OR Key
drop another .md file to compare - side-by-side diff against sync-creds

sync-creds

Refreshes your saved logins on a new machine or after a change.
description: "Triggers on prompt mention of 'sync-creds'."
personal 2 files 10 recent evals

What it does for you

Refreshes your saved logins on a new machine or after a change.

What it produces

A recent result, so you can see the kind of work it returns.

loading…

How to get it

These run inside the Snappy workspace. Want this working in your business? I set skills like this up with you, in one focused week.

Work with me
For developers how this skill is built, graded, and how it runs

at a glance- the short version

eval modeauto
categorySystem
stages3
dependssettings

what's inside - the parts that make up a skill 2/4 present

A skill is just a few plain-text files. Only the main one is required. The rest are optional, added as the work needs them. This is what the skill is made of; how it runs is just below.

The skill
state/skills/sync-creds/SKILL.md present
the skill itself, in plain text
The main file. It says what the skill is and lays out the steps in plain English.
Code
state/lib/sync-creds.ts not present
code the skill can run
Optional. Many skills are just words and need no code at all.
Scripts
state/bin/sync-creds/ not present
helper scripts
Optional. Added when a skill has a few commands to run.
Loader
state/skills/sync-creds/AGENTS.md present
what the AI loads on the fly
Loaded automatically the moment this skill is needed. Kept short on purpose.

how it's graded - what counts as a good run 4 criteria · 4 deterministic

Each row is one thing a good run has to get right. deterministic means a quick check decides, pass or fail. judge means the AI reads the result and rates it. Grading each piece on its own (instead of one overall score) shows exactly where a run fell short, so the fix is obvious.

name
kind
check
env_cache_file_created
deterministic
The file `~/projects/snappy-os/.env.cache` exists.
env_cache_permissions
deterministic
The file `~/projects/snappy-os/.env.cache` has permissions `600`.
critical_keys_present
deterministic
The `.env.cache` file contains `ANTHROPIC_API_KEY`, `OPENAI_API_KEY`, and `SNAPPY_MASTER_KEY`.
eval_log_entry_created
deterministic
A log entry for 'sync-creds' exists in `state/log/evals.ndjson` with 'source_used' and 'verified_keys' fields.

how it runs - the shared frame every skill uses 3/5 present

Every skill runs the same way. One part does the work, a separate part checks it, and a short loader hands the AI exactly what it needs for the job. Anything this skill doesn't use shows a one-line note saying why, on purpose, not by accident.

makes the work The worker
inferred
# On the from a command
No worker named, so the first command in the skill is treated as the worker.
checks the work The reviewer
inferred
grep "^ANTHROPIC_API_KEY=" from the check command
The check is a quick command that confirms the result looks right.
frame
learns Self-correction
present
fixes itself learns from gaps
When a run hits a gap, the skill gets edited on the spot [FIXED] or queued for a bigger rewrite [LOGGED], so it keeps getting better.
tidies up Background fixes
present
queued for rewrite runs in the background
Bigger fixes that can't be made on the spot get queued and rewritten in the background later.
remembers Run history
present
state/log/evals.ndjson unknown runs
Every run is written down here, so the next time this skill is used it already knows how the last runs went.
Critical rules the things this skill must not get wrong
  1. NEVER commit .env.cache to git — .gitignore blocks it, but the rule is a hard line, not a safety net.
  2. NEVER log actual credential values. Log only key names and presence (e.g., verified_keys: 12, never ANTHROPIC_API_KEY=sk-...).
  3. ALWAYS chmod 600 ~/projects/snappy-os/.env.cache after writing.
  4. The canonical path is ~/projects/snappy-os/.env.cache. The kernel path ~/.claude/skills/snappy-settings/.env.cache is a back-compat symlink — do not write through it.
  5. Source preference order: 1Password CLI → Doppler → Tailscale rsync. 1Password is the durable answer; rsync requires knowing which machine is "authoritative".

what it has learned - fixes written back in over time sample

When a run hits something this skill didn't handle, the fix gets written back into the skill so it doesn't happen again. FIXED means it was corrected on the spot. LOGGED means it's queued for a bigger rewrite. Either way, the skill gets a little better and never makes the same mistake twice.

