the vault or hit the network on every run.
  • Honest limit: the value lives in the child's environment — readable via /proc/<pid>/environ by the same user and inherited by descendants. This is the same model as op run / aws-vault exec: far safer than files, clipboards, or history, but it is not process isolation.
Show full SKILL.md (207 more words)Show less

pass-cli list — listing is the safe step

bash
pass-cli list            # default table: NO username column (usernames can be sensitive)
pass-cli list -q         # bare service names, one per line — ideal for agents/scripts
pass-cli list --show-usernames   # opt the username column back in (only if you need it)
pass-cli list --format json      # full metadata incl. usernames — explicit, structured opt-in

Usernames are hidden by default because that field often holds sensitive values (card/account/routing numbers stored as an entry's "username"). Use pass-cli list -q to discover service names without dumping anything sensitive.

pass-cli get — last resort, and the trap

bash
pass-cli get github --quiet --no-clipboard --field password

--quiet prints only the field value to stdout; --no-clipboard skips the clipboard. But this still puts the secret on stdout — and the trap is what you do with it next:

bash
# ❌ NEVER — the value is now in the transcript / log
echo "$(pass-cli get github --quiet --no-clipboard)"
TOKEN=$(pass-cli get github --quiet --no-clipboard); curl -H "Authorization: $TOKEN" ...
#   ^ if any layer runs `set -x`, or a file-watcher captures the command, the token leaks

# ✅ Prefer exec — the value never becomes a shell variable or a transcript line
pass-cli exec --set TOKEN=github -- curl -H 'Authorization: Bearer '"$TOKEN" ...
#   (the child reads $TOKEN from its own env; pass-cli printed nothing)

If you genuinely must capture into a variable (a tool with no env-var path), pipe it directly into the consumer in the same command, never echo it, and never enable shell tracing in that shell.

Leak-trap checklist (before you run anything)

  • Am I about to echo/print a secret, or interpolate it into a logged command? → use exec.
  • Is set -x / xtrace active in this shell? → a get/substitution will dump the value. Disable it or use exec.
  • Am I writing the secret into a .env* or any file a tool watches? → the harness echoes file changes; don't.
  • Do I just need to see what's stored? → pass-cli list -q (names only).

If a secret value ever does reach the transcript: tell the user immediately so they can rotate it. The leak cannot be undone.

© reyamira, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/pass-cli of reyamira/pass-cli.

Open the folder on GitHubat commit f42ade3

Compare with similar skills

Pass CLI next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Pass CLI compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Pass CLI this skillreyamira/pass-cli114—~1.5kAutomated safety check: NotesApache-2.0
Monitor CInrwl/nx29k6 repos~4.7kAutomated safety check: PassMIT
Terraform and OpenTofu Guideagentscope-ai/QwenPaw36k6 repos~4.2kAutomated safety check: PassApache-2.0
Vercel Optimize Auditvercel-labs/agent-skills32k8 repos~4.3kAutomated safety check: PassNone
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence
Openclaw Live Updateropenclaw/openclaw392k—~3.7kAutomated safety check: PassMIT

Similar skills

  • Monitor CI

    nrwl/nx

    Monitor Nx Cloud CI pipeline and handle self-healing fixes. An agent skill from nrwl/nx.

    29k GitHub starsUsed in 6 repos~4.7k tokens
    DevOps & CloudAuto-check passed
  • Terraform and OpenTofu Guide

    agentscope-ai/QwenPaw

    Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

    36k GitHub starsUsed in 6 repos~4.2k tokens
    DevOps & CloudAuto-check passed
  • Vercel Optimize Audit

    vercel-labs/agent-skills

    Official

    Runs a metrics-first audit of a deployed Vercel project, gating investigations on real signals to produce ranked, citation-backed cost and performance recommendations.

    32k GitHub starsUsed in 8 repos~4.3k tokens
    DevOps & CloudAuto-check passed
  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Docs Learn PR Preview

    netdata/netdata

    Use only when the user explicitly asks to build, run, preview, inspect, or validate learn.netdata.cloud locally using the contents of a PR or documentation branch before merge.

    81k GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed

Categories

Questions about Pass CLI

What does Pass CLI do?

How an AI agent should safely drive the pass-cli password manager (this repo's binary). Pass CLI is an agent skill from reyamira/pass-cli. How an AI agent should safely drive the pass-cli password manager (this repo's binary).

When should I use Pass CLI?

Pass CLI fits situations like: A task needs a stored secret/credential to run a command; listing a pass-cli vault; youre about to capture a secret with get/command substitution — there is a safer path.

How do I install Pass CLI in Claude Code?

Run `npx skills add reyamira/pass-cli --skill pass-cli -a claude-code`. Or copy the skill folder (.claude/skills/pass-cli in reyamira/pass-cli) into .claude/skills/pass-cli in your project. Claude Code loads it when a task matches its description.

How do I install Pass CLI in Codex?

Run `npx skills add reyamira/pass-cli --skill pass-cli -a codex`. Or copy the skill folder (.claude/skills/pass-cli in reyamira/pass-cli) into .agents/skills/pass-cli in your project. Codex loads it when a task matches its description.

Can I use Pass CLI in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add reyamira/pass-cli --skill pass-cli -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/pass-cli, .gemini/skills/pass-cli, .github/skills/pass-cli and .opencode/skills/pass-cli in your project.

What does Pass CLI need to run?

Going by SKILL.md and its folder, Pass CLI needs the command-line tools its instructions call (curl) and credentials named GITHUB_TOKEN, AWS_ACCESS_KEY_ID and AWS_SECRET_ACCESS_KEY. Our summary lists: Python 3; A credential in GITHUB_TOKEN; A credential in AWS_SECRET_ACCESS_KEY.

Does Pass CLI access the network?

SKILL.md contains no URLs. Its commands use curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Pass CLI safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Pass CLI use?

Pass CLI is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Pass CLI use?

About 1.5k tokens (SKILL.md is roughly 6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Pass CLI?

Skills that share tags, products or a category with Pass CLI: Monitor CI (nrwl/nx, 29k stars), Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 36k stars), Vercel Optimize Audit (vercel-labs/agent-skills, 32k stars) and Analyze GitHub Action Logs (withastro/astro, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Pass CLI?

reyamira (a GitHub organization) maintains it in reyamira/pass-cli, which has 114 GitHub stars. The repository was last updated on July 15, 2026.

Source: reyamira/pass-cli on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.