Skip to content
Back to skills

Env Setup

ASecurity

Add a .env.example and validate required config at startup so missing vars fail fast

  • 3 stars
  • 0 votes
  • 0 copies
  • 3 views
  • Added September 3, 2026
ai-agentsgogit

Security analysis

A100/100

Scanned September 3, 2026

npx -y skills add black141312/ada --skill env-setup --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Env Setup?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Env Setup
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/black141312-env-setup/badge)](https://www.skillsdirectory.com/skills/black141312-env-setup)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: env-setup
description: Add a .env.example and validate required config at startup so missing vars fail fast
category: ci-cd
---

# Env Setup

Use when config is read from environment variables and you want a discoverable template plus a hard fail on missing/invalid values.

1. Grep the codebase for every environment variable read (`process.env.X`, `os.environ[...]`, `getenv`) to build the full list.
2. Create `.env.example` listing each var with a safe placeholder or sane default and a one-line comment on its purpose.
3. Centralize config loading in one module that reads, type-coerces, and validates all vars at startup.
4. Validate on boot with a schema (zod, pydantic, envalid, or a manual check) and exit non-zero with a clear message naming any missing/invalid var.
5. Ensure real `.env` is gitignored and document the `cp .env.example .env` bootstrap step.
6. Run the app with a deliberately missing var to confirm it fails fast with an actionable error rather than crashing later.

## Rules
- Keep `.env.example` in sync with the code — a var read but undocumented is a setup trap.
- Never commit a real `.env` or real secret values; placeholders only in the example.
- Validate at startup, not lazily at first use, so misconfig surfaces immediately.
- Fail with a message that names the offending variable and what it expects.
- Read each var through the central config module, not scattered `process.env` access.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…