Skip to content
AI & Agents
Skill

/yao-secret

Secret management expert. ALWAYS invoke this skill when you need to read API keys, tokens, or other secrets configured by the user. Never hardcode credentials — use this skill to retrieve them securely.

BOOST
From plugin
yao
8.1k12 skills1 agent
Install
$ npx -y skills add YaoApp/yao --skill yao-secret --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/yao-secret

Context preview

The summary Claude sees to decide when to auto-load this skill.

Secret management expert. ALWAYS invoke this skill when you need to read API keys, tokens, or other secrets configured by the user. Never hardcode credentials — use this skill to retrieve them securely.

SKILL.md

yao-secret.SKILL.md
name: yao-secret
description: Secret management expert. ALWAYS invoke this skill when you need to read API keys, tokens, or other secrets configured by the user. Never hardcode credentials — use this skill to retrieve them securely.

Secret Tools

Two tools for accessing user-configured secrets, called via bash.

secret_list

List available secret names and descriptions. **Does not return secret values** — use `secret_read` for that.

tai tool secret_list '{}'

No parameters required. Returns secrets configured for the current assistant.

secret_read

Read a secret value by name. Returns the decrypted value for use in scripts.

tai tool secret_read '{"name": "GITHUB_TOKEN"}'
tai tool secret_read '{"name": "AWS_SECRET_KEY"}'

| Parameter | Type | Required | Description | |-----------|--------|----------|----------------------------------------------------------| | `name` | string | yes | Secret key name (e.g. `GITHUB_TOKEN`, `AWS_SECRET_KEY`) |

**Security**: Never log, print, or expose the returned secret value in output visible to users.

Typical Workflow

1. `secret_list` — discover what secrets are available 2. `secret_read` — retrieve a specific secret by name 3. Use the value in API calls, git auth, etc.

Guidelines

  • Always call `secret_list` first to check if a required secret exists before reading
  • Never hardcode API keys or tokens — always use `secret_read`
  • Secret values are decrypted at read time; treat them as sensitive
  • If a secret is not found, prompt the user to configure it in their settings
  • All output is JSON
Read more
Ships withyao

✨ All your agents and workspaces in one place, on every device you own. Track tasks on a board, accessible from desktop, mobile, browser, or API. Self-hosted.

Get the whole plugin
Stats
8,072
Stars
717
Forks
Active
Maintenance
Go
Language
5d ago
Last commit
5y ago
Created
3h ago
Added

Repo: YaoApp/yao

Other skills on yao.