Config secrets environments
Skill majiayu000/spellbook/skills/config-secrets-environments
Design, audit, and verify configuration, environment separation, secrets, BYOK flows, key rotation, config schema validation, and drift checks across local, dev, staging, and production. Use when adding env vars, changing runtime config, handling API keys or user-provided keys, diagnosing config drift, or preparing deploy/release configuration.From its SKILL.md
npx -y skills add majiayu000/spellbook --skill config-secrets-environmentsAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
SKILL.md
1.9 KB, 321 tokens by cl100k_base, as published. Nobody here has run it
Config Secrets Environments
Purpose
Use this skill when behavior depends on configuration or secrets. The goal is explicit config ownership, validation, and environment parity without exposing credentials.
Inventory
Collect:
- Config files and env var declarations.
- Runtime readers and startup wiring.
- Secret sources: env, secret manager, local keychain, BYOK storage.
- Environment matrix: local, test, dev, staging, prod.
- Rotation, revocation, and audit requirements.
- Existing
.env.example, schema, docs, and CI checks.
Never print real secrets. Redact values and report only names, source type, and wiring status.
Design Rules
- Define a schema for required and optional config.
- Fail closed for missing critical config; do not silently fall back to insecure or broad behavior.
- Keep defaults safe for local development and explicit for production.
- Separate build-time and runtime config.
- Keep tenant/user-provided keys isolated from platform keys.
- Document rotation and revocation paths.
- Verify config is wired into startup, not only declared.
Environment Matrix
Use this shape:
| Key | Local | Test | Staging | Prod | Secret? | Owner | Rotation |
|---|
Mark unknown values as unknown. Do not infer a production value from local files.
Output Shape
config_inventory:
environment_matrix:
secret_flows:
validation_and_startup_wiring:
drift_checks:
rotation_plan:
failure_behavior:
verification_commands:
What ships with it: 1 file
250 B alongside SKILL.md
agents/
- openai.yaml250 B
Gives 0 of the 12 instructions most project setup skills give in 321 tokens
Counted across 1,553 of the 3,091 authors here whose files we hold, read 2026-09-06
- Write the configuration filein 36 of 1553
- Create the directory structurein 35 of 1553, across 33 files
- Verify the setupin 31 of 1553, across 28 files
- Run the setup scriptin 30 of 1553, across 29 files
- Pre-determine the required sample sizein 29 of 1553, across 12 files
- Check if the configuration already existsin 29 of 1553
- Document every testin 26 of 1553, across 10 files
- Start with a hypothesisin 26 of 1553, across 11 files
- Ask one question at a timein 22 of 1553
- Test a single variable per testin 21 of 1553, across 9 files
- Read product marketing context before asking questionsin 19 of 1553, across 8 files
- Do not peek and stop earlyin 18 of 1553, across 7 files
Said here and by no other author read
- Fail closed for missing critical config
- Keep defaults safe for development
- Separate build-time and runtime config
- Keep tenant keys isolated
- Verify config is wired into startup
Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.