secrets-handling
Installation
SKILL.md
Secrets Handling
Five rules. The first four are already enforced elsewhere in this repo; the fifth records the fleet's 1Password operability default. This skill is the one place they are stated together. Each cites its enforcing source — cited, not absorbed: the sources below stay authoritative and keep their own text.
1. Never pass a secret via argv
Command-line arguments are world-readable in ps aux for the lifetime of the process. Pass
secrets via stdin, an environment variable, or a file descriptor — never as a positional
argument or flag value.
Enforced in
scripts/bin/onepassword-provision-secret:17— "ps auxoutput) and never echoed to stdout/stderr."