secrets-handling

Installation
SKILL.md

Secrets Handling

Five rules. The first four are already enforced elsewhere in this repo; the fifth records the fleet's 1Password operability default. This skill is the one place they are stated together. Each cites its enforcing source — cited, not absorbed: the sources below stay authoritative and keep their own text.

1. Never pass a secret via argv

Command-line arguments are world-readable in ps aux for the lifetime of the process. Pass secrets via stdin, an environment variable, or a file descriptor — never as a positional argument or flag value.

Enforced in scripts/bin/onepassword-provision-secret:17 — "ps aux output) and never echoed to stdout/stderr."

2. Never reproduce a secret's value in output

Installs
3
First Seen
Aug 2, 2026
secrets-handling — leonardoacosta/skills