Skip to content
Back to skills

Secrets

ASecurity

Request user-supplied credentials securely into a dotenv file without exposing their values to the agent.

  • 11 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 5, 2026
ai-agentsrustbashapidocumentation

Works with

  • cli
  • api

Security analysis

A100/100

Scanned October 5, 2026

npx -y skills add davidondrej/cloudroom-gui --skill secrets --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Secrets?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Secrets
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/davidondrej-secrets/badge)](https://www.skillsdirectory.com/skills/davidondrej-secrets)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: secrets
description: "Request user-supplied credentials securely into a dotenv file without exposing their values to the agent."
---

# Request secrets securely

Use `cloudroom secret request` when the user needs to supply a credential. Do not ask the user to paste a secret into chat.

Batch every currently known variable into one request. Inspect documentation or `.env.example` to identify variable names, but do not read or print an existing secret-bearing env file.

```bash
cloudroom secret request OPENAI_API_KEY RESEND_API_KEY \
  --purpose "Configure application credentials" \
  --describe OPENAI_API_KEY "OpenAI API key used by the server" \
  --describe RESEND_API_KEY "Resend API key used for transactional email" \
  --write-env .env.local
```

Always provide the exact `--write-env` destination, a concise purpose, and one short plain-language description per variable. Relative destinations resolve from the CLI working directory; absolute destinations may point anywhere on the thread's host. Never place secret values in argv, prompts, comments, logs, or follow-up messages.

After success, trust the command's path and added/updated/unchanged counts. Never verify by running `cat`, `sed`, `env`, or another command that would reveal the completed file.

If the command reports duplicate dotenv assignments, fix the file structure without reading values and rerun the request. If it reports repeated write conflicts, rerun the same request; do not ask the user to paste values. Under the workspace sandbox (Accept Edits / Approve for me), Claude's macOS sandbox permits the loopback access plugin CLI commands need; Linux and other provider sandboxes may still require escalation approval.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…