Secret management expert. ALWAYS invoke this skill when you need to read API keys, tokens, or other secrets configured by the user. Never hardcode credentials — use this skill to retrieve them securely.
npx skills add https://github.com/YaoApp/yao --skill yao-secret
Two tools for accessing user-configured secrets, called via bash.
List available secret names and descriptions. Does not return secret values — use secret_read for that.
tai tool secret_list '{}'
No parameters required. Returns secrets configured for the current assistant.
Read a secret value by name. Returns the decrypted value for use in scripts.
tai tool secret_read '{"name": "GITHUB_TOKEN"}'
tai tool secret_read '{"name": "AWS_SECRET_KEY"}'
| Parameter | Type | Required | Description |
|-----------|--------|----------|----------------------------------------------------------|
| name | string | yes | Secret key name (e.g. GITHUB_TOKEN, AWS_SECRET_KEY) |
Security: Never log, print, or expose the returned secret value in output visible to users.
secret_list — discover what secrets are availablesecret_read — retrieve a specific secret by namesecret_list first to check if a required secret exists before readingsecret_readTake yaoapp/yao-secret from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.