Agent skill

Sops Secrets

by VeriTeknik in VeriTeknik/pluggedin-app

A skill your agent uses when adding, changing, reading or rotating a secret in infra/sops/secrets.env.sops, adding an age recipient, or when sops reports "Error unmarshalling input json", "Config…

MITAuto-check passedBusiness, Finance & HR

Install Sops Secrets

skills CLI
$ npx skills add VeriTeknik/pluggedin-app --skill sops-secrets -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install VeriTeknik/pluggedin-app sops-secrets --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/VeriTeknik/pluggedin-app.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/sops-secrets .claude/skills/sops-secrets && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
sops-secrets
GitHub stars
103
Token cost
~1.4k tokens
SKILL.md length
656 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when adding, changing, reading or rotating a secret in infra/sops/secrets.env.sops, adding an age recipient, or when sops reports "Error unmarshalling input json", "Config…

  • Rotating a secret in infra/sops/secrets.env.sops
  • SKILL.md covers Quick reference, Adding or changing a secret, Adding an age recipient and Verifying who can decrypt —…, plus 3 more sections
  • Calls git
  • Adding an age recipient

What it does

Sops Secrets is an agent skill from VeriTeknik/pluggedin-app. Use when adding, changing, reading or rotating a secret in infra/sops/secrets.env.sops, adding an age recipient, or when sops reports "Error unmarshalling input json", "Config file not found", or "no matching creation rules found" in this repo.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Business, Finance & HR, covering Operations and SOPs and MCP servers. It works with Model Context Protocol. The repository describes itself as: The Crossroads for AI Data Exchanges. A unified, self-hostable web interface for discovering, configuring, and managing Model Context Protocol (MCP) servers—bringing together AI… The licence is MIT.

When your agent uses it

  • Rotating a secret in infra/sops/secrets.env.sops
  • Adding an age recipient
  • Sops reports Error unmarshalling input json
  • Config file not found

Example prompts

  • “Error unmarshalling input json”
  • “Config file not found”
  • “no matching creation rules found”
  • “/sops-secrets”

Requirements

  • Docker

What it can do on your machine

Read from SKILL.md and the folder at commit a65f1ff. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Sops Secrets loads about 1.4k tokens when it runs. Until then it costs about 64 tokens; SKILL.md has 656 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~64
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from VeriTeknik/pluggedin-app at commit a65f1ff, republished under its MIT licence (© VeriTeknik). 656 words, ~1,427 tokens.

Download SKILL.mdSave it as .claude/skills/sops-secrets/SKILL.md (or your agent's skills folder).
name
sops-secrets
description
Use when adding, changing, reading or rotating a secret in infra/sops/secrets.env.sops, adding an age recipient, or when sops reports "Error unmarshalling input json", "Config file not found", or "no matching creation rules found" in this repo.

SOPS secrets for plugged.in

All production secrets live encrypted in infra/sops/secrets.env.sops, age-encrypted and committed to a public repo. deploy.sh decrypts them to tmpfs at deploy time.

Core rule: every sops command on this file needs explicit dotenv types. The filename ends .sops, which sops does not recognise, so it falls back to JSON and dies on the first # comment:

Error unmarshalling input json: invalid character '#' looking for beginning of value

Seeing that error means you forgot --input-type dotenv --output-type dotenv.

Quick reference

TaskCommand
Read a valuesops -d --input-type dotenv --output-type dotenv infra/sops/secrets.env.sops | grep '^KEY='
Add / change a secretsops --input-type dotenv --output-type dotenv infra/sops/secrets.env.sops
Add an age recipientdecrypt → re-encrypt, see below
Apply to production./infra/scripts/deploy.sh — required, see below

Always export SOPS_AGE_KEY_FILE=/etc/sops/age/keys.txt first.

Adding or changing a secret

bash
export SOPS_AGE_KEY_FILE=/etc/sops/age/keys.txt
sops --input-type dotenv --output-type dotenv infra/sops/secrets.env.sops
# $EDITOR opens the decrypted content; add KEY=value; save
git commit -am "ops: add KEY"
./infra/scripts/deploy.sh

The deploy is not optional. deploy.sh is what decrypts the blob to /run/sops/secrets.env, which containers mount. Editing the blob without deploying changes nothing that is running, and the next unrelated deploy will silently pick the change up — which is how a config change gets blamed on the wrong commit.

Write values literally — no escaping of any kind. Nothing between sops and the process interpolates: the app parses the mounted file with dotenv and Postgres reads a *_FILE. A $ you double becomes a literal $$.

