CtrlK
BlogDocsLog inGet started
Tessl Logo

get-env-var

get an env var, fetch a secret, missing env var, missing token/API key, load secrets from Infisical, infisical. Fetch secrets from the team's Infisical workspace into the shell environment so subsequent commands can use them.

71

Quality

86%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

The canonical home for this skill is get-env-var in different-ai/openwork

SKILL.md
Quality
Evals
Security

Quality

Content

100%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is an exemplary short-form skill: every command is executable, setup and usage are cleanly separated, and rare failure paths (auth failure, missing secret) have explicit stop-and-recover guidance. It contains no filler, no explanations of known concepts, and needs no bundle files at its size.

DimensionReasoningScore

Conciseness

The body is ~48 lines of pure instruction with zero padding — "Never echo, print, or otherwise log secret values" and the one-line commands explain nothing Claude already knows. Every token earns its place, matching the lean-and-efficient anchor exactly rather than the minor-over-explanation anchor at 4.

5 / 5

Actionability

All guidance is copy-paste executable: `brew install infisical/get-cli/infisical`, `infisical user get`, `export NAME="$(infisical secrets get NAME --plain --silent)"`, and `infisical run -- <command>`, with concrete flag variants (`--env <slug>`, `--path /some/folder`) covering the common cases. This matches the fully-executable anchor, exceeding anchor 4's "minor gaps".

5 / 5

Workflow Clarity

For a simple single-purpose skill, each action is unambiguous, and the content includes explicit validation checkpoints with feedback loops: "Check auth with `infisical user get`; if it fails, run `infisical login`" and "If a secret does not exist, STOP and tell the user exactly which secret name and environment to add". Not a destructive or batch operation, so the cap at 3 does not apply; this matches the explicit-validation anchor.

5 / 5

Progressive Disclosure

The skill is under 50 lines with no need for external references (no references/, scripts/, or assets/ directories exist), and it is organized into clear, well-ordered sections (When to use, Setup, Fetch one secret, Inject everything, Rules). Per the rubric's guideline for short simple skills, this scores 5 with well-organized sections alone.

5 / 5

Total

20

/

20

Passed

Description

73%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description pairs a clear, concrete capability statement with an explicit set of natural trigger keywords tied to a specific tool, making it highly discoverable and distinct. Its main weakness is form: the trigger guidance is a keyword list rather than an explicit "Use when..." clause, and the action sentence names only one capability, leaving completeness and specificity just short of top marks.

Suggestions

Convert the keyword list into an explicit trigger clause, e.g., append "Use when a command needs an env var that is not set, a token or API key is missing, or the user asks to load secrets from Infisical."

Name the second core capability in the action sentence (e.g., "...or inject all project secrets into a single command via infisical run") to lift specificity.

Add one or two common synonyms such as "credentials" or "environment variable" to broaden natural trigger coverage.

DimensionReasoningScore

Specificity

"Fetch secrets from the team's Infisical workspace into the shell environment" names the domain and one concrete action, but the action sentence does not enumerate several specific capabilities (e.g., injecting into a command, environment selection). This matches the anchor for naming a domain with 1-2 concrete actions, not the several-actions anchors above.

3 / 5

Completeness

"Fetch secrets from the team's Infisical workspace into the shell environment so subsequent commands can use them" clearly answers "what", and "missing env var, missing token/API key" explicitly states triggering conditions, so "when" is present. It falls short of anchor 5 because the when-guidance is a keyword list rather than an explicit "Use when..." clause with concrete trigger phrases, but exceeds anchor 3 because the when is stated, not merely implied.

4 / 5

Trigger Term Quality

The keyword list "get an env var, fetch a secret, missing env var, missing token/API key, load secrets from Infisical, infisical" covers the natural terms users would say, but misses common synonyms such as "credentials" or the spelled-out "environment variable". Good coverage with a few natural terms missing fits anchor 4 rather than the comprehensive-synonym coverage of anchor 5.

4 / 5

Distinctiveness Conflict Risk

"Fetch secrets from the team's Infisical workspace" names a specific tool with distinct triggers ("infisical", "load secrets from Infisical"), giving it a clear niche with minimal conflict risk against generic skills. This clearly matches the anchor-5 example's specificity.

5 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
Devin-AXIS/iPolloWork
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.