secrets

Installation
SKILL.md

Secrets Management

Core Rules

  1. NEVER hardcode secrets, API keys, OAuth2 client IDs/secrets, tokens, passwords, or credentials in source code
  2. ALWAYS store secrets in .env files (or platform-native equivalents like local.properties, .xcconfig)
  3. ALWAYS load secrets from environment variables at runtime
  4. ALWAYS add .env to .gitignore before first commit
  5. ALWAYS provide a .env.example documenting required variables (with empty values)

Workflow

When Writing Code That Uses Secrets

Installs
13
GitHub Stars
2
First Seen
Feb 19, 2026
secrets — alfredang/skills