Kingdee MCP Dev
WaHaiLong/KingdeeMCP
Knowledge base for the Kingdee MCP Dev Squad. An agent skill from WaHaiLong/KingdeeMCP.
A skill your agent uses when adding, changing, reading or rotating a secret in infra/sops/secrets.env.sops, adding an age recipient, or when sops reports "Error unmarshalling input json", "Config…
$ npx skills add VeriTeknik/pluggedin-app --skill sops-secrets -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install VeriTeknik/pluggedin-app sops-secrets --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/VeriTeknik/pluggedin-app.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/sops-secrets .claude/skills/sops-secrets && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "sops-secrets" agent skill from https://github.com/VeriTeknik/pluggedin-app/tree/main/.claude/skills/sops-secrets into .claude/skills/sops-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sops-secrets", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/VeriTeknik/pluggedin-app/tree/main/.claude/skills/sops-secretsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add VeriTeknik/pluggedin-app --skill sops-secrets -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install VeriTeknik/pluggedin-app sops-secrets --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/VeriTeknik/pluggedin-app.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/sops-secrets .agents/skills/sops-secrets && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "sops-secrets" agent skill from https://github.com/VeriTeknik/pluggedin-app/tree/main/.claude/skills/sops-secrets into .agents/skills/sops-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sops-secrets", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add VeriTeknik/pluggedin-app --skill sops-secrets -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install VeriTeknik/pluggedin-app sops-secrets --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/VeriTeknik/pluggedin-app.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/sops-secrets .cursor/skills/sops-secrets && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "sops-secrets" agent skill from https://github.com/VeriTeknik/pluggedin-app/tree/main/.claude/skills/sops-secrets into .cursor/skills/sops-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sops-secrets", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/VeriTeknik/pluggedin-app.git --path .claude/skills/sops-secrets--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add VeriTeknik/pluggedin-app --skill sops-secrets -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install VeriTeknik/pluggedin-app sops-secrets --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/VeriTeknik/pluggedin-app.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/sops-secrets .gemini/skills/sops-secrets && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "sops-secrets" agent skill from https://github.com/VeriTeknik/pluggedin-app/tree/main/.claude/skills/sops-secrets into .gemini/skills/sops-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sops-secrets", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install VeriTeknik/pluggedin-app sops-secretsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add VeriTeknik/pluggedin-app --skill sops-secrets -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/VeriTeknik/pluggedin-app.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/sops-secrets .github/skills/sops-secrets && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "sops-secrets" agent skill from https://github.com/VeriTeknik/pluggedin-app/tree/main/.claude/skills/sops-secrets into .github/skills/sops-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sops-secrets", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add VeriTeknik/pluggedin-app --skill sops-secrets -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install VeriTeknik/pluggedin-app sops-secrets --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/VeriTeknik/pluggedin-app.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/sops-secrets .opencode/skills/sops-secrets && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "sops-secrets" agent skill from https://github.com/VeriTeknik/pluggedin-app/tree/main/.claude/skills/sops-secrets into .opencode/skills/sops-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "sops-secrets", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
sops-secretsA skill your agent uses when adding, changing, reading or rotating a secret in infra/sops/secrets.env.sops, adding an age recipient, or when sops reports "Error unmarshalling input json", "Config…
Sops Secrets is an agent skill from VeriTeknik/pluggedin-app. Use when adding, changing, reading or rotating a secret in infra/sops/secrets.env.sops, adding an age recipient, or when sops reports "Error unmarshalling input json", "Config file not found", or "no matching creation rules found" in this repo.
Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Business, Finance & HR, covering Operations and SOPs and MCP servers. It works with Model Context Protocol. The repository describes itself as: The Crossroads for AI Data Exchanges. A unified, self-hostable web interface for discovering, configuring, and managing Model Context Protocol (MCP) servers—bringing together AI… The licence is MIT.
Read from SKILL.md and the folder at commit a65f1ff. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Sops Secrets loads about 1.4k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 656 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from VeriTeknik/pluggedin-app at commit a65f1ff, republished under its MIT licence (© VeriTeknik). 656 words, ~1,427 tokens.
.claude/skills/sops-secrets/SKILL.md (or your agent's skills folder).All production secrets live encrypted in infra/sops/secrets.env.sops, age-encrypted
and committed to a public repo. deploy.sh decrypts them to tmpfs at deploy time.
