mcpbeat Sign in

Yao Secret Agent Skill

Secret management expert. ALWAYS invoke this skill when you need to read API keys, tokens, or other secrets configured by the user. Never hardcode credentials — use this skill to retrieve them securely.

417 tokens
context cost
the whole folder, loaded on every use
1
files
instructions only
0
copies elsewhere
how many repositories repackaged it
7694
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/YaoApp/yao --skill yao-secret

The instruction itself

5 sections, as written by the author

Secret Tools

Two tools for accessing user-configured secrets, called via bash.

secret_list

List available secret names and descriptions. Does not return secret values — use secret_read for that.

tai tool secret_list '{}'

No parameters required. Returns secrets configured for the current assistant.

secret_read

Read a secret value by name. Returns the decrypted value for use in scripts.

tai tool secret_read '{"name": "GITHUB_TOKEN"}'
tai tool secret_read '{"name": "AWS_SECRET_KEY"}'

| Parameter | Type | Required | Description |

|-----------|--------|----------|----------------------------------------------------------|

| name | string | yes | Secret key name (e.g. GITHUB_TOKEN, AWS_SECRET_KEY) |

Security: Never log, print, or expose the returned secret value in output visible to users.

Typical Workflow

  • secret_list — discover what secrets are available
  • secret_read — retrieve a specific secret by name
  • Use the value in API calls, git auth, etc.

Guidelines

  • Always call secret_list first to check if a required secret exists before reading
  • Never hardcode API keys or tokens — always use secret_read
  • Secret values are decrypted at read time; treat them as sensitive
  • If a secret is not found, prompt the user to configure it in their settings
  • All output is JSON

How to use it

Copy the folder

Take yaoapp/yao-secret from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.