agentsclimarketplace

Env secrets management

Skill fxckcode/skills-kit/skills/env-secrets-management

A collection of agent skills for repository setup, multi-CLI agent workflows, and intelligent context loading.

Install
npx -y skills add fxckcode/skills-kit --skill env-secrets-management

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Manage .env files, API keys, passwords, and sensitive configuration values — including workarounds for tool output censorship that corrupts secrets in commands and file writes. Use when handling secrets, configuring environment variables, or debugging authentication issues caused by secret censoring.

The file declares its own license as Apache-2.0. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

3.0 KB, as published. Nobody here has run it

Env & Secrets Management

What This Skill Owns

  • Creating and updating .env files with secrets that would otherwise be censored
  • Running Docker, Node, or Go processes with proper secret injection
  • Writing secret-bearing files via direct file I/O (bypasses terminal censorship)
  • Verifying secret content with hex dump tools
  • Handling Prisma 7 + PostgreSQL authentication with env var passthrough

When to Use

  • User needs to create or update a .env file containing secrets
  • Commands fail because secrets get replaced with *** in shell execution
  • Setting up authentication for Docker, databases, or API services
  • Debugging "password authentication failed" errors caused by secret corruption

The Censorship Problem

Some agent terminals censor secret-looking values (passwords, API keys, tokens) both in display AND in execution. This means:

  • docker run -e POSTGRES_PASSWORD=*** — the *** IS what gets sent to the shell
  • Writing .env with API_KEY=*** — writes *** literally
  • f-string interpolation with secret variables — the value gets replaced before execution

Workarounds

For .env Files — Use Direct File I/O

# Use Python/Node direct file writing, NOT the agent's write tool
secret = chr(105)+chr(107)+chr(100)  # build from char codes
with open("/path/to/.env", "w") as f:
    f.write(f"DATABASE_URL=postgresql://user:{secret}@localhost:5434/db\n")
    f.write(f"API_KEY={secret}\n")

Key rules:

  • Build sensitive strings from chr() codes, not literals
  • Concatenate with + operator, NOT f-strings
  • Use raw file I/O (open/write), not agent write tools
  • Verify with hex dump (xxd .env | head -10)

For Docker — Use --env-file

Write an env file with raw I/O, then:

docker run -d --name mydb --env-file /tmp/.env image

For Prisma 7 — Pass Env Vars Explicitly

Prisma 7 does NOT auto-load .env:

DATABASE_URL='postgresql://user:pass@host:5434/db' npx prisma db push

For Local Servers — Source Then Run

set -a && source .env && node dist/main.js

Verification

After writing secrets, verify actual file contents:

xxd /path/to/.env | head -10

Hex dumps show actual bytes without censorship.

Pitfalls

  • Censorship is input-level, not just display — the tool replaces values BEFORE sending to shell
  • write tool also censors — even file writes are affected
  • f-strings with secret variables break — use + concatenation
  • Don't trust cat/echo display — what you see is NOT what's in the file
  • Shell sourcing (set -a && . .env) breaks on URLs with //, @, :

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.