Skip to content
Back to skills

Env Setup

ASecurity

Environment configuration and secrets management. Use when setting up .env files, managing secrets, or configuring environments.

  • 69 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added May 27, 2026
data-aigoawsgitdatabaseci/cd

Security analysis

A100/100

Scanned May 27, 2026

npx -y skills add Tibsfox/gsd-skill-creator --skill env-setup --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Env Setup?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Env Setup
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/tibsfox-env-setup/badge)](https://www.skillsdirectory.com/skills/tibsfox-env-setup)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: env-setup
description: Environment configuration and secrets management. Use when setting up .env files, managing secrets, or configuring environments.
version: 1.0.0
format: 2025-10-02
triggers:
  - setting up
updated: 2026-04-25
status: ACTIVE
---

# Environment Configuration

## Non-Negotiable Rules

| Rule | Why |
|------|-----|
| NEVER commit .env to git | Secrets persist in history forever |
| NEVER log secret values | Logs stored in plain text, forwarded |
| NEVER hardcode secrets | Source code is widely shared |
| ALWAYS use .env.example | Documents vars without exposing values |
| ALWAYS add .env* to .gitignore FIRST | Prevents accidental commit |
| ALWAYS validate config at startup | Fail fast, not hours into production |

## .gitignore (add before creating .env)

```gitignore
.env
.env.*
!.env.example
*.pem
*.key
credentials.json
```

## Naming Conventions

- UPPER_SNAKE_CASE: `DATABASE_URL`, `JWT_SECRET`
- Prefix by service: `DB_`, `REDIS_`, `AWS_`
- Booleans: `ENABLE_CACHE=true` (not 1/yes)
- Feature flags: `FEATURE_*`

## Key Patterns

- **No defaults for secrets** — force explicit configuration
- **Validate at startup** with Zod/Joi/Pydantic, not at first use
- **Unique secrets per environment** — one leak shouldn't compromise all
- **Rotate leaked secrets immediately** — check git history, audit access logs
- **Process env always wins** — CI/CD overrides file-based config

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…