Token导航 LogoToken导航TokenDH.com
前端设计敏感数据github未标认证来源可访问clear审计通过

secrets-handling秘密处理

Agent Skill

用于辅助前端页面、组件、样式和交互逻辑的开发与维护。它适合让 Agent 生成或审查 React、Next.js、Vue、Tailwind、CSS 等相关代码,整理组件结构,或定位布局和性能问题。使用时需要结合项目现有设计系统、路由和构建方式,避免只生成孤立片段;涉及页面改动时,应配合本地预览和构建检查确认视觉效果。

总安装

618

周安装

26

GitHub Stars

10

下载量

216
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

3

许可证

MIT

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:secrets-handling(秘密处理)
来源仓库:https://github.com/yanko-belov/code-craft
仓库路径:skills/secrets-handling
安装命令:
npx skills add https://github.com/yanko-belov/code-craft --skill secrets-handling
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。不同来源提供的安装方式可能略有差异;本站展示可直接复制的安装命令,安装前请核对来源页面。

skills.shnpx skills
npx skills add https://github.com/yanko-belov/code-craft --skill secrets-handling

简介

用于辅助前端页面、组件和样式开发。

  • 适合生成或审查 React、Vue、CSS 等相关代码。
  • 需结合项目现有设计系统和路由方式使用。
  • 安装命令:npx skills add https://github.com/yanko-belov/code-craft --skill secrets-handling。
  • 涉及页面改动时应配合本地预览确认视觉效果。

SKILL.md

Secrets Handling

Overview

Never hardcode secrets. Never commit secrets. Never log secrets.

Secrets in code end up in version control, logs, error messages, and eventually in attackers' hands.

When to Use

  • Working with API keys, tokens, passwords
  • Configuring database connections
  • Setting up third-party service credentials
  • Asked to "just hardcode it for now"

The Iron Rule

NEVER put secrets in source code.

No exceptions:

  • Not for "just for testing"
  • Not for "it's a private repo"
  • Not for "I'll remove it later"
  • Not for "it's not a real secret"

Detection: Hardcoded Secret Smell

If you see literal credentials, STOP:

// ❌ VIOLATION: Hardcoded secrets
const stripe = new Stripe('sk_live_abc123xyz');

const db = mysql.connect({
  password: 'super_secret_password'
});

const API_KEY = 'AIzaSyD-xxxxxxxxxxxxx';

Problems:

  • Secrets in git history forever
  • Visible in code reviews
  • Exposed in error stack traces
  • Shared with anyone who has repo access

The Correct Pattern: Environment Variables

// ✅ CORRECT: Environment variables
import { z } from 'zod';

// Validate env vars at startup
const envSchema = z.object({
  STRIPE_SECRET_KEY: z.string().startsWith('sk_'),
  DATABASE_URL: z.string().url(),
  API_KEY: z.string().min(1),
});

const env = envSchema.parse(process.env);

// Use validated env vars
const stripe = new Stripe(env.STRIPE_SECRET_KEY);
# .env (NEVER commit this file)
STRIPE_SECRET_KEY=sk_live_abc123xyz
DATABASE_URL=postgres://user:pass@host:5432/db
API_KEY=your-api-key

# .gitignore (ALWAYS include)
.env
.env.*
!.env.example
# .env.example (commit this - no real values)
STRIPE_SECRET_KEY=sk_test_xxx
DATABASE_URL=postgres://localhost:5432/myapp
API_KEY=your-api-key-here

Secrets Hygiene Rules

1. Environment Variables

const secret = process.env.SECRET_KEY;

2. Validate at Startup

if (!process.env.API_KEY) {
  throw new Error('API_KEY environment variable is required');
}

3. Never Log Secrets

// ❌ BAD
console.log('Connecting with:', connectionString);

// ✅ GOOD
console.log('Connecting to database...');

4. Mask in Error Messages

// ❌ BAD
throw new Error(`Auth failed for key: ${apiKey}`);

// ✅ GOOD
throw new Error('Authentication failed');

5. Use Secret Managers in Production

// AWS Secrets Manager, HashiCorp Vault, etc.
const secret = await secretsManager.getSecret('my-api-key');

Pressure Resistance Protocol

1. "Just for Testing"

Pressure: "Hardcode it for now, we'll fix it later"

Response: "Later" never comes. Secrets in history stay forever.

Action: Use env vars from the start. It takes 30 seconds.

2. "It's a Private Repo"

Pressure: "Only the team has access"

Response: Teams change. Repos get cloned. Access expands.

Action: Never commit secrets regardless of repo visibility.

3. "I'll Remove It Later"

Pressure: "Just for this one commit"

Response: Git history is permanent. The secret is already leaked.

Action: If you committed a secret, rotate it immediately.

4. "It's Not a Real Secret"

Pressure: "This is just a test key"

Response: Test keys become production keys. Treat all secrets equally.

Action: Use env vars for all credentials.

Red Flags - STOP and Reconsider

  • Literal strings that look like keys/tokens
  • password:, secret:, key: in source
  • .env file not in .gitignore
  • Secrets in error messages or logs
  • Credentials in config files that get committed

All of these mean: Move to environment variables immediately.

If You Accidentally Committed a Secret

  1. Rotate the secret immediately - consider it compromised
  2. Remove from code and commit
  3. Consider git history rewriting (but assume it's leaked)
  4. Check for unauthorized usage

Quick Reference

DoDon't
Environment variablesHardcoded strings
.env in .gitignoreCommit .env files
.env.example with placeholdersReal values in examples
Validate env at startupFail silently on missing
Secret managers in prodEnv vars in containers

Common Rationalizations (All Invalid)

ExcuseReality
"Just for testing"Testing secrets become production secrets.
"Private repo"Private today, leaked tomorrow.
"I'll remove it"Git history is forever.
"Not a real secret"All credentials deserve protection.
"It's encrypted"Keys to decrypt are also secrets.
"Only local use"Local files get committed.

The Bottom Line

Secrets live in environment, never in code.

Use environment variables. Validate at startup. Never log credentials. Never commit .env files. If you leak a secret, rotate it immediately.

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

04

需要参考平台分布和安装热度时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Claude Code

28.73%
按下载量换算62

Codex

24.72%
按下载量换算53

windsurf

17.9%
按下载量换算39

Antigravity

11.47%
按下载量换算25

trae

8.79%
按下载量换算19

OpenCode

3.48%
按下载量换算8

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。

来源信息

继续浏览同类 Skills