agentsclimarketplace

Env var auditor

Skill kakarot-oncloud/claude-dev-skills/skills/env-var-auditor

15 practical Claude Agent Skills for software developers — commit messages, PR descriptions, code review, SQL, regex, tests, migrations, and more. Official SKILL.md format, ready to upload to Claude.ai.

Install
npx -y skills add kakarot-oncloud/claude-dev-skills --skill env-var-auditor

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Audits how a project handles environment variables and secrets — finds hardcoded values, missing .env.example entries, unsafe defaults, and inconsistent naming. Generates a clean .env.example. Use this skill when the user asks to "audit env vars", "generate .env.example", "find secrets in my code", or wants to clean up configuration handling before open-sourcing or onboarding.

SKILL.md

3.5 KB, as published. Nobody here has run it

Env Var Auditor

You audit how a codebase handles configuration and produce a clean, safe setup.

What to find

1. Hardcoded secrets and config in source

  • API keys, tokens, passwords, connection strings literally in code
  • Magic URLs (https://api.production.com) that should be env vars
  • Magic numbers that vary by environment (timeouts, batch sizes, ports)

2. Missing or stale .env.example

  • Vars used in code but not documented in .env.example
  • Vars in .env.example no longer used in code
  • .env.example containing real values instead of placeholders

3. Unsafe handling

  • process.env.X used without validation or default
  • Secrets logged on startup or in error messages
  • Secrets committed to git history (suggest scanning with gitleaks / trufflehog)
  • .env not in .gitignore
  • Different naming conventions in same project (DB_HOST vs DATABASE_URL vs databaseHost)

4. Configuration smells

  • One giant .env mixing secrets + non-secrets — split secrets out
  • No distinction between required and optional vars
  • No type coercion (env vars are always strings — process.env.PORT is a string, not a number)

Output format

## Audit summary
<2-3 sentence overall verdict>

## Findings

### 🔴 Critical
- `src/db.ts:14` — DB password hardcoded as `'changeme'`. Move to `DATABASE_PASSWORD`.
- `.env` is tracked by git. Add to `.gitignore` and rotate exposed secrets.

### 🟠 Major
- Missing in `.env.example`: `STRIPE_WEBHOOK_SECRET`, `REDIS_URL`, `SENTRY_DSN`
- `process.env.PORT` used as number without parsing in `src/server.ts:8`

### 🟡 Minor
- Inconsistent naming: `DB_HOST` and `DATABASE_URL` both used. Standardize.

## Suggested .env.example
<full file contents in code block>

## Suggested config module
<a single typed config loader in the project's language, with validation>

.env.example conventions

# Required ─────────────────────────────────────────────
# Postgres connection string
DATABASE_URL=postgresql://user:password@localhost:5432/mydb

# Stripe API key (test mode for dev). Get from dashboard.stripe.com
STRIPE_SECRET_KEY=sk_test_...

# Optional ─────────────────────────────────────────────
# Logging level: debug | info | warn | error (default: info)
LOG_LEVEL=info

# Port to bind to (default: 3000)
PORT=3000

Rules

  1. Group required vs optional. Required at top with no default; optional below with default noted.
  2. Comment every var with: what it does, where to get it, and the default.
  3. Use placeholder values, never real ones — even for local-only stuff use changeme or your-key-here.
  4. Suggest a typed config loader (zod / pydantic / envconfig / viper) so missing vars fail at startup, not at first use.
  5. Recommend secret managers for production (Vault, AWS SSM, GCP Secret Manager) over .env files on servers.
  6. Never print or log secrets in audit output. Show variable names only — DATABASE_PASSWORD=<redacted>, never the actual value found in code.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.