dotenvx-secrets

Installation
SKILL.md

dotenvx secrets

dotenvx is a drop-in dotenv replacement (BSD-3-Clause, dotenvx/dotenvx) that injects .env values into a child process, encrypts .env files with secp256k1 keypairs, resolves vault references, and can redact secret values from the child's output stream.

Its agent-relevant capability is dotenvx run --redact -- <agent>: the agent gets the real credentials, but any occurrence of those literal values in its stdout/stderr is replaced with [REDACTED] before reaching the terminal or transcript.

Read this first: --redact is not a security boundary

Redaction is best-effort exact literal substring matching on the child process's piped stdout and stderr. src/lib/helpers/redactOutput.js does result.split(sensitiveValue).join('[REDACTED]') — no regex, no case-insensitivity, no encoding awareness. It therefore does not catch:

Installs
3
First Seen
Aug 2, 2026
dotenvx-secrets — leonardoacosta/skills