Agent skill

Sops Encryption

by sickn33 in sickn33/agentic-awesome-skills

Encrypt files and configs with Mozilla SOPS. An agent skill from sickn33/agentic-awesome-skills.

MITAuto-check passedBusiness, Finance & HR

Install Sops Encryption

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill sops-encryption -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills sops-encryption --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/sops-encryption .claude/skills/sops-encryption && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sops-encryption
GitHub stars
47k
Used in
1 other repo
Token cost
~751 tokens
SKILL.md length
132 words
Files
1
Skills in repo
1,394
Repo updated
First seen
Licence
MIT

At a glance

Encrypt files and configs with Mozilla SOPS. An agent skill from sickn33/agentic-awesome-skills.

  • Tasks that involve Operations and SOPs
  • SKILL.md covers When to Use This Skill, Prerequisites, Installation and Basic Usage, plus 5 more sections
  • Calls brew and wget; reaches github.com

What it does

Sops Encryption is an agent skill from sickn33/agentic-awesome-skills. Encrypt files and configs with Mozilla SOPS.

Its SKILL.md is about 750 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not…

It sits in Business, Finance & HR, covering Operations and SOPs. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Tasks that involve Operations and SOPs

Example prompts

  • “/sops-encryption”

Requirements

  • Compatibility (from SKILL.md): Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled.

What it can do on your machine

Read from SKILL.md and the folder at commit 1e53ce2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • brew
    • wget

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled.

    From compatibility in the SKILL.md frontmatter.

Context cost

Sops Encryption loads about 751 tokens when it runs. Until then it costs about 15 tokens; SKILL.md has 132 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~15
When it runs · the whole SKILL.md, loaded when a task matches
~751

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit 1e53ce2, republished under its MIT licence (© sickn33). 132 words, ~751 tokens.

Download SKILL.mdSave it as .claude/skills/sops-encryption/SKILL.md (or your agent's skills folder).
name
sops-encryption
description
Encrypt files and configs with Mozilla SOPS.
compatibility
Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled.
category
security
risk
critical
source
https://github.com/BagelHole/DevOps-Security-Agent-Skills
source_repo
BagelHole/DevOps-Security-Agent-Skills
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/BagelHole/DevOps-Security-Agent-Skills/blob/main/LICENSE
metadata.author
devops-skills
metadata.version
1.0

SOPS Encryption

Encrypt secrets in configuration files while keeping structure visible.

When to Use This Skill

Use this skill when:

  • Encrypting secrets in Git
  • Implementing GitOps with secrets
  • Managing Kubernetes secrets as code
  • Encrypting configuration files

Prerequisites

  • SOPS installed
  • KMS access (AWS, GCP, Azure) or PGP key

Installation

bash
# macOS
brew install sops

# Linux
wget https://github.com/getsops/sops/releases/download/v3.8.0/sops-v3.8.0.linux.amd64
chmod +x sops-v3.8.0.linux.amd64
mv sops-v3.8.0.linux.amd64 /usr/local/bin/sops

Basic Usage

bash
# Encrypt with AWS KMS
sops --encrypt --kms arn:aws:kms:region:account:key/key-id secrets.yaml > secrets.enc.yaml

# Decrypt
sops --decrypt secrets.enc.yaml

# Edit encrypted file
sops secrets.enc.yaml

# Encrypt in place
sops --encrypt --in-place secrets.yaml

Configuration

yaml
# .sops.yaml
creation_rules:
  - path_regex: .*\.prod\.yaml$
    kms: arn:aws:kms:us-east-1:account:key/prod-key
  - path_regex: .*\.dev\.yaml$
    kms: arn:aws:kms:us-east-1:account:key/dev-key
  - path_regex: .*
    pgp: fingerprint

Kubernetes Integration

yaml
# encrypted secret
apiVersion: v1
kind: Secret
metadata:
  name: myapp-secrets
type: Opaque
stringData:
  password: ENC[AES256_GCM,data:encrypted...]
sops:
  kms:
    - arn: arn:aws:kms:region:account:key/key-id
bash
# With ArgoCD
# Install ksops plugin for ArgoCD to decrypt secrets

Best Practices

  • Store .sops.yaml in repository
  • Use different keys per environment
  • Rotate encryption keys regularly
  • Never commit unencrypted secrets
  • Use key aliases for readability
  • hashicorp-vault (hashicorp-vault) - Centralized secrets
  • argocd-gitops (argocd-gitops) - GitOps integration

Limitations

  • Apply guidance only within authorized scope; test destructive steps in non-production first.
  • Docs-only import: upstream scripts and templates not bundled.
Example
bash
# Read-only first: inventory before any active step.
which <tool> && <tool> --help | head -n 20

Adapted from BagelHole/DevOps-Security-Agent-Skills (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: helper scripts and templates not bundled.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/sops-encryption of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit 1e53ce2

