Secret Tools

SkillSecurity

Lets your agent retrieve API keys and tokens from the user's configured secrets instead of hardcoding them.

Available today. Use it from your connected AI after setup.

Connect ahel once, and every AI you use reads what you have installed.

Then ask your AI: use the Secret Tools skill

About this capability

Secret management expert. ALWAYS invoke this skill when you need to read API keys, tokens, or other secrets configured by the user. Never hardcode credentials — use this skill to retrieve them securely.

What this skill tells your AI

The instructions your AI receives, as published by yaoapp/yao in tools/skills/yao-secret/SKILL.md and read by ahel’s review.

Two tools for accessing user-configured secrets, called via bash.

secret_list

List available secret names and descriptions. Does not return secret values — use secret_read for that.

tai tool secret_list '{}'

No parameters required. Returns secrets configured for the current assistant.

secret_read

Read a secret value by name. Returns the decrypted value for use in scripts.

tai tool secret_read '{"name": "GITHUB_TOKEN"}'
tai tool secret_read '{"name": "AWS_SECRET_KEY"}'
ParameterTypeRequiredDescription
namestringyesSecret key name (e.g. GITHUB_TOKEN, AWS_SECRET_KEY)

Security: Never log, print, or expose the returned secret value in output visible to users.

Typical Workflow

  1. secret_list — discover what secrets are available
  2. secret_read — retrieve a specific secret by name
  3. Use the value in API calls, git auth, etc.

Guidelines

  • Always call secret_list first to check if a required secret exists before reading
  • Never hardcode API keys or tokens — always use secret_read
  • Secret values are decrypted at read time; treat them as sensitive
  • If a secret is not found, prompt the user to configure it in their settings
  • All output is JSON

Signals

GitHub stars
8k
Forks
708
Last commit
Sep 2026
Advanced
Catalog kind
skill
Gateway key
yao-secret
Source
github.com/yaoapp/yao