agentsclimarketplace

Sops encrypt

Skill joaquimscosta/arkhe-claude-plugins/plugins/devtools/skills/sops-encrypt

Supercharge Claude Code with 109 specialized components — 22 agents, 32 commands, 55 skills across 13 modular plugins. Deep reasoning, autonomous dev loops, DDD architecture, design system enforcement, git automation, and more.

Install
npx -y skills add joaquimscosta/arkhe-claude-plugins --skill sops-encrypt

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 21 stars21 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Encrypt .env files using SOPS + age. Converts dotenv to YAML format (avoids SOPS bug #1435), then encrypts. Auto-detects unencrypted .env files. Use when user mentions "encrypt env", "sops encrypt", "encrypt secrets", "encrypt .env", "encrypt environment", "re-encrypt", "update encrypted".

SKILL.md

2.3 KB, as published. Nobody here has run it

SOPS Encrypt

Encrypt .env files by converting to YAML and encrypting with SOPS + age.

Why YAML? SOPS dotenv store has a known bug (#1435) that corrupts backslash and \n sequences. The helper script converts dotenv→YAML before encryption.

Workflow

  1. Detect current state:

    python3 ${CLAUDE_SKILL_DIR}/../sops-setup/scripts/detect_sops.py <project-root>
    
  2. Verify prerequisites:

    • tools.sops.installed must be true — if not, tell user to run /devtools:sops-setup
    • project.sops_yaml.exists must be true — if not, tell user to run /devtools:sops-setup
    • age_key.exists must be true — if not, tell user to run /devtools:sops-setup
  3. Show unencrypted .env files from project.env_files. If empty, report "No .env files found to encrypt" and exit.

  4. Use AskUserQuestion (multiSelect: true) — which files to encrypt. List each .env* file. If a corresponding .enc.yaml file already exists, note it will be overwritten.

  5. Encrypt each selected file (convert dotenv→YAML, then encrypt):

    python3 ${CLAUDE_SKILL_DIR}/../sops-setup/scripts/dotenv_yaml.py to-yaml <file> > <file>.enc.yaml.tmp
    sops --encrypt <file>.enc.yaml.tmp > <file>.enc.yaml
    rm <file>.enc.yaml.tmp
    

    Example: .env.local.env.local.enc.yaml

  6. Verify each encrypted file exists and is non-empty.

  7. Summary:

    | File | Encrypted To | Status |
    |------|-------------|--------|
    | .env.local | .env.local.enc.yaml | done |
    | .env.production | .env.production.enc.yaml | done |
    

    Remind user to commit the .enc.yaml files.

Key Rules

  • Always verify .sops.yaml exists before attempting encryption
  • Always convert dotenv→YAML before encrypting (use the helper script)
  • Warn if an .enc.yaml file will be overwritten
  • Never delete the original .env file — only create the .enc.yaml copy
  • Clean up .tmp files even if encryption fails

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.