1Password CLI
Use this skill for host-side secret workflows with 1Password CLI.
Default Workflow
- Check whether
opis installed:op --version - If it is missing, tell the user to run:
or install it manually.hybridclaw skill install 1password op - Verify sign-in state:
op whoami op vault list - Confirm the exact vault and item before reading any secret.
- Prefer secret injection over copying values into files or chat.
Safe Read Patterns
List items:
op item list --vault "Engineering"
Inspect an item without dumping every field:
op item get "Prod API" --vault "Engineering"
Read one field only:
op item get "Prod API" --vault "Engineering" --fields label=password
Read by secret reference:
op read "op://Engineering/Prod API/password"
Safe Injection Patterns
Run a command with secrets injected:
op run --env-file=.env.1password -- your-command
Inject a template into a throwaway runtime file:
RUNTIME_ENV="$(mktemp /tmp/runtime.env.XXXXXX)"
chmod 600 "$RUNTIME_ENV"
trap 'rm -f "$RUNTIME_ENV"' EXIT INT TERM
op inject -i .env.template -o "$RUNTIME_ENV"
Prefer /tmp or an untracked runtime path. Do not inject into tracked files unless the user explicitly asks. If you are done before the shell exits, run rm -f "$RUNTIME_ENV" and trap - EXIT INT TERM.
Rules
- Never paste a secret value into chat unless the user explicitly requests it and there is no safer option.
- Never commit, log, or echo secrets into shell history on purpose.
- Default to read-only operations. Creating or editing vault items needs explicit user confirmation.
- If
op whoamifails, stop and tell the user they need to unlock the desktop app or sign in again. - If the task only needs a secret for one command, use
op runinstead of reading the secret into plain text.