  1. Loading feedback rows…

how the work flows- step by step

inputs settings
1 stage
Tailscale + rsync (the simplest working default)
If both machines are on Tailscale and have SSH keys set up:
# On the target machine, pull from the authoritative machine:
what this step does
If both machines are on Tailscale and have SSH keys set up: This is what runs today. Requires knowing which machine is "authoritative" (the one you most recently rotated keys on).
2 stage
1Password CLI (the durable answer)
Once op://snappy-os/env-cache is populated:
op read "op://snappy-os/env-cache" > ~/projects/snappy-os/.env.cache
what this step does
Once op://snappy-os/env-cache is populated: No concept of "authoritative machine" — 1Password is the source. Every machine pulls the latest. Requires one-time op signin.
3 stage
Doppler (if you prefer a devops-style secret sto
```bash
doppler secrets download --project snappy-os --no-file > ~/projects/snappy-os/.env.cache

SKILL.md- the skill, written out in plain English

sync-creds

The "make a new machine work" skill. snappy-os owns .env.cache at the repo root (not the kernel path - see program.md Credentials section). But that file is .gitignored because it contains secrets, so pulling the repo alone doesn't give you credentials. This skill closes that gap.

When to run this

  • New machine setup: clone the repo, run this skill, every credential-using

skill works immediately.

  • After rotating a key on one machine: run this on every other machine to

propagate.

  • Daily on the Mac Mini: cron entry keeps the Mac Mini in sync with the

laptop without manual intervention.

Sources (pick one, documented in order of preference)

1. Tailscale + rsync (the simplest working default)

If both machines are on Tailscale and have SSH keys set up:

# On the target machine, pull from the authoritative machine:
rsync -av macbook-pro:~/projects/snappy-os/.env.cache ~/projects/snappy-os/.env.cache
chmod 600 ~/projects/snappy-os/.env.cache

This is what runs today. Requires knowing which machine is "authoritative" (the one you most recently rotated keys on).

2. 1Password CLI (the durable answer)

Once op://snappy-os/env-cache is populated:

op read "op://snappy-os/env-cache" > ~/projects/snappy-os/.env.cache
chmod 600 ~/projects/snappy-os/.env.cache

No concept of "authoritative machine" - 1Password is the source. Every machine pulls the latest. Requires one-time op signin.

3. Doppler (if you prefer a devops-style secret store)

doppler secrets download --project snappy-os --no-file > ~/projects/snappy-os/.env.cache

Steps

  1. Detect source: check which source is available (1Password CLI, Doppler

CLI, Tailscale peer reachable).

  1. Pull: execute the source-specific command.
  2. Chmod: chmod 600 - the file contains secrets.
  3. Verify: check that a critical key (e.g., ANTHROPIC_API_KEY) is present:
   grep -q "^ANTHROPIC_API_KEY=" ~/projects/snappy-os/.env.cache || echo "MISSING"
  1. Log: append a row to state/log/evals.ndjson with the source used and

the key count.

Eval

score("sync-creds", run_id, {
  score:
    verified_keys >= 10 && expected_keys.every(k => present.includes(k))
      ? 1.0
      : verified_keys > 0
        ? 0.5
        : 0.0,
  source_used,
  verified_keys,
  missing_expected: expected_keys.filter(k => !present.includes(k)),
  primary_issue:
    verified_keys === 0 ? "fetch-failed" :
    !expected_keys.every(k => present.includes(k)) ? "key-missing" :
    null,
});

Expected keys (baseline for any machine running snappy-os):

  • ANTHROPIC_API_KEY
  • OPENAI_API_KEY
  • GEMINI_API_KEY
  • OPENROUTER_API_KEY
  • SNAPPY_MASTER_KEY
