Agent skill

Op Session

by sd0xdev in sd0xdev/sd0x-harness

Initialize 1Password CLI session for Claude Code. An agent skill from sd0xdev/sd0x-harness.

MITAuto-check passedDevelopment

Install Op Session

skills CLI
$ npx skills add sd0xdev/sd0x-harness --skill op-session -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sd0xdev/sd0x-harness op-session --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sd0xdev/sd0x-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/op-session .claude/skills/op-session && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
op-session
GitHub stars
192
Token cost
~1.3k tokens
SKILL.md length
410 words
Files
3 (incl. scripts)
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Initialize 1Password CLI session for Claude Code. An agent skill from sd0xdev/sd0x-harness.

  • : starting a session that needs 1Password secrets
  • SKILL.md covers Problem, Solution, Workflow and Usage, plus 5 more sections
  • Runs Shell scripts from its folder; calls bash
  • Op CLI keeps prompting biometric auth

What it does

Op Session is an agent skill from sd0xdev/sd0x-harness. Initialize 1Password CLI session for Claude Code. Use when: starting a session that needs 1Password secrets, op CLI keeps prompting biometric auth, setting up OPSESSION token. Solves: Claude Code's no-TTY subprocess model triggers 1Password biometric auth on every op call. Supports both token-based and App Integration auth modes — auto-detects which mode to use.

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including scripts (for example `scripts/op-session-init.sh` and `scripts/op-with-session.sh`).

It sits in Development. The repository describes itself as: The harness layer for Claude Code — a reference implementation of harness engineering with hook-enforced dual review, state-machine gates that survive context compaction, and… The licence is MIT.

When your agent uses it

  • : starting a session that needs 1Password secrets
  • Op CLI keeps prompting biometric auth
  • Setting up OPSESSION token
  • 1Password biometric auth on every op call

Example prompts

  • “/op-session”

Requirements

  • A Bash shell
  • Pre-approved tools (allowed-tools): Bash(bash:*)

What it can do on your machine

Read from SKILL.md and the folder at commit c9a2036. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(bash:*)

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Op Session loads about 1.3k tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 410 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from sd0xdev/sd0x-harness at commit c9a2036, republished under its MIT licence (© sd0xdev). 410 words, ~1,262 tokens.

Download SKILL.mdSave it as .claude/skills/op-session/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
op-session
description
Initialize 1Password CLI session for Claude Code. Use when: starting a session that needs 1Password secrets, op CLI keeps prompting biometric auth, setting up OP_SESSION token. Solves: Claude Code's no-TTY subprocess model triggers 1Password biometric auth on every op call. Supports both token-based and App Integration auth modes — auto-detects which mode to use.
allowed-tools
Bash(bash:*)

1Password Session for Claude Code

Problem

Claude Code executes each Bash tool call in a new subprocess without TTY. 1Password CLI's app integration binds auth to the terminal session, so every op call triggers a biometric prompt.

Solution

Auto-detect the auth mode and configure accordingly:

ModeConditionBehavior
Tokenop signin --raw returns a tokenCache token in ~/.op-claude-session; wrapper passes --session flag
App Integrationop signin --raw returns empty + op whoami succeedsRecord mode in session file; wrapper calls op directly (IPC with desktop app)

Workflow

/op-session [--account <name>]
     │
     ▼
 op signin --raw
     │
     ├─ token non-empty ──► Token mode
     │                       Verify → write session file → done
     │
     └─ token empty ──► op whoami succeeds?
                          ├─ YES → App Integration mode
                          │        Write session file (no token) → done
                          └─ NO  → ERROR: signin failed

Usage

Initialize Session
bash
bash skills/op-session/scripts/op-session-init.sh
# or with specific account
bash skills/op-session/scripts/op-session-init.sh --account my-team
List Available Accounts
bash
bash skills/op-session/scripts/op-session-init.sh --list
Check Session Status
bash
bash skills/op-session/scripts/op-session-init.sh --check
Clear Session
bash
bash skills/op-session/scripts/op-session-init.sh --clear

Use the secure helper script — it handles mode detection, token loading, validation, and expiry:

bash
bash skills/op-session/scripts/op-with-session.sh read "op://vault/item/field"
bash skills/op-session/scripts/op-with-session.sh item list --vault Production
bash skills/op-session/scripts/op-with-session.sh whoami

The helper:

  • Auto-detects auth mode from session file (OP_AUTH_MODE)
  • Token mode: passes --session and --account flags
  • App mode: passes only --account flag (auth via desktop app IPC)
  • Validates session before each call
  • Returns clear error if session is missing, expired, or app is locked

Session Lifecycle

EventToken ModeApp Integration Mode
Idle timeout30 min → expires10 min → expires (auto-refresh on use)
Each op callResets idle timerResets idle timer
Hard limit12hr12hr
1Password app locksDoes NOT revoke tokenNext op call fails until unlocked
/op-session --clearRemoves session fileRemoves session file

Session File Format

bash
# Token mode
export OP_AUTH_MODE='token'
export OP_SESSION='<session-token>'
export OP_ACCOUNT='<account-id>'

# App Integration mode
export OP_AUTH_MODE='app'
export OP_SESSION=''
export OP_ACCOUNT='<account-id>'

Legacy session files (without OP_AUTH_MODE) are auto-detected as token mode if OP_SESSION is non-empty.

