跳到主要内容
知仓学习社ZHICANG

yao-secret

Secret management expert. ALWAYS invoke this skill when you need to read API keys, tokens, or other secrets configured by the user. Never hardcode c…

不碰外部(只输出文字)无严重或高危命中YaoApp/yao

它会碰到什么

扫了多少1 个文本文件,2 KB
它会碰到什么不碰外部(只输出文字)
命中总数0 处
命中统计严重 0 · 高 0 · 中 0 · 低 0

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Secret Tools

Two tools for accessing user-configured secrets, called via bash.

secret_list

List available secret names and descriptions. Does not return secret values — use secret_read for that.

tai tool secret_list '{}'

No parameters required. Returns secrets configured for the current assistant.

secret_read

Read a secret value by name. Returns the decrypted value for use in scripts.

tai tool secret_read '{"name": "GITHUB_TOKEN"}'
tai tool secret_read '{"name": "AWS_SECRET_KEY"}'

| Parameter | Type | Required | Description |

|-----------|--------|----------|----------------------------------------------------------|

| name | string | yes | Secret key name (e.g. GITHUB_TOKEN, AWS_SECRET_KEY) |

Security: Never log, print, or expose the returned secret value in output visible to users.

Typical Workflow

  1. secret_list — discover what secrets are available
  2. secret_read — retrieve a specific secret by name
  3. Use the value in API calls, git auth, etc.

Guidelines

  • Always call secret_list first to check if a required secret exists before reading
  • Never hardcode API keys or tokens — always use secret_read
  • Secret values are decrypted at read time; treat them as sensitive
  • If a secret is not found, prompt the user to configure it in their settings
  • All output is JSON

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 7,962
本站分层T1
该仓技能数12
原文件路径tools/skills/yao-secret/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 12 个技能