Used in 1 other repository

We found 5 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Sops Encryption next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sops Encryption compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sops Encryption this skillsickn33/agentic-awesome-skills47k1 repos~751Automated safety check: PassMIT
Capacity Plannerborghei/Claude-Skills874—~3kAutomated safety check: PassMIT
Cc Sdd New Agentgotalab/cc-sdd3.7k—~1.1kAutomated safety check: PassMIT
DBS Business Toolkit Entrydontbesilent2025/dbskill10k—~1.9kAutomated safety check: PassCustom licence
Agent Sop Authorstrands-agents/agent-sop1.2k—~3.5kAutomated safety check: PassApache-2.0
Diffusion Narrative Denouncingcanwhite/Krebs1k—~831Automated safety check: PassMIT

Similar skills

  • Capacity Planner

    borghei/Claude-Skills

    Headcount and delivery-capacity planning — effective capacity from raw headcount, hire/contract/defer scenarios, and capacity-vs-commitment gap reports.

    874 GitHub stars~3k tokensUpdated yesterday
    Business, Finance & HRAuto-check passed
  • Cc Sdd New Agent

    gotalab/cc-sdd

    Add or extend coding-agent support in cc-sdd by executing the SOP in docs/cc-sdd/sop-new-agent.md end-to-end.

    3.7k GitHub stars~1.1k tokensUpdated 14 days ago
    Business, Finance & HRAuto-check passed
  • DBS Business Toolkit Entry

    dontbesilent2025/dbskill

    Chinese-language entry skill for the dontbesilent business toolkit: onboards new users, orchestrates tasks across sub-skills, runs numbered prompts and lists hidden ones.

    10k GitHub stars~1.9k tokensUpdated 9 days ago
    Business, Finance & HRAuto-check passed
  • Agent Sop Author

    strands-agents/agent-sop

    Create (or update) and validate Agent SOPs (Standard Operating Procedures) - markdown-based workflows that guide AI agents through complex, multi-step tasks with RFC 2119 constraints.

    1.2k GitHub stars~3.5k tokensUpdated 16 days ago
    Business, Finance & HRAuto-check passed
  • 基于"扩散模型叙事去噪流"的小说写作 SOP。将 AI 视为去杂质机器,通过锁定全局信号、预测叙事噪声、精准去噪、随机修正四个步骤,解决 AI 翻译腔、逻辑断层和故事平淡的问题。

    1k GitHub stars~831 tokensUpdated 1 mo ago
    Business, Finance & HRAuto-check passed
  • Polanyi Perspective

    0xenzyme/polanyi-skill

    Michael Polanyi 的思维框架。用 Polanyi 视角分析隐性知识、技能习得、经验传承、师徒制、 知识管理、学习方法、AI/工具替代边界、科学共同体与后批判哲学问题。

    137 GitHub stars~1.3k tokensUpdated 3 mo ago
    Business, Finance & HRAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,394 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Questions about Sops Encryption

What does Sops Encryption do?

Encrypt files and configs with Mozilla SOPS. An agent skill from sickn33/agentic-awesome-skills. Sops Encryption is an agent skill from sickn33/agentic-awesome-skills. Encrypt files and configs with Mozilla SOPS.

When should I use Sops Encryption?

Sops Encryption fits situations like: tasks that involve Operations and SOPs.

How do I install Sops Encryption in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill sops-encryption -a claude-code`. Or copy the skill folder (skills/sops-encryption in sickn33/agentic-awesome-skills) into .claude/skills/sops-encryption in your project. Claude Code loads it when a task matches its description.

How do I install Sops Encryption in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill sops-encryption -a codex`. Or copy the skill folder (skills/sops-encryption in sickn33/agentic-awesome-skills) into .agents/skills/sops-encryption in your project. Codex loads it when a task matches its description.

Can I use Sops Encryption in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill sops-encryption -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sops-encryption, .gemini/skills/sops-encryption, .github/skills/sops-encryption and .opencode/skills/sops-encryption in your project.

What does Sops Encryption need to run?

Going by SKILL.md and its folder, Sops Encryption needs the command-line tools its instructions call (brew and wget). Compatibility (from SKILL.md): Requires the relevant security tooling (scanners, vault CLIs) and an authorized scope for any active assessment. Docs-only; helper scripts and templates not bundled..

Does Sops Encryption access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Sops Encryption safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sops Encryption use?

Sops Encryption is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sops Encryption use?

About 751 tokens (SKILL.md is roughly 3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sops Encryption?

Skills that share tags, products or a category with Sops Encryption: Capacity Planner (borghei/Claude-Skills, 874 stars), Cc Sdd New Agent (gotalab/cc-sdd, 3.7k stars), DBS Business Toolkit Entry (dontbesilent2025/dbskill, 10k stars) and Agent Sop Author (strands-agents/agent-sop, 1.2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sops Encryption?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,304 GitHub stars. The repository holds 1,394 skills in this directory. The repository was last updated on October 6, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.