Core rule: every sops command on this file needs explicit dotenv types. The
filename ends .sops, which sops does not recognise, so it falls back to JSON and
dies on the first # comment:
Error unmarshalling input json: invalid character '#' looking for beginning of valueSeeing that error means you forgot --input-type dotenv --output-type dotenv.
| Task | Command |
|---|---|
| Read a value | sops -d --input-type dotenv --output-type dotenv infra/sops/secrets.env.sops | grep '^KEY=' |
| Add / change a secret | sops --input-type dotenv --output-type dotenv infra/sops/secrets.env.sops |
| Add an age recipient | decrypt → re-encrypt, see below |
| Apply to production | ./infra/scripts/deploy.sh — required, see below |
Always export SOPS_AGE_KEY_FILE=/etc/sops/age/keys.txt first.
export SOPS_AGE_KEY_FILE=/etc/sops/age/keys.txt
sops --input-type dotenv --output-type dotenv infra/sops/secrets.env.sops
# $EDITOR opens the decrypted content; add KEY=value; save
git commit -am "ops: add KEY"
./infra/scripts/deploy.shThe deploy is not optional. deploy.sh is what decrypts the blob to
/run/sops/secrets.env, which containers mount. Editing the blob without deploying
changes nothing that is running, and the next unrelated deploy will silently pick the
change up — which is how a config change gets blamed on the wrong commit.
Write values literally — no escaping of any kind. Nothing between sops and the
process interpolates: the app parses the mounted file with dotenv and Postgres reads a
*_FILE. A $ you double becomes a literal $$.
(Historical note, because the reverse used to be true: while services used
env_file:, Compose interpolated it and truncated values at the first $, so
deploy.sh doubled them. That step was removed when secrets moved out of the
environment — keeping it would have corrupted exactly the bcrypt-shaped secrets it
was added to protect.)
If the new secret is consumed via *_FILE indirection rather than by the app
(as Traefik's dashboard auth and the Postgres password are), add an extract_secret
line to deploy.sh too — otherwise the file it points at never appears and the
consumer fails closed.
Add the public key to the age: list in .sops.yaml at the repo root, then
re-wrap the data key from the repo root:
export SOPS_AGE_KEY_FILE=/etc/sops/age/keys.txt
sops updatekeys --input-type dotenv -y infra/sops/secrets.env.sops--input-type dotenv is required here as everywhere else. Verify with the negative
test below before committing.
.sops.yaml must stay at the repo root. sops searches upward from the working
directory and matches path_regex against the path as given, so with the config
inside infra/sops/ neither location worked — the repo root gave Config file not found, and running from inside the directory found the config but matched a bare
filename and gave no matching creation rules found.
sops falls back to the default keyring at ~/.config/sops/age/keys.txt. If a copy of
the deploy key is there, every decryption test passes, including with a key that is
not a recipient at all — a stranger key appearing to read 91 secrets is that false
positive, not a breach. That copy has since been removed from this host, but isolate
HOME anyway: the test should not depend on a file's continued absence.
EMPTY=$(mktemp -d)
# must succeed
HOME="$EMPTY" SOPS_AGE_KEY_FILE=/etc/sops/age/keys.txt \
sops -d --input-type dotenv --output-type dotenv infra/sops/secrets.env.sops | grep -c '^[A-Z_0-9]*='
# must print 0 and "none were successful"
HOME="$EMPTY" SOPS_AGE_KEY_FILE=/path/to/non-recipient.txt \
sops -d --input-type dotenv --output-type dotenv infra/sops/secrets.env.sopsAlways include the negative case. A test that only checks the happy path cannot tell "the key works" from "the keyring rescued me".
Only values are encrypted. Key names are plaintext in the committed file —
grep GITHUB infra/sops/secrets.env.sops reveals which integrations exist. Never
encode anything sensitive in a variable name.
The repo is public and git history is append-only: once pushed, that ciphertext is public permanently, and the age private key is the only thing protecting it. Rotating a secret later protects you from that point forward; it does not unpublish the old blob.
docs/ops/docker-traefik-sops-migration.md.| Mistake | Result |
|---|---|
Omitting --input-type dotenv | Error unmarshalling input json |
Editing the blob without deploy.sh | Running containers keep the old value |
Pre-escaping $ in a value | Doubled twice, value corrupted |
Testing decryption without isolating HOME | False pass — the default keyring answers |
Adding a *_FILE secret without touching deploy.sh | Consumer fails closed |
© VeriTeknik, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/sops-secrets of VeriTeknik/pluggedin-app.
