ship-it
78Ship Changes Through Pull Requests and CI
Finishing a change requires careful verification, commits, pull-request setup, and CI follow-through. This skill manages that workflow until every check passes.
Manage SOPS Secrets in Repositories
Encrypted repository secrets require careful commands, keys, and environment handling. This skill guides SOPS workflows through an existing pnpm secrets wrapper.
لا تثبّت هذا Skill تلقائيًا.
تتطلب السياسة المعتمدة مراجعة المشغّل قبل أي إجراء تثبيت.
انسخ هذا الطلب إلى Agent لديك. يتضمن صفحة Skill المعتمدة وملف manifest.
Review the Skillstore skill "using-sops" from https://skillstore.io/skills/jssblck-using-sops.md and its manifest at https://skillstore.io/api/skills/jssblck-using-sops/manifest. Verify the artifact. Do not auto-install. Inspect the skill and report your findings, then wait for an operator or manual installation decision.يجب أن يواصل Agent عرض خطته وطلب أي تأكيد تفرضه سياسة الأمان.
استخدم هذه الروابط عندما يحتاج AI Agent أو crawler أو script إلى سياق نظيف بدلًا من قراءة الصفحة كاملة.
جارٍ استخدام "using-sops". Retrieve the development Stripe key without showing other secrets.
النتيجة المتوقعة:
The assistant identifies the repository wrapper, requests confirmation, retrieves only the named value, and avoids echoing unrelated decrypted data.
جارٍ استخدام "using-sops". Add a required API endpoint to every accessible environment.
النتيجة المتوقعة:
جارٍ استخدام "using-sops". Rotate a lost production recipient.
النتيجة المتوقعة:
The assistant lists recipient replacement, file re-encryption, value rotation, deployment updates, verification, and encrypted history exposure.
The skill intentionally grants agents broad access to encrypted development secrets and supports persistent production elevation. The most serious design stores a shared private key in persistent cloud environment variables, creating cross-project credential exposure.
هذه قدرات محلية حقيقية قد يُتوقع وجودها لهذه المهارة، لذا فهي تتطلب مراجعة ولكن لا تُحتسب كسلوك خبيث مؤكد.
شارك تقرير التقييم المرتبط بالإصدار والشارة المحايدة وبطاقة التضمين والاستشهادات. تعرض Skillstore الأدلة من دون أن تقرر ما إذا كانت هذه المهارة آمنة.
https://skillstore.io/skills/jssblck-using-sops/audits/1?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/jssblck-using-sops?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/jssblck-using-sops?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/jssblck-using-sops/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/jssblck-using-sops.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>jssblck. (2026). using-sops security audit report (audit version 1) [Author version unspecified]. Skillstore. https://skillstore.io/skills/jssblck-using-sops/audits/1@techreport{jssblck-jssblck-using-sops-2026,
author = {jssblck},
title = {using-sops security audit report (audit version 1)},
institution = {Skillstore},
year = {2026},
number = {1},
url = {https://skillstore.io/skills/jssblck-using-sops/audits/1},
note = {Author version unspecified}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "using-sops security audit report (audit version 1)"
version: "unspecified"
type: report
authors:
- name: "jssblck"
date-released: "2026-08-23"
url: "https://skillstore.io/skills/jssblck-using-sops/audits/1"
identifiers:
- type: other
value: "skillstore:jssblck-using-sops:audit:1"
description: "Skillstore immutable audit report identifier"
Inspect or change an encrypted development variable through the repository wrapper.
Prepare production decryption and service startup while keeping the key outside application files.
Replace a lost or compromised age recipient and re-encrypt affected secret files.
Use the repository secrets wrapper to retrieve [VARIABLE] from development. Explain the command first and avoid displaying unrelated values.
Add [VARIABLE] to the development secrets and environment schema. Confirm before changing files and report any environment you cannot decrypt.
Run [COMMAND] with development secrets through the repository wrapper. Verify the command scope and do not print decrypted values.
