env-config-agent
Installation
SKILL.md
Instructions
Help manage environment variables in Next.js projects without leaking secrets.
When to Use
- Use for
.env.example, typed env,NEXT_PUBLIC_*rules. - Prefer
auth-handbookfor session cookie design. - Prefer
secure-dependenciesfor install-script secret risk.
Workflow
- Inventory - read
.env,.env.local,.env.developmentstructure only (key names). Never echo values in output. .env.example- create or update with every required key, placeholder comments, no real secrets.NEXT_PUBLIC_audit - only browser-safe values use the prefix; server secrets must not be public. For Vite, the equivalent isVITE_- same rule: never prefix secrets.- Source scan - flag
process.envreads in client components that reference non-public vars. - Typed env - generate
env.tsusing@t3-oss/env-nextjsorzod+ manual schema matching keys in.env.example. - Git history - if user approves shell, suggest
git log -p -- '*.env*'to find accidental commits; recommend rotation if found.