CtrlK
BlogDocsLog inGet started
Tessl Logo

secret-guard

Lets an agent authenticate to APIs and MCP servers WITHOUT ever seeing secret values. Use whenever a task needs an API token, MCP token, password, or key. The agent passes a credential *reference* (a name); a trusted non-LLM broker resolves it from the OS keyring, injects it into the request, scrubs the response, and returns only scrubbed output. The secret value never enters the agent's context or the LLM.

68

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-crafted policy skill: executable copy-paste broker commands, a clear primary/fallback mechanism decision with a discouraged-path rationale, hard Never-Do rules, and a real, properly referenced implementation script. It falls just short of top marks due to repeated restatement of the core invariant, an advisory-only MCP section, and the absence of any explicit verification or failure-handling step for broker outcomes.

Suggestions

Consolidate the repeated 'the secret never enters your context' statements (currently ~6 phrasings across Core Principle, mechanisms, and Reference Implementation) into one authoritative statement plus the Never-Do list.

Add one concrete MCP example (e.g., a snippet of server config using ${input:...} or env indirection with a named credential) so the MCP authentication path is as executable as the API path.

Add a short verification step for broker outcomes — e.g., what to do when the broker reports a missing keyring entry or a failed request, mirroring the existing 'no keyring entry exists' recovery guidance.

DimensionReasoningScore

Conciseness

The body is imperative and free of concepts Claude already knows, but the core invariant is restated roughly six times ('You never possess a secret value', 'never enters the model's context window', 'You never see the value', 'exists only inside the broker process', 'never written to stdout/stderr, never logged, never returned'). Minor over-explanation that could be trimmed fits anchor 4 rather than 5.

4 / 5

Actionability

Both mechanisms get copy-paste-ready commands ('python3 scripts/keyring_broker.py request --name github_token --url ... --header "Authorization: Bearer {secret}"' and the exec example), but the MCP-server subsection is advisory only ('Prefer OAuth flows', 'Use ${input:...}/env indirection') with no executable example despite MCP being a stated use case. Mostly executable with minor gaps fits anchor 4.

4 / 5

Workflow Clarity

The primary-vs-fallback decision is clearly sequenced with rationale for each, and an error-recovery path exists ('If a secret is unavoidable and no keyring entry exists, ask the user to run keyring set ...'). Not a destructive/batch skill, so no cap applies; but there is no explicit verification step (e.g., how to confirm output was scrubbed or handle broker failure), fitting anchor 4 rather than 5.

4 / 5

Progressive Disclosure

Verified against the actual bundle: scripts/keyring_broker.py exists, is correctly pathed, is used in both examples, and is explicitly signaled in the Reference Implementation section, with implementation appropriately split out of the policy body. Minor gap: the broker's full CLI surface and MCP-config patterns are only inline in the ~100-line body with no separate reference doc, fitting anchor 4 rather than 5.

4 / 5

Total

16

/

20

Passed

Description

88%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it concretely explains the reference-based broker mechanism in third person and gives an explicit 'Use whenever...' trigger clause. The only weakness is trigger breadth — a few common synonyms (API key, credentials) are missing and the wide trigger phrasing creates minor overlap risk with general API-usage skills.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions — 'passes a credential *reference* (a name); a trusted non-LLM broker resolves it from the OS keyring, injects it into the request, scrubs the response, and returns only scrubbed output' — with comprehensive coverage of the mechanism in third-person voice. No meaningful coverage gaps, so it fits the top anchor rather than 4.

5 / 5

Completeness

Both questions are answered explicitly and concretely: what ('a trusted non-LLM broker resolves it from the OS keyring, injects it into the request, scrubs the response') and when ('Use whenever a task needs an API token, MCP token, password, or key'). This matches the top anchor exactly.

5 / 5

Trigger Term Quality

'Use whenever a task needs an API token, MCP token, password, or key' provides good natural keyword coverage (token, password, key, authenticate), but common variants users would actually say — 'API key', 'credentials', 'login' — are missing. Good coverage with a few natural terms absent fits anchor 4, not 5.

4 / 5

Distinctiveness Conflict Risk

The keyring-broker niche is clearly distinct from other skills, but the trigger 'whenever a task needs an API token, MCP token, password, or key' is broad and could fire on many ordinary API-usage tasks that overlap with provider-specific skills. Mostly distinct with minor overlap risk fits anchor 4 rather than 5.

4 / 5

Total

18

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
canonical/copilot-collections
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.