Review the SOPS recipients for [PROJECT]. Propose a rotation plan for [COMPROMISED_RECIPIENT], including affected files, approvals, re-encryption, and credential replacement.
المؤلف
jssblckالترخيص
MIT
مراجعة Skillstore
r1
تنبيه الإصدار
لم يعلن المؤلف عن إصدار.
المستودع
https://github.com/jssblck/agents/tree/4658295e88faed205cc134edf987f7ea4e0c8ea4/skills/using-sopsمرجع
0139ec01bdea5a1eaac3b0e3c90753dbfe65aaa1
حداثة الصيانة
٢٣/٨/٢٠٢٦
الاستخدام
0 تنزيلات · 0 مشاهدات
بنية الملفات
Ship Changes Through Pull Requests and CI
Finishing a change requires careful verification, commits, pull-request setup, and CI follow-through. This skill manages that workflow until every check passes.
Remove Machine-Written Tells from Durable Prose
Durable prose can sound generic when rhetoric obscures concrete facts. This skill removes formulaic patterns while preserving meaning, technical details, and voice.
Manage Stacked Pull Requests with gh-stack
Dependent pull requests are difficult to organize, update, and merge safely. This skill guides reliable gh-stack workflows for linear branch stacks.
Coordinate Parallel Agents With Fewer Conflicts
Parallel coding agents often collide in shared files and documentation. This skill provides structural and editing practices that reduce merge conflicts.
Merge Open Pull Requests as One Stack
Merging several open pull requests together requires careful ordering, conflict handling, and repeated verification. This skill builds one GitHub stack and merges it through repository protections.
Build Reliable Code with Durable Principles
Inconsistent engineering choices make code harder to review and maintain. This skill applies clear design, testing, error, and tooling defaults across common languages.
بناء حزم قيادة الحوادث المحكومة
بواسطة yaojingang
غالبا ما تفتقر ملاحظات الحوادث إلى وضوح في درجة الخطورة والملكية والتواصل المخصص لكل جمهور. تحول هذه المهارة الأدلة التشغيلية إلى حزمة محكومة للاستجابة والمراجعة والمتابعة.
أتمتة مسارات DevOps وعمليات النشر
بواسطة alirezarezvani
غالبا ما يتطلب عمل DevOps أنماطا قابلة للتكرار للمسارات والبنية التحتية وعمليات النشر. توفر هذه المهارة نصوصا إرشادية وأدلة مرجعية لمراجعة CI/CD وIaC والنشر والعمليات.
تنسيق سير عمل DevOps السحابي
بواسطة sickn33
غالبًا ما يمتد عمل تسليم السحابة عبر العديد من الأدوات والمراحل. تنظم هذه المهارة أعمال البنية التحتية، وCI/CD، وKubernetes، والمراقبة، والأمان، والتكاليف، والاسترداد في مطالبات واضحة.
بناء وحدات Terraform أفضل
بواسطة sickn33
غالبا ما تنمو مشاريع Terraform لتصبح وحدات غير متسقة، واختبارات غير واضحة، وسير عمل إصدارات محفوفا بالمخاطر. تمنح هذه المهارة Claude وCodex وClaude Code أنماط Terraform وOpenTofu عملية لتسليم بنية تحتية أكثر أمانا.
تصميم بنية Helm Chart للإنتاج
بواسطة 92Bilal26
غالبًا ما تنسخ الفرق أمثلة Helm لا تتوافق مع قيودها التشغيلية. توجه هذه المهارة بنية Chart عبر التبعيات، والخطافات، والقيم، والبيئات، واحتياجات المشغلين.
إنشاء Kubernetes Manifests بأمان
بواسطة sickn33
يسهل إساءة ضبط Kubernetes manifests عندما تكتبها الفرق من الذاكرة. تحوّل هذه المهارة المتطلبات إلى إرشادات YAML منظمة تتضمن الأمان، والفحوصات، والموارد، وأنماط Service.