Skip to main content
ClaudeWave
Skill7.9k repo starsupdated 4d ago

yao-secret

Secret management expert. ALWAYS invoke this skill when you need to read API keys, tokens, or other secrets configured by the user. Never hardcode credentials — use this skill to retrieve them securely.

Install in Claude Code
Copy
git clone --depth 1 https://github.com/YaoApp/yao /tmp/yao-secret && cp -r /tmp/yao-secret/tools/skills/yao-secret ~/.claude/skills/yao-secret
Then start a new Claude Code session; the skill loads automatically.

SKILL.md

# Secret Tools

Two tools for accessing user-configured secrets, called via bash.

## secret_list

List available secret names and descriptions. **Does not return secret values** — use `secret_read` for that.

```bash
tai tool secret_list '{}'
```

No parameters required. Returns secrets configured for the current assistant.

## secret_read

Read a secret value by name. Returns the decrypted value for use in scripts.

```bash
tai tool secret_read '{"name": "GITHUB_TOKEN"}'
tai tool secret_read '{"name": "AWS_SECRET_KEY"}'
```

| Parameter | Type   | Required | Description                                              |
|-----------|--------|----------|----------------------------------------------------------|
| `name`    | string | yes      | Secret key name (e.g. `GITHUB_TOKEN`, `AWS_SECRET_KEY`)  |

**Security**: Never log, print, or expose the returned secret value in output visible to users.

## Typical Workflow

1. `secret_list` — discover what secrets are available
2. `secret_read` — retrieve a specific secret by name
3. Use the value in API calls, git auth, etc.

## Guidelines

- Always call `secret_list` first to check if a required secret exists before reading
- Never hardcode API keys or tokens — always use `secret_read`
- Secret values are decrypted at read time; treat them as sensitive
- If a secret is not found, prompt the user to configure it in their settings
- All output is JSON
secretSkill
yao-agentSkill

Agent management expert. ALWAYS invoke this skill when you need to list available agents, download or reference agent source code, deploy agent code to the host, or query the LLM connector matrix. Do not guess agent structures — use this skill first.

yao-audioSkill

Audio expert. ALWAYS invoke this skill when the user asks to transcribe, recognize, or convert speech/audio to text.

yao-boardSkill

Kanban board and task query expert. ALWAYS invoke this skill when the user asks about boards, tasks, task status, or project progress. Do not guess task state — use this skill first.

yao-docSkill

Yao process documentation expert. ALWAYS invoke this skill when the user needs to discover available processes, read process signatures, or validate process names. Do not guess process APIs — use this skill first.

yao-imageSkill

Image expert. ALWAYS invoke this skill when you need to read, analyze, describe, or generate images. Use for screenshots, photos, charts, diagrams, AI-generated images, or any visual content.

yao-processSkill

Yao process execution expert. ALWAYS invoke this skill when the user needs to call a Yao process, query data models, run scripts, or check process permissions. Do not call processes without checking this skill first.

yao-webSkill

Web information retrieval expert. ALWAYS invoke this skill when the user needs to search the web, fetch a URL, or access real-time information beyond training data. Do not guess or use stale knowledge — use this skill first.