.md file to compare - side-by-side diff against sync-creds
sync-creds
description: "Triggers on prompt mention of 'sync-creds'."
What it does for you
Refreshes your saved logins on a new machine or after a change.
What it produces
A recent result, so you can see the kind of work it returns.
loading…
How to get it
These run inside the Snappy workspace. Want this working in your business? I set skills like this up with you, in one focused week.
For developers how this skill is built, graded, and how it runs
at a glance- the short version
what's inside - the parts that make up a skill 2/4 present
A skill is just a few plain-text files. Only the main one is required. The rest are optional, added as the work needs them. This is what the skill is made of; how it runs is just below.
state/skills/sync-creds/SKILL.md
present
state/lib/sync-creds.ts
not present
state/bin/sync-creds/
not present
state/skills/sync-creds/AGENTS.md
present
how it's graded - what counts as a good run 4 criteria · 4 deterministic
Each row is one thing a good run has to get right. deterministic means a quick check decides, pass or fail. judge means the AI reads the result and rates it. Grading each piece on its own (instead of one overall score) shows exactly where a run fell short, so the fix is obvious.
how it runs - the shared frame every skill uses 3/5 present
Every skill runs the same way. One part does the work, a separate part checks it, and a short loader hands the AI exactly what it needs for the job. Anything this skill doesn't use shows a one-line note saying why, on purpose, not by accident.
state/log/evals.ndjson - NEVER commit .env.cache to git — .gitignore blocks it, but the rule is a hard line, not a safety net.
- NEVER log actual credential values. Log only key names and presence (e.g., verified_keys: 12, never ANTHROPIC_API_KEY=sk-...).
- ALWAYS chmod 600 ~/projects/snappy-os/.env.cache after writing.
- The canonical path is ~/projects/snappy-os/.env.cache. The kernel path ~/.claude/skills/snappy-settings/.env.cache is a back-compat symlink — do not write through it.
- Source preference order: 1Password CLI → Doppler → Tailscale rsync. 1Password is the durable answer; rsync requires knowing which machine is "authoritative".
what it has learned - fixes written back in over time sample
When a run hits something this skill didn't handle, the fix gets written back into the skill so it doesn't happen again. FIXED means it was corrected on the spot. LOGGED means it's queued for a bigger rewrite. Either way, the skill gets a little better and never makes the same mistake twice.
- Loading feedback rows…
how the work flows- step by step
# On the target machine, pull from the authoritative machine:
what this step does
op read "op://snappy-os/env-cache" > ~/projects/snappy-os/.env.cache
what this step does
doppler secrets download --project snappy-os --no-file > ~/projects/snappy-os/.env.cache
SKILL.md- the skill, written out in plain English
sync-creds
The "make a new machine work" skill. snappy-os owns .env.cache at the repo root (not the kernel path - see program.md Credentials section). But that file is .gitignored because it contains secrets, so pulling the repo alone doesn't give you credentials. This skill closes that gap.
When to run this
- New machine setup: clone the repo, run this skill, every credential-using
skill works immediately.
- After rotating a key on one machine: run this on every other machine to
propagate.
- Daily on the Mac Mini: cron entry keeps the Mac Mini in sync with the
laptop without manual intervention.
Sources (pick one, documented in order of preference)
1. Tailscale + rsync (the simplest working default)
If both machines are on Tailscale and have SSH keys set up:
# On the target machine, pull from the authoritative machine:
rsync -av macbook-pro:~/projects/snappy-os/.env.cache ~/projects/snappy-os/.env.cache
chmod 600 ~/projects/snappy-os/.env.cache
This is what runs today. Requires knowing which machine is "authoritative" (the one you most recently rotated keys on).
2. 1Password CLI (the durable answer)
Once op://snappy-os/env-cache is populated:
op read "op://snappy-os/env-cache" > ~/projects/snappy-os/.env.cache
chmod 600 ~/projects/snappy-os/.env.cache
No concept of "authoritative machine" - 1Password is the source. Every machine pulls the latest. Requires one-time op signin.
3. Doppler (if you prefer a devops-style secret store)
doppler secrets download --project snappy-os --no-file > ~/projects/snappy-os/.env.cache
Steps
- Detect source: check which source is available (1Password CLI, Doppler
CLI, Tailscale peer reachable).
- Pull: execute the source-specific command.