Show full SKILL.md (180 more words)Show less

Security

AspectToken ModeApp Integration Mode
Token at rest~/.op-claude-session (owner-only via umask 077)No token stored
Process args--session $TOKEN visible to same-user processesNo --session flag
Auth controlToken possession = accessDesktop app biometric
ScopeAll vaults you can accessAll vaults you can access
Risk levelModerate (token on disk)Lower (no token on disk)
MitigationShort-lived token, --clear when doneApp auto-manages session

Known Limitations

LimitationCauseWorkaround
ls on home-dir paths blocked in ! context checksClaude Code sandbox may restrict ls/find to working directory in command template expansionUse test -f via bash -c wrapper; see skills/op-session/SKILL.md
allowed-tools cannot be narrowed to specific script paths${CLAUDE_PLUGIN_ROOT} unavailable in command markdown (#9354)Keep Bash(bash:*) until upstream fix
Context check is best-effort UISandbox policy may tightenAuthoritative status via bash skills/op-session/scripts/op-session-init.sh --check
App mode fails when desktop app is lockedCLI cannot IPC with locked appUnlock 1Password app, or run /op-session to reinitialize

Prerequisites

  • 1Password CLI (op) installed and configured
  • 1Password desktop app running (for initial biometric auth)
  • Account signed in to 1Password app

© sd0xdev, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in skills/op-session of sd0xdev/sd0x-harness.

  • SKILL.md
  • scripts/op-session-init.sh
  • scripts/op-with-session.sh

Open the folder on GitHubat commit c9a2036

Compare with similar skills

Op Session next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Op Session compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Op Session this skillsd0xdev/sd0x-harness192—~1.3kAutomated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k24 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Greplooponyx-dot-app/onyx32k4 repos~3.3kAutomated safety check: PassMIT

Similar skills

  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 24 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed
  • Guidelines

    akash-network/node

    Behavioral guidelines to reduce common LLM coding mistakes. An agent skill from akash-network/node.

    1.1k GitHub starsUsed in 22 repos~577 tokens
    DevelopmentAuto-check passed

More from sd0xdev/sd0x-harness

All 91 skills in this repo
  • Adr

    sd0xdev/sd0x-harness

    Write an Architecture Decision Record (ADR) for a feature — Context / Decision / Status / Consequences / Alternatives, filed as docs/features/<feature/adr-<NNN-<title.md with a 3-digit zero-padded…

    192 GitHub stars~4.8k tokensUpdated yesterday
    Auto-check passed
  • Load PR Review

    sd0xdev/sd0x-harness

    Load GitHub PR review comments into AI session — analyze, triage, plan.

    192 GitHub stars~4.4k tokensUpdated yesterday
    Auto-check passed
  • Next Step

    sd0xdev/sd0x-harness

    Change-aware next step advisor. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.6k tokensUpdated yesterday
    Auto-check passed
  • Obsidian CLI

    sd0xdev/sd0x-harness

    Obsidian vault integration via official CLI. An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check passed
  • Orchestrate

    sd0xdev/sd0x-harness

    Agent-driven workflow orchestration (v1 report-only). An agent skill from sd0xdev/sd0x-harness.

    192 GitHub stars~2.5k tokensUpdated yesterday
    Auto-check passed
  • PR Comment

    sd0xdev/sd0x-harness

    Post friendly review comments to a GitHub PR — prepare locally, preview, then submit as atomic review.

    192 GitHub stars~1.5k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Op Session

What does Op Session do?

Initialize 1Password CLI session for Claude Code. An agent skill from sd0xdev/sd0x-harness. Op Session is an agent skill from sd0xdev/sd0x-harness. Initialize 1Password CLI session for Claude Code.

When should I use Op Session?

Op Session fits situations like: : starting a session that needs 1Password secrets; op CLI keeps prompting biometric auth; setting up OPSESSION token; 1Password biometric auth on every op call.

How do I install Op Session in Claude Code?

Run `npx skills add sd0xdev/sd0x-harness --skill op-session -a claude-code`. Or copy the skill folder (skills/op-session in sd0xdev/sd0x-harness) into .claude/skills/op-session in your project. Claude Code loads it when a task matches its description.

How do I install Op Session in Codex?

Run `npx skills add sd0xdev/sd0x-harness --skill op-session -a codex`. Or copy the skill folder (skills/op-session in sd0xdev/sd0x-harness) into .agents/skills/op-session in your project. Codex loads it when a task matches its description.

Can I use Op Session in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sd0xdev/sd0x-harness --skill op-session -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/op-session, .gemini/skills/op-session, .github/skills/op-session and .opencode/skills/op-session in your project.

What does Op Session need to run?

Going by SKILL.md and its folder, Op Session needs a shell for the scripts in its folder and the command-line tools its instructions call (bash). Our summary lists: A Bash shell. Its frontmatter pre-approves these tools: Bash(bash:*).

Does Op Session access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Op Session safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Op Session use?

Op Session is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Op Session use?

About 1.3k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Op Session?

Skills that share tags, products or a category with Op Session: Finishing a Development Branch (obra/superpowers, 296k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars), PR Babysitter (openinterpreter/openinterpreter, 69k stars) and Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Op Session?

sd0xdev (a GitHub user) maintains it in sd0xdev/sd0x-harness, which has 192 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 6, 2026.

Source: sd0xdev/sd0x-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.