Secret management expert. ALWAYS invoke this skill when you need to read API keys, tokens, or other secrets configured by the user. Never hardcode credentials — use this skill to retrieve them securely.
Scanned 8/31/2026
Install to Claude Code
npx -y skills add YaoApp/yao --skill yao-secret --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Yao Secret?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/yaoapp-yao-secret)More formats (shields.io, HTML) on the badges page.
---
name: yao-secret
description: Secret management expert. ALWAYS invoke this skill when you need to read API keys, tokens, or other secrets configured by the user. Never hardcode credentials — use this skill to retrieve them securely.
---
# Secret Tools
Two tools for accessing user-configured secrets, called via bash.
## secret_list
List available secret names and descriptions. **Does not return secret values** — use `secret_read` for that.
```bash
tai tool secret_list '{}'
```
No parameters required. Returns secrets configured for the current assistant.
## secret_read
Read a secret value by name. Returns the decrypted value for use in scripts.
```bash
tai tool secret_read '{"name": "GITHUB_TOKEN"}'
tai tool secret_read '{"name": "AWS_SECRET_KEY"}'
```
| Parameter | Type | Required | Description |
|-----------|--------|----------|----------------------------------------------------------|
| `name` | string | yes | Secret key name (e.g. `GITHUB_TOKEN`, `AWS_SECRET_KEY`) |
**Security**: Never log, print, or expose the returned secret value in output visible to users.
## Typical Workflow
1. `secret_list` — discover what secrets are available
2. `secret_read` — retrieve a specific secret by name
3. Use the value in API calls, git auth, etc.
## Guidelines
- Always call `secret_list` first to check if a required secret exists before reading
- Never hardcode API keys or tokens — always use `secret_read`
- Secret values are decrypted at read time; treat them as sensitive
- If a secret is not found, prompt the user to configure it in their settings
- All output is JSON
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!