secret

SkillSecurity

Lets your agent track tasks on a shared board you can reach from desktop, mobile, browser, or API.

Use secret in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add secret and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the secret skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

About this skill

Secret Management, set, get, list, delete, rotate, scan via configured provider

What this skill tells your AI

The instructions your AI receives, as published by the-agency-ai/the-agency in .claude/skills/secret/SKILL.md and read by ahel’s review.

Secret Management

Manage secrets through the configured provider (SPEC-PROVIDER pattern). Generic skill that dispatches to a provider tool based on agency/config/agency.yaml.

Arguments

  • $ARGUMENTS: One of:
    • set <name> [value] — store a secret (prompts if value omitted)
    • get <name> — retrieve a secret
    • list — list all secrets
    • delete <name> — remove a secret
    • rotate <name> — rotate a secret (get current → set new)
    • scan — scan codebase for leaked secrets

Instructions

Step 1: Resolve the provider

Read agency/config/agency.yaml for the secrets provider:

secrets:
  provider: "vault"  # or "aws", "1password", etc.

The provider maps to a tool: ./agency/tools/secret-{provider}

If no provider is configured, default to vault.

Step 2: Verify the provider tool exists

Check ./agency/tools/secret-{provider} exists and is executable. If not:

  • List available provider tools: list files matching ./agency/tools/secret-*
  • Tell the user which providers are available
  • Suggest configuring a different provider in agency.yaml

Step 3: Map verbs to provider commands

Different providers use different verbs:

  • vault provider (./agency/tools/secret-vault):
    • set → maps to create
    • get, list, delete, rotate pass through directly
  • other providers (./agency/tools/secret-{provider}):
    • all verbs pass through directly
  • scan verb (any provider): use ./agency/tools/secrets-scan directly

Step 4: Execute

Run the provider tool with the mapped verb:

./agency/tools/secret-vault create api-key
./agency/tools/secret-{provider} get database-url
./agency/tools/secrets-scan

Use relative paths — never $CLAUDE_PROJECT_DIR/agency/tools/... (the env var is empty in agent Bash calls).

Step 5: Report

Show the user the result. Never echo secret values to the conversation — pipe them to the appropriate destination (env file, clipboard, etc.) or confirm completion without revealing the value.

Error Handling

  • No provider configured: default to vault, warn the user they should set secrets.provider in agency.yaml
  • Provider tool missing: list ./agency/tools/secret-* files, suggest alternatives
  • Verb not supported: show the provider's --help output
  • Secret not found: clear error message, do not invent values

Security Rules

  • Never log secret values to conversation, transcripts, or telemetry
  • Never commit secret values to git
  • Never write secrets to a file in the project unless it's already in .gitignore
  • Use the provider's own audit log if it has one — don't roll your own

SPEC-PROVIDER Pattern

This skill is one of several using the SPEC-PROVIDER pattern (see agency/README-THEAGENCY.md SPEC-PROVIDER section). The skill is generic; the provider implements the contract. Add new providers by creating ./agency/tools/secret-{name} that supports the standard verbs.

OFFENDERS WILL BE FED TO THE — CUTE — ATTACK KITTENS!

Signals

GitHub stars
66
Forks
12
Last commit
Sep 2026
Advanced
Item type
skill
Key
secret
Source
github.com/the-agency-ai/the-agency