- Chmod:
chmod 600- the file contains secrets. - Verify: check that a critical key (e.g.,
ANTHROPIC_API_KEY) is present:
grep -q "^ANTHROPIC_API_KEY=" ~/projects/snappy-os/.env.cache || echo "MISSING"
- Log: append a row to
state/log/evals.ndjsonwith the source used and
the key count.
Eval
score("sync-creds", run_id, {
score:
verified_keys >= 10 && expected_keys.every(k => present.includes(k))
? 1.0
: verified_keys > 0
? 0.5
: 0.0,
source_used,
verified_keys,
missing_expected: expected_keys.filter(k => !present.includes(k)),
primary_issue:
verified_keys === 0 ? "fetch-failed" :
!expected_keys.every(k => present.includes(k)) ? "key-missing" :
null,
});
Expected keys (baseline for any machine running snappy-os):
ANTHROPIC_API_KEYOPENAI_API_KEYGEMINI_API_KEYOPENROUTER_API_KEYSNAPPY_MASTER_KEYLINKEDIN_CLIENT_IDDO_SPACES_KEY
Hard rules
- Never commit
.env.cacheto git. The repo's.gitignoreblocks it. - Never log the actual credential values - only their names and presence.
- Always
chmod 600after writing. - If the source is 1Password or Doppler, never cache the decrypted content
anywhere other than ~/projects/snappy-os/.env.cache.
Bootstrap on a fresh machine
git clone github.com/snappyai/snappy-os ~/projects/snappy-os
cd ~/projects/snappy-os
npm install -g snappy-skills
snappy-skills install
# Wire the PID self-improvement loop into the machine's Stop hook so skills
# regenerate automatically when eval trends drop:
mkdir -p ~/.claude/hooks
cat > ~/.claude/hooks/auto-regen-skills.sh <<'HOOK'
#!/usr/bin/env bash
set -euo pipefail
SNAPPY_OS="${HOME}/projects/snappy-os"
[ -x "$SNAPPY_OS/state/bin/auto-regen.sh" ] && "$SNAPPY_OS/state/bin/auto-regen.sh" || true
exit 0
HOOK
chmod +x ~/.claude/hooks/auto-regen-skills.sh
# Now run this skill:
# (from Claude Code: "skill: sync-creds")
# (from any shell: invoke the sync-creds verb via state/lib/env.ts loader)
After those commands, the machine has: the code, the hooks, the PID loop, the credentials. Every skill works. No further setup.
Rubric
criteria:
- name: env_cache_file_created
kind: deterministic
check: "The file `~/projects/snappy-os/.env.cache` exists."
- name: env_cache_permissions
kind: deterministic
check: "The file `~/projects/snappy-os/.env.cache` has permissions `600`."
- name: critical_keys_present
kind: deterministic
check: "The `.env.cache` file contains `ANTHROPIC_API_KEY`, `OPENAI_API_KEY`, and `SNAPPY_MASTER_KEY`."
- name: eval_log_entry_created
kind: deterministic
check: "A log entry for 'sync-creds' exists in `state/log/evals.ndjson` with 'source_used' and 'verified_keys' fields."AGENTS.md- what the AI loads when this skill comes up
sync-creds - loader
Per-turn rules for the sync-creds skill. Full reference: state/skills/sync-creds/SKILL.md. Do not skip these.
Critical Rules
- NEVER commit
.env.cacheto git -.gitignoreblocks it, but the rule is a hard line, not a safety net. - NEVER log actual credential values. Log only key names and presence (e.g.,
verified_keys: 12, neverANTHROPIC_API_KEY=sk-...). - ALWAYS
chmod 600 ~/projects/snappy-os/.env.cacheafter writing. - The canonical path is
~/projects/snappy-os/.env.cache. The kernel path~/.claude/skills/snappy-settings/.env.cacheis a back-compat symlink - do not write through it. - Source preference order: 1Password CLI → Doppler → Tailscale rsync. 1Password is the durable answer; rsync requires knowing which machine is "authoritative".
Commands
| ui dashboard | state/skills/sync-creds/resources/ui.openui | |invoke (1password): op read "op://snappy-os/env-cache" > ~/projects/snappy-os/.env.cache && chmod 600 ~/projects/snappy-os/.env.cache |invoke (rsync): rsync -av macbook-pro:~/projects/snappy-os/.env.cache ~/projects/snappy-os/.env.cache && chmod 600 ~/projects/snappy-os/.env.cache |invoke (doppler): doppler secrets download --project snappy-os --no-file > ~/projects/snappy-os/.env.cache |verify: grep -q "^ANTHROPIC_API_KEY=" ~/projects/snappy-os/.env.cache || echo "MISSING" |eval log: state/log/evals.ndjson (skill: "sync-creds") - fields: source_used, verified_keys, missing_expected
OpenUI Resource
- Skill-owned OpenUI Lang resource:
state/skills/sync-creds/resources/ui.openui. Read it before rendering or editing this skill's generated component surface. - Treat this resource as a first-class artifact of the skill, not a generic chat response. Improve it when the skill's user-facing output needs to become richer.
