Agent Skills
› YaoApp/yao
› yao-secret
yao-secret
GitHub管理用户配置的密钥,提供列出和读取 API 密钥、令牌等敏感信息的功能,严禁硬编码凭据,确保调用安全。
Trigger Scenarios
需要读取 API 密钥或令牌时
配置 Git 认证或调用需认证的 API 时
Install
npx skills add YaoApp/yao --skill yao-secret -g -y
SKILL.md
Frontmatter
{
"name": "yao-secret",
"description": "Secret management expert. ALWAYS invoke this skill when you need to read API keys, tokens, or other secrets configured by the user. Never hardcode credentials — use this skill to retrieve them securely."
}
Secret Tools
Two tools for accessing user-configured secrets, called via bash.
secret_list
List available secret names and descriptions. Does not return secret values — use secret_read for that.
tai tool secret_list '{}'
No parameters required. Returns secrets configured for the current assistant.
secret_read
Read a secret value by name. Returns the decrypted value for use in scripts.
tai tool secret_read '{"name": "GITHUB_TOKEN"}'
tai tool secret_read '{"name": "AWS_SECRET_KEY"}'
| Parameter | Type | Required | Description |
|---|---|---|---|
name |
string | yes | Secret key name (e.g. GITHUB_TOKEN, AWS_SECRET_KEY) |
Security: Never log, print, or expose the returned secret value in output visible to users.
Typical Workflow
secret_list— discover what secrets are availablesecret_read— retrieve a specific secret by name- Use the value in API calls, git auth, etc.
Guidelines
- Always call
secret_listfirst to check if a required secret exists before reading - Never hardcode API keys or tokens — always use
secret_read - Secret values are decrypted at read time; treat them as sensitive
- If a secret is not found, prompt the user to configure it in their settings
- All output is JSON
Version History
- 94ab88a Current 2026-08-20 19:13


