yao-secret
Secret management expert. ALWAYS invoke this skill when you need to read API keys, tokens, or other secrets configured by the user. Never hardcode c…
它会碰到什么
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Secret Tools
Two tools for accessing user-configured secrets, called via bash.
secret_list
List available secret names and descriptions. Does not return secret values — use secret_read for that.
tai tool secret_list '{}'
No parameters required. Returns secrets configured for the current assistant.
secret_read
Read a secret value by name. Returns the decrypted value for use in scripts.
tai tool secret_read '{"name": "GITHUB_TOKEN"}'
tai tool secret_read '{"name": "AWS_SECRET_KEY"}'
| Parameter | Type | Required | Description |
|-----------|--------|----------|----------------------------------------------------------|
| name | string | yes | Secret key name (e.g. GITHUB_TOKEN, AWS_SECRET_KEY) |
Security: Never log, print, or expose the returned secret value in output visible to users.
Typical Workflow
secret_list— discover what secrets are availablesecret_read— retrieve a specific secret by name- Use the value in API calls, git auth, etc.
Guidelines
- Always call
secret_listfirst to check if a required secret exists before reading - Never hardcode API keys or tokens — always use
secret_read - Secret values are decrypted at read time; treat them as sensitive
- If a secret is not found, prompt the user to configure it in their settings
- All output is JSON
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。