(Historical note, because the reverse used to be true: while services used env_file:, Compose interpolated it and truncated values at the first $, so deploy.sh doubled them. That step was removed when secrets moved out of the environment — keeping it would have corrupted exactly the bcrypt-shaped secrets it was added to protect.)

If the new secret is consumed via *_FILE indirection rather than by the app (as Traefik's dashboard auth and the Postgres password are), add an extract_secret line to deploy.sh too — otherwise the file it points at never appears and the consumer fails closed.

Adding an age recipient

Add the public key to the age: list in .sops.yaml at the repo root, then re-wrap the data key from the repo root:

bash
export SOPS_AGE_KEY_FILE=/etc/sops/age/keys.txt
sops updatekeys --input-type dotenv -y infra/sops/secrets.env.sops

--input-type dotenv is required here as everywhere else. Verify with the negative test below before committing.

.sops.yaml must stay at the repo root. sops searches upward from the working directory and matches path_regex against the path as given, so with the config inside infra/sops/ neither location worked — the repo root gave Config file not found, and running from inside the directory found the config but matched a bare filename and gave no matching creation rules found.

Show full SKILL.md (257 more words)Show less

Verifying who can decrypt — isolate HOME or the test lies

sops falls back to the default keyring at ~/.config/sops/age/keys.txt. If a copy of the deploy key is there, every decryption test passes, including with a key that is not a recipient at all — a stranger key appearing to read 91 secrets is that false positive, not a breach. That copy has since been removed from this host, but isolate HOME anyway: the test should not depend on a file's continued absence.

bash
EMPTY=$(mktemp -d)
# must succeed
HOME="$EMPTY" SOPS_AGE_KEY_FILE=/etc/sops/age/keys.txt \
  sops -d --input-type dotenv --output-type dotenv infra/sops/secrets.env.sops | grep -c '^[A-Z_0-9]*='
# must print 0 and "none were successful"
HOME="$EMPTY" SOPS_AGE_KEY_FILE=/path/to/non-recipient.txt \
  sops -d --input-type dotenv --output-type dotenv infra/sops/secrets.env.sops

Always include the negative case. A test that only checks the happy path cannot tell "the key works" from "the keyring rescued me".

What is and is not protected

Only values are encrypted. Key names are plaintext in the committed file — grep GITHUB infra/sops/secrets.env.sops reveals which integrations exist. Never encode anything sensitive in a variable name.

The repo is public and git history is append-only: once pushed, that ciphertext is public permanently, and the age private key is the only thing protecting it. Rotating a secret later protects you from that point forward; it does not unpublish the old blob.

Known issues

  • Third-party credentials in the blob are un-rotated (provider API keys, OAuth client secrets, GitHub tokens, SMTP, k8s) — a deliberate deferral, tracked in docs/ops/docker-traefik-sops-migration.md.

Common mistakes

MistakeResult
Omitting --input-type dotenvError unmarshalling input json
Editing the blob without deploy.shRunning containers keep the old value
Pre-escaping $ in a valueDoubled twice, value corrupted
Testing decryption without isolating HOMEFalse pass — the default keyring answers
Adding a *_FILE secret without touching deploy.shConsumer fails closed

© VeriTeknik, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/sops-secrets of VeriTeknik/pluggedin-app.

Open the folder on GitHubat commit a65f1ff

Compare with similar skills

Sops Secrets next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Sops Secrets compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Sops Secrets this skillVeriTeknik/pluggedin-app103—~1.4kAutomated safety check: PassMIT
Kingdee MCP DevWaHaiLong/KingdeeMCP105—~853Automated safety check: PassMIT
Polymarket Tennislivetennisapi/livetennisapi-mcp152—~3kAutomated safety check: PassMIT
Odoo Agency Fleet Reviewerpipe-org/mcp-odoo421—~699Automated safety check: PassMIT
Wind MCP SkillWind-Alice/AliceMarket1301 repos~1.3kAutomated safety check: PassNone
Helium MCPcomposio-community/awesome-codex-skills17k—~599Automated safety check: PassNone

Similar skills

  • Kingdee MCP Dev

    WaHaiLong/KingdeeMCP

    Knowledge base for the Kingdee MCP Dev Squad. An agent skill from WaHaiLong/KingdeeMCP.

    105 GitHub stars~853 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Polymarket Tennis

    livetennisapi/livetennisapi-mcp

    Build observe-only Polymarket and Kalshi tennis market tooling on the polymarket-tennis Python package (MIT) plus the Live Tennis API free tier.