- System resources compose OpenUI primitives and inherit SnappyChat tokens. Use
ui_contract: brandedin SKILL.md only for deliberate platform or client visuals.
Known Pitfalls
- Expected baseline keys:
ANTHROPIC_API_KEY,OPENAI_API_KEY,GEMINI_API_KEY,OPENROUTER_API_KEY,SNAPPY_MASTER_KEY,LINKEDIN_CLIENT_ID,DO_SPACES_KEY. Missing any → score 0.5 withkey-missing. - Score 0.0 only when
verified_keys === 0(fetch-failed) - partial pulls land at 0.5. - If using 1Password/Doppler, never cache decrypted content anywhere other than
~/projects/snappy-os/.env.cache. - After running, every credential-using skill should work immediately - no further setup.
Self-Test
An agent reading this should correctly:
- [ ] Refuse to commit
.env.cache - [ ] Run
chmod 600after writing the file - [ ] Detect source automatically (try
op→doppler→tailscalereachability)
Self-report
If this loader fell short, append a line:
echo "[$(date -u +%FT%TZ)] sync-creds: <what was missing>" >> state/log/loader-feedback.log
<!-- kernel-ok: historical attribution for the PID-loader pattern. -->
Self-correcting loader (PID feedback)
This is the rule that makes loaders learn. Ported from snappy-kernel, where it demonstrably worked: the snappy-dom-cartographer skill mapped Skool admin UI once, every later ship-agent inherited the full map for free.
Before you finish, do two things:
1. Fix gaps (P - proportional). MANDATORY. If this loader didn't cover your case - if you had to read another file, run an undocumented command, work around a wrong selector, or discover a quirk - you MUST attempt an Edit to this AGENTS.md before you log.
- Default action: edit this file. Surgical. Add the missing line, table
row, or code example where it belongs. No restructuring.
- Only
LOGGEDis allowed when: the fix needs >10 lines, spans multiple
files, or requires a structural rewrite. In that case the state/regen/drain.sh queue picks it up asynchronously.
- "I didn't have time" / "it's minor" / "the next agent will figure it out"
are NOT valid reasons. Minor gaps compound - that's the whole point of this loop.
- Concrete example of a valid P-fix: discover
agent-browser screenshot
takes path positionally not as --output <path>. One line in a table. Edit it in. Do not just log it.
- The goal: the next agent never has to leave the loader.
2. Log the result.
echo "[$(date -u +%FT%TZ)] sync-creds: <what was missing or fixed> [FIXED|LOGGED]" >> state/log/loader-feedback.log
FIXED= you patched this loader inline (P-fix).LOGGED= too large for inline; the PostToolUse enqueue + Stop-hook drain
will rewrite the loader from scratch on next session-end.
Do not skip this. Every agent run must leave the system better than it found it. The loader is the setpoint; you are the sensor; the gap is the error signal; closing the gap is the correction.
api.ts- the code it can call
⚠ no api.ts - this skill has no typed action surface
scripts- helper scripts it can run
prose-only skill - 6 inline code blocks live in SKILL.md above (no state/bin/ sidecar yet).
how we check it- the checks, plus the last 10 runs
| timestamp | verb | score | primary_issue | artifact |
|---|---|---|---|---|
| 2026-04-25 04:11Z | - | 1.00 | - | - |
| 2026-04-21 15:58Z | - | 1.00 | - | - |
| 2026-04-21 15:57Z | - | 1.00 | - | - |
| 2026-04-21 03:53Z | - | 1.00 | - | - |
| 2026-04-25 04:11Z | - | 1.00 | - | - |
| 2026-04-21 15:58Z | - | 1.00 | - | - |
| 2026-04-21 15:57Z | - | 1.00 | - | - |
| 2026-04-21 03:53Z | - | 1.00 | - | - |
| 2026-04-25 04:11Z | - | 1.00 | - | - |
| 2026-04-21 15:58Z | - | 1.00 | - | - |