Skip to content
Back to skills

One Password

BSecurity

1Password CLI (op): service-account first, targeted secret read/store/inject, tmux session.

  • 10 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 10, 2026
ai-agentsshellbashrailsgitapi

Works with

  • cli
  • api

Security analysis

B88/100
  • criticalSends environment variables or credentials to an external URL

Pro shows the line behind each finding and how to fix it

Scanned October 10, 2026

npx -y skills add mouadja02/skills --skill one-password --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of One Password?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for One Password
[![Security: B — Skills Directory](https://www.skillsdirectory.com/api/skills/mouadja02-one-password/badge)](https://www.skillsdirectory.com/skills/mouadja02-one-password)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: one-password
description: "1Password CLI (op): service-account first, targeted secret read/store/inject, tmux session."
source: "https://github.com/steipete/agent-scripts"
attribution: "steipete/agent-scripts by Peter Steinberger"
version: "1.0.0"
---

# 1Password CLI

> **Attribution:** Sourced from [steipete/agent-scripts](https://github.com/steipete/agent-scripts) by [Peter Steinberger](https://github.com/steipete).

## When to Use

- Reading or storing secrets via 1Password CLI (`op`)
- Injecting secrets into environment variables or config files
- Using service-account-first auth with tmux session fallback

Official docs: https://developer.1password.com/docs/cli/get-started/

## Workflow

1. Check OS + shell.
2. Verify CLI present inside tmux: `op --version`.
3. **REQUIRED**: create exactly one persistent named tmux session for the whole secret task.
4. Try service-account access first when a matching token/workflow exists — no dialogs.
5. If service-account access is missing or lacks the exact item/field needed, stop and ask before desktop-app sign-in.
6. Desktop fallback: confirm app integration/unlock, then `op signin` once inside the same session.
7. Verify chosen access path inside that same session: `op whoami`.
8. If a command fails, reuse the same tmux session; do not start a second session.

## Default Account

- Default account: `my.1password.com`
- Pass `--account my.1password.com` on every `op` command when storing or reading secrets.

## Required Persistent Tmux Session

The shell tool uses a fresh TTY per command. Run `op` inside one dedicated tmux session:

```bash
SESSION="op-work"
tmux has-session -t "$SESSION" 2>/dev/null || tmux new -d -s "$SESSION" -n shell
tmux send-keys -t "$SESSION:" -- "op signin --account my.1password.com" Enter
tmux send-keys -t "$SESSION:" -- "op whoami" Enter
tmux capture-pane -p -J -t "$SESSION:" -S -200
```

## Exact Field Reads (safe pattern)

For a known item/field:

```bash
op item get "Item Title" --account my.1password.com --fields label=field_name
```

Print shape only, never values:
```bash
value="$(op item get "Item Title" --account my.1password.com --fields label=api_key)"
echo "field_len:${#value}"
```

## Service-Specific Workflows

- For npm registry/package work, use the `npm` skill.
- This skill owns only the generic 1Password rules: tmux-only `op`, targeted reads, one persistent session, no broad enumeration, no secret output.

## Guardrails

- Never paste secrets into logs, chat, or code.
- Prefer `op run` / `op inject` over writing secrets to disk.
- Do not run `op` outside tmux; stop and ask if tmux is unavailable.
- Print presence/shape only, never token or secret values.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…