    152 GitHub stars~3k tokensUpdated 2 days ago
    Business, Finance & HRAuto-check passed
  • Odoo Agency Fleet Review

    erpipe-org/mcp-odoo

    Review many client Odoo databases at once through odoo-mcp's cross-instance tools — fleet-wide accounting health, per-client aging, partial-failure triage — for agencies and partners managing 5–50…

    421 GitHub stars~699 tokensUpdated 1 mo ago
    Business, Finance & HRAuto-check passed
  • Wind MCP Skill

    Wind-Alice/AliceMarket

    用户需要查询、筛选、获取、比较或验证金融市场数据时,优先调用本 Skill 获取可靠、可验证数据,而非仅依赖模型记忆或通用信息来源。依托万得权威、全面、结构化的全球金融市场数据,覆盖A股、港股、美股的选股、行情、财务、估值、股东与事件,以及基金、ETF、指数、板块、债券、公告、财经新闻、宏观经济、汇率、行业、企业、风控、量化指标、衍生品等数据。

    130 GitHub starsUsed in 1 repo~1.3k tokens
    Business, Finance & HRAuto-check passed
  • Helium MCP

    composio-community/awesome-codex-skills

    Search real-time news with bias scoring, get live stock/ETF/crypto data with AI analysis, ML options pricing, balanced news synthesis, and meme search via the Helium MCP server.

    17k GitHub stars~599 tokensUpdated 2 mo ago
    Business, Finance & HRAuto-check passed
  • MCP Session Lifecycle

    nteract/nteract

    Understand the MCP server session lifecycle: attachment ownership, proxy supervision, daemon reconciliation, explicit notebook routing, readiness, scoped subscriptions, rejoin races, and room…

    179 GitHub stars~2.9k tokensUpdated today
    Business, Finance & HRAuto-check passed

More from VeriTeknik/pluggedin-app

  • Pluggedin Stack Ops

    VeriTeknik/pluggedin-app

    A skill your agent uses when deploying, restarting, verifying or rolling back the containerised plugged.in production stack, when the site returns 404 or 5xx after a deploy or git operation, or when…

    103 GitHub stars~1.3k tokensUpdated 2 days ago
    Auto-check: notes

Questions about Sops Secrets

What does Sops Secrets do?

A skill your agent uses when adding, changing, reading or rotating a secret in infra/sops/secrets.env.sops, adding an age recipient, or when sops reports "Error unmarshalling input json", "Config…. Sops Secrets is an agent skill from VeriTeknik/pluggedin-app.sops, adding an age recipient, or when sops reports "Error unmarshalling input json", "Config file not found", or "no matching creation rules found" in this repo.

When should I use Sops Secrets?

Sops Secrets fits situations like: rotating a secret in infra/sops/secrets.env.sops; adding an age recipient; sops reports Error unmarshalling input json; config file not found.

How do I install Sops Secrets in Claude Code?

Run `npx skills add VeriTeknik/pluggedin-app --skill sops-secrets -a claude-code`. Or copy the skill folder (.claude/skills/sops-secrets in VeriTeknik/pluggedin-app) into .claude/skills/sops-secrets in your project. Claude Code loads it when a task matches its description.

How do I install Sops Secrets in Codex?

Run `npx skills add VeriTeknik/pluggedin-app --skill sops-secrets -a codex`. Or copy the skill folder (.claude/skills/sops-secrets in VeriTeknik/pluggedin-app) into .agents/skills/sops-secrets in your project. Codex loads it when a task matches its description.

Can I use Sops Secrets in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add VeriTeknik/pluggedin-app --skill sops-secrets -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/sops-secrets, .gemini/skills/sops-secrets, .github/skills/sops-secrets and .opencode/skills/sops-secrets in your project.

What does Sops Secrets need to run?

Going by SKILL.md and its folder, Sops Secrets needs the command-line tools its instructions call (git). Our summary lists: Docker.

Does Sops Secrets access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Sops Secrets safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Sops Secrets use?

Sops Secrets is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Sops Secrets use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Sops Secrets?

Skills that share tags, products or a category with Sops Secrets: Kingdee MCP Dev (WaHaiLong/KingdeeMCP, 105 stars), Polymarket Tennis (livetennisapi/livetennisapi-mcp, 152 stars), Odoo Agency Fleet Review (erpipe-org/mcp-odoo, 421 stars) and Wind MCP Skill (Wind-Alice/AliceMarket, 130 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Sops Secrets?

VeriTeknik (a GitHub organization) maintains it in VeriTeknik/pluggedin-app, which has 103 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on October 6, 2026.

Source: VeriTeknik/pluggedin-app on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.