Borrowing it
Nothing to install: this file belongs to markmhendrickson/neotoma. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/markmhendrickson/neotoma/main/.claude/skills/sync-env-from-1password/SKILL.mdgit clone --depth 1 https://github.com/markmhendrickson/neotomaWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/markmhendrickson/neotoma/sync-env-from-1password)<a href="https://agentmods.dev/skills/markmhendrickson/neotoma/sync-env-from-1password"><img src="https://agentmods.dev/badge/skills/markmhendrickson/neotoma/sync-env-from-1password/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/markmhendrickson/neotoma/sync-env-from-1password"><img src="https://agentmods.dev/badge/skills/markmhendrickson/neotoma/sync-env-from-1password.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00014 | $0.01929 |
| Opus 5 | $0.00007 | $0.00964 |
| Sonnet 5 | $0.00003 | $0.00386 |
| Haiku 4.5 | $0.00001 | $0.00193 |
Grade A, and why
sync-env-from-1password scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 9d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
Copies of this mod
2 near-identical copies found in the catalogue:
- sync-env-from-1password — 95% identical, 7 lines differ
- sync_env_from_1password — 89% identical, 12 lines differ
How it starts
The opening of the file, as written. The whole thing — 310 lines — stays where its author put it; the contents beside it link to each section on GitHub.
name: sync-env-from-1password description: Sync .env from 1Password using env_var_mappings. triggers:
- sync env from 1password
- /sync_env_from_1password
- sync-env-from-1password
Sync Environment Variables from 1Password
Sync environment variables from 1Password to local .env file using environment variable mappings stored in the truth layer (per neotoma_parquet_migration_rules.mdc).
Command
sync_env_from_1password
or
sync env from 1password
Purpose
This command syncs environment variables from 1Password to your local .env file based on mappings stored in the truth layer (per neotoma_parquet_migration_rules.mdc). Parquet path when used: $DATA_DIR/env_var_mappings/env_var_mappings.parquet.
Key features:
- Automatic backup before modification
- Preserves unmanaged environment variables
- Never prints secret values
- Supports environment-based keys (e.g., different API keys for dev/prod)
- Uses 1Password MCP server (preferred) or CLI (fallback)
Prerequisites
Option 1: 1Password MCP Server (Recommended)
Benefits:
- Persistent connection (no session expiration)
- Better error handling
- No repeated authentication
- Consistent with other MCP integrations
Setup:
-
Ensure 1Password CLI is installed:
brew install 1password-cli op signin -
Configure MCP server in
~/.cursor/mcp.json:{ "mcpServers": { "onepassword": { "command": "bash", "args": [ "/Users/markmhendrickson/repos/ateles/mcp/onepassword/run-onepassword-mcp.sh" ], "env": {} } } } -
Verify MCP server is running:
- Restart Cursor after updating mcp.json
- MCP server status visible in Cursor MCP panel
For detailed setup instructions, see: mcp/onepassword/README.md
Option 2: 1Password CLI (Fallback)
When to use:
- MCP server not configured
- Temporary/one-off sync
- Troubleshooting MCP issues
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 9d ago First seen · 310 lines · 14 tokens per session scan A 8ee678facada
sync-env-from-1password is a skill published in the GitHub repository markmhendrickson/neotoma (32 stars, last pushed today), licensed MIT. It adds 14 tokens to every session and 1,929 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
akf-trust-metadata
The AI native file format. EXIF for AI — stamps every file with trust scores, source provenance, and compliance metadata. Embeds into 20+ formats (DOCX, PDF, images, code). EU AI Act, SOX, HIPAA auditing.
bilibili_search
Search for videos on Bilibili using keyword queries generated from user interests.
bernstein-approve
Review and approve/reject pending tasks or plans in Bernstein. Use when the user asks about approvals, wants to review agent work, or needs to approve/reject a plan before execution begins.
bernstein-quality
Show quality metrics for Bernstein runs - success rates per model, lint/test pass rates, completion time distributions. Use when the user asks about quality, reliability, which model performs best, or pass rates.
manager
Planning - decompose goals, create tasks via task server.
Supply Chain Security
Software supply chain security — SBOM generation and analysis, dependency confusion and typosquatting detection, malicious package indicators, CI/CD pipeline hardening, and artifact provenance/signing (SLSA, Sigstore).