secret-handling
Installation
SKILL.md
Context
Spawned agents have read access to the entire repository, including .env files containing live credentials. If an agent reads secrets and writes them to .squad/ files (decisions, logs, history), Scribe auto-commits them to git, exposing them in remote history. This skill codifies absolute prohibitions and safe alternatives.
Patterns
Prohibited File Reads
NEVER read these files:
.env(production secrets).env.local(local dev secrets).env.production(production environment).env.development(development environment).env.staging(staging environment).env.test(test environment with real credentials)- Any file matching
.env.*UNLESS explicitly allowed (see below)