secret
SkillSecurityLets your agent track tasks on a shared board you can reach from desktop, mobile, browser, or API.
Use secret in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add secret and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the secret skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
About this skill
Secret Management, set, get, list, delete, rotate, scan via configured provider
What this skill tells your AI
The instructions your AI receives, as published by the-agency-ai/the-agency in .claude/skills/secret/SKILL.md and read by ahel’s review.
Secret Management
Manage secrets through the configured provider (SPEC-PROVIDER pattern). Generic skill that dispatches to a provider tool based on agency/config/agency.yaml.
Arguments
$ARGUMENTS: One of:set <name> [value]— store a secret (prompts if value omitted)get <name>— retrieve a secretlist— list all secretsdelete <name>— remove a secretrotate <name>— rotate a secret (get current → set new)scan— scan codebase for leaked secrets
Instructions
Step 1: Resolve the provider
Read agency/config/agency.yaml for the secrets provider:
secrets:
provider: "vault" # or "aws", "1password", etc.
The provider maps to a tool: ./agency/tools/secret-{provider}
If no provider is configured, default to vault.
Step 2: Verify the provider tool exists
Check ./agency/tools/secret-{provider} exists and is executable. If not:
- List available provider tools: list files matching
./agency/tools/secret-* - Tell the user which providers are available
- Suggest configuring a different provider in
agency.yaml
Step 3: Map verbs to provider commands
Different providers use different verbs:
- vault provider (
./agency/tools/secret-vault):set→ maps tocreateget,list,delete,rotatepass through directly
- other providers (
./agency/tools/secret-{provider}):- all verbs pass through directly
- scan verb (any provider): use
./agency/tools/secrets-scandirectly
Step 4: Execute
Run the provider tool with the mapped verb:
./agency/tools/secret-vault create api-key
./agency/tools/secret-{provider} get database-url
./agency/tools/secrets-scan
Use relative paths — never $CLAUDE_PROJECT_DIR/agency/tools/... (the env var is empty in agent Bash calls).
Step 5: Report
Show the user the result. Never echo secret values to the conversation — pipe them to the appropriate destination (env file, clipboard, etc.) or confirm completion without revealing the value.
Error Handling
- No provider configured: default to
vault, warn the user they should setsecrets.providerinagency.yaml - Provider tool missing: list
./agency/tools/secret-*files, suggest alternatives - Verb not supported: show the provider's
--helpoutput - Secret not found: clear error message, do not invent values
Security Rules
- Never log secret values to conversation, transcripts, or telemetry
- Never commit secret values to git
- Never write secrets to a file in the project unless it's already in
.gitignore - Use the provider's own audit log if it has one — don't roll your own
SPEC-PROVIDER Pattern
This skill is one of several using the SPEC-PROVIDER pattern (see agency/README-THEAGENCY.md SPEC-PROVIDER section). The skill is generic; the provider implements the contract. Add new providers by creating ./agency/tools/secret-{name} that supports the standard verbs.
OFFENDERS WILL BE FED TO THE — CUTE — ATTACK KITTENS!
Signals
- GitHub stars
- 66
- Forks
- 12
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
secret- Source
- github.com/the-agency-ai/the-agency
github.com/the-agency-ai/the-agency