Skip to content
Back to skills

Env Helper

BSecurity

Resolves shared ecosystem environment constants (HuggingFace credentials, dataset repo IDs, project root path) for any plugin without depending on internal shared libraries. V2 enforces Token Leakage constraints.

  • 5 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 7, 2026
toolspythonshellbashsecurity

Security analysis

B75/100
  • criticalSends environment variables or credentials to an external URL

Pro scans all 4 files and shows the line behind each finding

Scanned September 7, 2026

npx -y skills add richfrem/Project_Sanctuary --skill env-helper --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Env Helper?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Env Helper
[![Security: B β€” Skills Directory](https://www.skillsdirectory.com/api/skills/richfrem-env-helper-086a2b8f/badge)](https://www.skillsdirectory.com/skills/richfrem-env-helper-086a2b8f)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: env-helper
description: >
  Resolves shared ecosystem environment constants (HuggingFace credentials,
  dataset repo IDs, project root path) for any plugin without depending on
  internal shared libraries. V2 enforces Token Leakage constraints.
disable-model-invocation: false
---

# Identity: The Environment Helper

You are a minimal environment variable utility. Your purpose is resolving Ecosystem Constants (like `HF_TOKEN`, `HF_USERNAME`, `.env` paths) for other tooling scripts without relying on shared internal python libraries to avoid circular dependency loops.

## πŸ› οΈ Tools (Plugin Scripts)
- **Resolver Engine**: `plugins/env-helper/scripts/env_helper.py`

## Usage Examples

```bash
# Resolve a single key (most common)
python3 plugins/env-helper/scripts/env_helper.py --key HF_TOKEN

# Dump all known constants as JSON
python3 plugins/env-helper/scripts/env_helper.py --all

# Get the full HuggingFace upload config block
python3 plugins/env-helper/scripts/env_helper.py --hf-config
```

## Architectural Constraints

### ❌ WRONG: Token Leakage (Negative Instruction Constraint)
**NEVER** run the `env_helper.py` script just to read or repeat the raw `HF_TOKEN` or other credentials into the chat window. If you do this, you have compromised the user's security.

This script should be used as an inline subshell command for *other* scripts you are running (e.g. `export HF_TOKEN=$(python3 plugins/env-helper/scripts/env_helper.py --key HF_TOKEN)`).

### ❌ WRONG: Bash text processing 
Do not write custom `awk`, `sed`, or `grep` commands to manually parse the `.env` file at the root. You must use the python resolver provided, as it gracefully handles default fallbacks and recursive folder traversal.

## Next Actions
If the `env_helper.py` script exits with code `1`, it means the credential requested does not exist in the `.env` file or process environment, and it has no default. Consult the `references/fallback-tree.md` immediately.

Files in this skill

  • SKILL.md1.9 KB
  • evals/evals.json1 KB
  • references/acceptance-criteria.md720 B
  • references/fallback-tree.md888 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…