Generative-AI-for-beginners-dotnet: Skill for Claude Code

.github/skills/secret-handling/SKILL.md

secret-handling is a skill for Claude Code, Codex from microsoft/Generative-AI-for-beginners-dotnet. It costs 19 tokens per session (1,998 once invoked), scanned A, a copy of secret-handling, MIT.

A safety guide for handling environment files and other files that may contain passwords, tokens, or other private credentials.

In plain words
What is it for?
Use it when working in repositories with .env files, especially when documenting decisions, configuring tools, or asking for connection details. It directs agents toward safe examples and documentation instead.
Why use it?
It prevents agents from exposing secrets by reading them and copying them into committed project logs or records.

Skill for Claude CodeCodex ✓ vendor

Written for no agent in particular: nothing here depends on one.

This is microsoft/Generative-AI-for-beginners-dotnet's own configuration. It tells Claude Code and Codex how to work on Generative-AI-for-beginners-dotnet itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything Generative-AI-for-beginners-dotnet configures →

About the project

Generative AI for Beginners .NET is a hands-on course that teaches .NET developers to build applications using generative AI models and related tools. Its lessons use practical samples covering scenarios such as chat, audio transcription, agents, and local AI. The catalogue entries are add-ons associated with the course repository.

microsoft/Generative-AI-for-beginners-dotnet · 3,057 stars · on GitHub · aka.ms

Reuse

Borrowing it

Nothing to install: this file belongs to microsoft/Generative-AI-for-beginners-dotnet. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/microsoft/Generative-AI-for-beginners-dotnet/main/.github/skills/secret-handling/SKILL.md
Clone the repo
git clone --depth 1 https://github.com/microsoft/Generative-AI-for-beginners-dotnet

Made for: Claude Code, Codex.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for secret-handling

README.md
[![agentmods](https://agentmods.dev/badge/skills/microsoft/generative-ai-for-beginners-dotnet/secret-handling/github.svg)](https://agentmods.dev/skills/microsoft/generative-ai-for-beginners-dotnet/secret-handling)
Your own site
<a href="https://agentmods.dev/skills/microsoft/generative-ai-for-beginners-dotnet/secret-handling"><img src="https://agentmods.dev/badge/skills/microsoft/generative-ai-for-beginners-dotnet/secret-handling/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for secret-handling

Your own site · 80×15
<a href="https://agentmods.dev/skills/microsoft/generative-ai-for-beginners-dotnet/secret-handling"><img src="https://agentmods.dev/badge/skills/microsoft/generative-ai-for-beginners-dotnet/secret-handling.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 19 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,998 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin 100% copy Near-identical to another mod in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00019 $0.01998
Opus 5 $0.00010 $0.00999
Sonnet 5 $0.00004 $0.00400
Haiku 4.5 $0.00002 $0.00200

Measured 10d ago against content hash b9222aa13274, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-09, from the pricing page.

Security

Grade A, and why

secret-handling scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

This is a copy

100% identical to secret-handling — 0 lines differ, which has more behind it and is treated as the original. This page carries a canonical link to it rather than competing with it.

.github/skills/secret-handling/SKILL.md · 201 lines

How it starts

The opening of the file, as written. The whole thing — 201 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Context

Spawned agents have read access to the entire repository, including .env files containing live credentials. If an agent reads secrets and writes them to .squad/ files (decisions, logs, history), Scribe auto-commits them to git, exposing them in remote history. This skill codifies absolute prohibitions and safe alternatives.

Patterns

Prohibited File Reads

NEVER read these files:

  • .env (production secrets)
  • .env.local (local dev secrets)
  • .env.production (production environment)
  • .env.development (development environment)
  • .env.staging (staging environment)
  • .env.test (test environment with real credentials)
  • Any file matching .env.* UNLESS explicitly allowed (see below)

Allowed alternatives:

  • .env.example (safe — contains placeholder values, no real secrets)
  • .env.sample (safe — documentation template)
  • .env.template (safe — schema/structure reference)

If you need config info:

  1. Ask the user directly — "What's the database connection string?"
  2. Read .env.example — shows structure without exposing secrets
  3. Read documentation — check README.md, docs/, config guides

NEVER assume you can "just peek at .env to understand the schema." Use .env.example or ask.

Prohibited Output Patterns

NEVER write these to .squad/ files:

Pattern Type Examples Regex Pattern (for scanning)
API Keys OPENAI_API_KEY=sk-proj-..., GITHUB_TOKEN=ghp_... `[A-Z_]+(?:KEY
Passwords DB_PASSWORD=super_secret_123, password: "..." `(?:PASSWORD
Connection Strings postgres://user:pass@host:5432/db, Server=...;Password=... `(?:postgres
JWT Tokens eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9... eyJ[A-Za-z0-9_-]+\.eyJ[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+
Private Keys -----BEGIN PRIVATE KEY-----, -----BEGIN RSA PRIVATE KEY----- -----BEGIN [A-Z ]+PRIVATE KEY-----
AWS Credentials AKIA..., aws_secret_access_key=... `AKIA[0-9A-Z]{16}
Email Addresses [email protected] (PII violation per team decision) [a-zA-Z0-9._%+-]+@[a-zA-Z0-9.-]+\.[a-zA-Z]{2,}

Read the full file on GitHub · 201 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 10d ago First seen · 201 lines · 19 tokens per session scan A b9222aa13274

Subscribe to this mod's changes

secret-handling is a skill published in the GitHub repository microsoft/Generative-AI-for-beginners-dotnet (3,057 stars, last pushed 9d ago), licensed MIT. It adds 19 tokens to every session and 1,998 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. It is 100% identical to secret-handling, differing in 0 lines, and is treated as a copy.

Related

Other skills, from other repositories

tidy-skill

Keep local AI agent environments clean, explainable, and recoverable. Use for repo artifact governance, workspace cache audits, WSL2/Docker hygiene, package and model cache mapping, C-drive growth diagnosis, and safe cleanup boundaries. Prevent throwaway Markdown files, audit local development environment sprawl, and…

Phoenix0531-sudo/tidy-skill · 82 tokens

terminal-management

Teaches AI agents to properly manage VS Code terminal lifecycle — always use background terminals and kill them after commands complete. Prevents zombie terminal accumulation in GitHub Codespaces and VS Code.

nirholas/auto-kill-terminal · 0 tokens

azure-ml-dataset-creator

Generate synthetic and simulated datasets for evaluation and fine-tuning using Azure AI Foundry simulators. Create non-adversarial task data, adversarial safety data, and conversation datasets without manual data collection.

kimtth/azure-ml-finetuning-eval-skills · 48 tokens

azure-ml-model-evaluation

Evaluate generative AI applications and models locally or in the cloud using Azure AI Evaluation SDK. Measure quality, safety, and performance with built-in and custom evaluators.

kimtth/azure-ml-finetuning-eval-skills · 40 tokens

azure-ml-llm-trainer

Train or fine-tune LLMs on Azure ML managed compute with TRL trainers. Uses direct trainer loops (SFT, DPO, RL) without relying on serverless APIs or Hugging Face infrastructure.

kimtth/azure-ml-finetuning-eval-skills · 52 tokens

systematic-debugging

Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.

obra/superpowers · 21 tokens