Skill: get-env-var
Fetch a secret from the team's Infisical workspace into the current shell so the next command can use it.
When to use
- A command or script needs an env var that is not set, such as
BLOB_READ_WRITE_TOKEN. - A token, API key, or other secret is missing from the environment.
- The user asks to load secrets from Infisical.
Setup (once per machine)
- Install the CLI on macOS:
brew install infisical/get-cli/infisical. - Check auth with
infisical user get; if it fails, runinfisical loginand complete the browser flow. - For CI or other non-interactive runs, set
INFISICAL_TOKENfrom a machine identity; the CLI skips login when it is present. - This repo is already project-linked via tracked
.infisical.json(workspaceId: "e9f4542a-8714-46c3-a8fd-99d8cb370aeb", emptydefaultEnvironment). From the repo root,infisicaldefaults to thedevenvironment slug when--envis omitted.
Fetch one secret into the environment
Run from the repo root:
export NAME="$(infisical secrets get NAME --plain --silent)"
- Replace
NAMEwith the secret name. - Add
--env <slug>for a non-default environment; this repo defaults todev. - Add
--path /some/folderwhen secrets are organized in folders.
Inject everything into a command
Run the command through Infisical so all project secrets are available only to that process:
infisical run -- <command>
Rules
- Never echo, print, or otherwise log secret values.
- Never write secrets to files, logs, commit messages, PR bodies, or comments.
- Only use
--plaininside command substitution, as inexport NAME="$(...)". - If a secret does not exist, STOP and tell the user exactly which secret name and environment to add in Infisical; do not invent values.
Source: different-ai/openwork → .opencode/skills/get-env-var/SKILL.md