  • LINKEDIN_CLIENT_ID
  • DO_SPACES_KEY

Hard rules

  • Never commit .env.cache to git. The repo's .gitignore blocks it.
  • Never log the actual credential values - only their names and presence.
  • Always chmod 600 after writing.
  • If the source is 1Password or Doppler, never cache the decrypted content

anywhere other than ~/projects/snappy-os/.env.cache.

Bootstrap on a fresh machine

git clone github.com/snappyai/snappy-os ~/projects/snappy-os
cd ~/projects/snappy-os
npm install -g snappy-skills
snappy-skills install

# Wire the PID self-improvement loop into the machine's Stop hook so skills
# regenerate automatically when eval trends drop:
mkdir -p ~/.claude/hooks
cat > ~/.claude/hooks/auto-regen-skills.sh <<'HOOK'
#!/usr/bin/env bash
set -euo pipefail
SNAPPY_OS="${HOME}/projects/snappy-os"
[ -x "$SNAPPY_OS/state/bin/auto-regen.sh" ] && "$SNAPPY_OS/state/bin/auto-regen.sh" || true
exit 0
HOOK
chmod +x ~/.claude/hooks/auto-regen-skills.sh

# Now run this skill:
# (from Claude Code: "skill: sync-creds")
# (from any shell: invoke the sync-creds verb via state/lib/env.ts loader)

After those commands, the machine has: the code, the hooks, the PID loop, the credentials. Every skill works. No further setup.

Rubric

criteria:
  - name: env_cache_file_created
    kind: deterministic
    check: "The file `~/projects/snappy-os/.env.cache` exists."
  - name: env_cache_permissions
    kind: deterministic
    check: "The file `~/projects/snappy-os/.env.cache` has permissions `600`."
  - name: critical_keys_present
    kind: deterministic
    check: "The `.env.cache` file contains `ANTHROPIC_API_KEY`, `OPENAI_API_KEY`, and `SNAPPY_MASTER_KEY`."
  - name: eval_log_entry_created
    kind: deterministic
    check: "A log entry for 'sync-creds' exists in `state/log/evals.ndjson` with 'source_used' and 'verified_keys' fields."

AGENTS.md- what the AI loads when this skill comes up

sync-creds - loader

Per-turn rules for the sync-creds skill. Full reference: state/skills/sync-creds/SKILL.md. Do not skip these.

Critical Rules

  • NEVER commit .env.cache to git - .gitignore blocks it, but the rule is a hard line, not a safety net.
  • NEVER log actual credential values. Log only key names and presence (e.g., verified_keys: 12, never ANTHROPIC_API_KEY=sk-...).
  • ALWAYS chmod 600 ~/projects/snappy-os/.env.cache after writing.
  • The canonical path is ~/projects/snappy-os/.env.cache. The kernel path ~/.claude/skills/snappy-settings/.env.cache is a back-compat symlink - do not write through it.
  • Source preference order: 1Password CLI → Doppler → Tailscale rsync. 1Password is the durable answer; rsync requires knowing which machine is "authoritative".

Commands

| ui dashboard | state/skills/sync-creds/resources/ui.openui | |invoke (1password): op read "op://snappy-os/env-cache" > ~/projects/snappy-os/.env.cache && chmod 600 ~/projects/snappy-os/.env.cache |invoke (rsync): rsync -av macbook-pro:~/projects/snappy-os/.env.cache ~/projects/snappy-os/.env.cache && chmod 600 ~/projects/snappy-os/.env.cache |invoke (doppler): doppler secrets download --project snappy-os --no-file > ~/projects/snappy-os/.env.cache |verify: grep -q "^ANTHROPIC_API_KEY=" ~/projects/snappy-os/.env.cache || echo "MISSING" |eval log: state/log/evals.ndjson (skill: "sync-creds") - fields: source_used, verified_keys, missing_expected

OpenUI Resource

  • Skill-owned OpenUI Lang resource: state/skills/sync-creds/resources/ui.openui. Read it before rendering or editing this skill's generated component surface.
  • Treat this resource as a first-class artifact of the skill, not a generic chat response. Improve it when the skill's user-facing output needs to become richer.
