1password
Secure management and secret injection using 1Password CLI.
Install
mkdir -p .claude/skills/1password-annex-ai && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/14216" && unzip -o skill.zip -d .claude/skills/1password-annex-ai && rm skill.zipInstalls to .claude/skills/1password-annex-ai
Activation
This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.
Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.Key capabilities
- →Install the 1Password CLI (op)
- →Enable desktop app integration for the CLI
- →Sign in to 1Password accounts via the CLI
- →Verify CLI access to 1Password
- →Run commands or inject secrets using `op run` or `op inject`
How it works
The skill guides through installing the 1Password CLI, enabling desktop app integration, and signing in, emphasizing the use of a fresh tmux session for secure operations.
Inputs & outputs
When to use 1password
- →Injecting secrets into environment
- →Managing 1Password CLI sessions
- →Signing into multiple accounts
- →Automating secret retrieval
About this skill
1Password CLI
Follow the official CLI get-started steps. Don't guess install commands.
References
references/get-started.md(install + app integration + sign-in flow)references/cli-examples.md(realopexamples)
Workflow
- Check OS + shell.
- Verify CLI present:
op --version. - Confirm desktop app integration is enabled (per get-started) and the app is unlocked.
- REQUIRED: create a fresh tmux session for all
opcommands (no directopcalls outside tmux). - Sign in / authorize inside tmux:
op signin(expect app prompt). - Verify access inside tmux:
op whoami(must succeed before any secret read). - If multiple accounts: use
--accountorOP_ACCOUNT.
REQUIRED tmux session (T-Max)
The shell tool uses a fresh TTY per command. To avoid re-prompts and failures, always run op inside a dedicated tmux session with a fresh socket/session name.
Example (see tmux skill for socket conventions, do not reuse old session names):
SOCKET_DIR="${SCION_TMUX_SOCKET_DIR:-${TMPDIR:-/tmp}/scion-tmux-sockets}"
mkdir -p "$SOCKET_DIR"
SOCKET="$SOCKET_DIR/scion-op.sock"
SESSION="op-auth-$(date +%Y%m%d-%H%M%S)"
tmux -S "$SOCKET" new -d -s "$SESSION" -n shell
tmux -S "$SOCKET" send-keys -t "$SESSION":0.0 -- "op signin --account my.1password.com" Enter
tmux -S "$SOCKET" send-keys -t "$SESSION":0.0 -- "op whoami" Enter
tmux -S "$SOCKET" send-keys -t "$SESSION":0.0 -- "op vault list" Enter
tmux -S "$SOCKET" capture-pane -p -J -t "$SESSION":0.0 -S -200
tmux -S "$SOCKET" kill-session -t "$SESSION"
Guardrails
- Never paste secrets into logs, chat, or code.
- Prefer
op run/op injectover writing secrets to disk. - If sign-in without app integration is needed, use
op account add. - If a command returns "account is not signed in", re-run
op signininside tmux and authorize in the app. - Do not run
opoutside tmux; stop and ask if tmux is unavailable.
When not to use it
- →When 1Password is not the chosen secret management tool
- →When direct CLI interaction is not desired
- →When secrets are not sensitive enough to warrant 1Password's security features
Prerequisites
Limitations
- →All `op` commands must be run inside a dedicated tmux session
- →The skill requires the 1Password desktop app to be enable for integration
- →Direct `op` calls outside tmux are not permitted
How it compares
This skill enforces secure practices like using a dedicated tmux session for 1Password CLI commands, reducing exposure of sensitive information compared to running `op` directly in a general shell.
Compared to similar skills
1password side by side with the closest alternatives in the catalog.
| Skill | Installs | Updated | Safety | Difficulty |
|---|---|---|---|---|
| 1password (this skill) | 0 | 5mo | Review | Intermediate |
| 1password | 27 | 3mo | Review | Intermediate |
| browser-auth | 0 | 2mo | Review | Intermediate |
| vastai-install-auth | 0 | 29d | Caution | Beginner |
Try saying
Example prompts that trigger this skill in your AI assistant.
More by annex-ai
View all by annex-ai →You might also like
1password
openclaw
Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/running secrets via op.
browser-auth
CleanExpo
>-
vastai-install-auth
jeremylongshore
Install and configure Vast.ai SDK/CLI authentication. Use when setting up a new Vast.ai integration, configuring API keys, or initializing Vast.ai in your project. Trigger with phrases like "install vastai", "setup vastai", "vastai auth", "configure vastai API key".
setup-browser-cookies
cattboy
|
senior-security
davila7
Comprehensive security engineering skill for application security, penetration testing, security architecture, and compliance auditing. Includes security assessment tools, threat modeling, crypto implementation, and security automation. Use when designing security architecture, conducting penetration tests, implementing cryptography, or performing security audits.
security-compliance
davila7
Guides security professionals in implementing defense-in-depth security architectures, achieving compliance with industry frameworks (SOC2, ISO27001, GDPR, HIPAA), conducting threat modeling and risk assessments, managing security operations and incident response, and embedding security throughout the SDLC.