Open the folder on GitHubat commit a65f1ff
Sops Secrets next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Sops Secrets this skillVeriTeknik/pluggedin-app | 103 | — | ~1.4k | Automated safety check: Pass | MIT | |
| Kingdee MCP DevWaHaiLong/KingdeeMCP | 105 | — | ~853 | Automated safety check: Pass | MIT | |
| Polymarket Tennislivetennisapi/livetennisapi-mcp | 152 | — | ~3k | Automated safety check: Pass | MIT | |
| Odoo Agency Fleet Reviewerpipe-org/mcp-odoo | 421 | — | ~699 | Automated safety check: Pass | MIT | |
| Wind MCP SkillWind-Alice/AliceMarket | 130 | 1 repos | ~1.3k | Automated safety check: Pass | None | |
| Helium MCPcomposio-community/awesome-codex-skills | 17k | — | ~599 | Automated safety check: Pass | None |
WaHaiLong/KingdeeMCP
Knowledge base for the Kingdee MCP Dev Squad. An agent skill from WaHaiLong/KingdeeMCP.
livetennisapi/livetennisapi-mcp
Build observe-only Polymarket and Kalshi tennis market tooling on the polymarket-tennis Python package (MIT) plus the Live Tennis API free tier.
erpipe-org/mcp-odoo
Review many client Odoo databases at once through odoo-mcp's cross-instance tools — fleet-wide accounting health, per-client aging, partial-failure triage — for agencies and partners managing 5–50…
Wind-Alice/AliceMarket
用户需要查询、筛选、获取、比较或验证金融市场数据时,优先调用本 Skill 获取可靠、可验证数据,而非仅依赖模型记忆或通用信息来源。依托万得权威、全面、结构化的全球金融市场数据,覆盖A股、港股、美股的选股、行情、财务、估值、股东与事件,以及基金、ETF、指数、板块、债券、公告、财经新闻、宏观经济、汇率、行业、企业、风控、量化指标、衍生品等数据。
composio-community/awesome-codex-skills
Search real-time news with bias scoring, get live stock/ETF/crypto data with AI analysis, ML options pricing, balanced news synthesis, and meme search via the Helium MCP server.
nteract/nteract
Understand the MCP server session lifecycle: attachment ownership, proxy supervision, daemon reconciliation, explicit notebook routing, readiness, scoped subscriptions, rejoin races, and room…
VeriTeknik/pluggedin-app
A skill your agent uses when deploying, restarting, verifying or rolling back the containerised plugged.in production stack, when the site returns 404 or 5xx after a deploy or git operation, or when…
Works with
Categories
A skill your agent uses when adding, changing, reading or rotating a secret in infra/sops/secrets.env.sops, adding an age recipient, or when sops reports "Error unmarshalling input json", "Config…. Sops Secrets is an agent skill from VeriTeknik/pluggedin-app.sops, adding an age recipient, or when sops reports "Error unmarshalling input json", "Config file not found", or "no matching creation rules found" in this repo.
Sops Secrets fits situations like: rotating a secret in infra/sops/secrets.env.sops; adding an age recipient; sops reports Error unmarshalling input json; config file not found.
Run `npx skills add VeriTeknik/pluggedin-app --skill sops-secrets -a claude-code`. Or copy the skill folder (.claude/skills/sops-secrets in VeriTeknik/pluggedin-app) into .claude/skills/sops-secrets in your project. Claude Code loads it when a task matches its description.
Run `npx skills add VeriTeknik/pluggedin-app --skill sops-secrets -a codex`. Or copy the skill folder (.claude/skills/sops-secrets in VeriTeknik/pluggedin-app) into .agents/skills/sops-secrets in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add VeriTeknik/pluggedin-app --skill sops-secrets -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sops-secrets, .gemini/skills/sops-secrets, .github/skills/sops-secrets and .opencode/skills/sops-secrets in your project.
Going by SKILL.md and its folder, Sops Secrets needs the command-line tools its instructions call (git). Our summary lists: Docker.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Sops Secrets is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Sops Secrets: Kingdee MCP Dev (WaHaiLong/KingdeeMCP, 105 stars), Polymarket Tennis (livetennisapi/livetennisapi-mcp, 152 stars), Odoo Agency Fleet Review (erpipe-org/mcp-odoo, 421 stars) and Wind MCP Skill (Wind-Alice/AliceMarket, 130 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
VeriTeknik (a GitHub organization) maintains it in VeriTeknik/pluggedin-app, which has 103 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 6, 2026.
Source: VeriTeknik/pluggedin-app on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.