  • System resources compose OpenUI primitives and inherit SnappyChat tokens. Use ui_contract: branded in SKILL.md only for deliberate platform or client visuals.

Known Pitfalls

  • Expected baseline keys: ANTHROPIC_API_KEY, OPENAI_API_KEY, GEMINI_API_KEY, OPENROUTER_API_KEY, SNAPPY_MASTER_KEY, LINKEDIN_CLIENT_ID, DO_SPACES_KEY. Missing any → score 0.5 with key-missing.
  • Score 0.0 only when verified_keys === 0 (fetch-failed) - partial pulls land at 0.5.
  • If using 1Password/Doppler, never cache decrypted content anywhere other than ~/projects/snappy-os/.env.cache.
  • After running, every credential-using skill should work immediately - no further setup.

Self-Test

An agent reading this should correctly:

  1. [ ] Refuse to commit .env.cache
  2. [ ] Run chmod 600 after writing the file
  3. [ ] Detect source automatically (try opdopplertailscale reachability)

Self-report

If this loader fell short, append a line:

echo "[$(date -u +%FT%TZ)] sync-creds: <what was missing>" >> state/log/loader-feedback.log

<!-- kernel-ok: historical attribution for the PID-loader pattern. -->

Self-correcting loader (PID feedback)

This is the rule that makes loaders learn. Ported from snappy-kernel, where it demonstrably worked: the snappy-dom-cartographer skill mapped Skool admin UI once, every later ship-agent inherited the full map for free.

Before you finish, do two things:

1. Fix gaps (P - proportional). MANDATORY. If this loader didn't cover your case - if you had to read another file, run an undocumented command, work around a wrong selector, or discover a quirk - you MUST attempt an Edit to this AGENTS.md before you log.

  • Default action: edit this file. Surgical. Add the missing line, table

row, or code example where it belongs. No restructuring.

  • Only LOGGED is allowed when: the fix needs >10 lines, spans multiple

files, or requires a structural rewrite. In that case the state/regen/drain.sh queue picks it up asynchronously.

  • "I didn't have time" / "it's minor" / "the next agent will figure it out"

are NOT valid reasons. Minor gaps compound - that's the whole point of this loop.

  • Concrete example of a valid P-fix: discover agent-browser screenshot

takes path positionally not as --output <path>. One line in a table. Edit it in. Do not just log it.

  • The goal: the next agent never has to leave the loader.

2. Log the result.

echo "[$(date -u +%FT%TZ)] sync-creds: <what was missing or fixed> [FIXED|LOGGED]" >> state/log/loader-feedback.log
  • FIXED = you patched this loader inline (P-fix).
  • LOGGED = too large for inline; the PostToolUse enqueue + Stop-hook drain

will rewrite the loader from scratch on next session-end.

Do not skip this. Every agent run must leave the system better than it found it. The loader is the setpoint; you are the sensor; the gap is the error signal; closing the gap is the correction.

api.ts- the code it can call

⚠ no api.ts - this skill has no typed action surface

scripts- helper scripts it can run

prose-only skill - 6 inline code blocks live in SKILL.md above (no state/bin/ sidecar yet).

how we check it- the checks, plus the last 10 runs

rubric auto no rubric declared
recent mean 1.00 · 10 runs actor/auditor: unverifiable
deps settings
timestamp verb score primary_issue artifact
2026-04-25 04:11Z - 1.00 - -
2026-04-21 15:58Z - 1.00 - -
2026-04-21 15:57Z - 1.00 - -
2026-04-21 03:53Z - 1.00 - -
2026-04-25 04:11Z - 1.00 - -
2026-04-21 15:58Z - 1.00 - -
2026-04-21 15:57Z - 1.00 - -
2026-04-21 03:53Z - 1.00 - -
2026-04-25 04:11Z - 1.00 - -
2026-04-21 15:58Z - 1.00 - -