.md file to compare - side-by-side diff against sync-creds
sync-creds
description: "Triggers on prompt mention of 'sync-creds'."
What it does for you
Refreshes your saved logins on a new machine or after a change.
What it produces
A recent result, so you can see the kind of work it returns.
loading…
How to get it
These run inside the Snappy workspace. Want this working in your business? I set skills like this up with you, in one focused week.
For developers how this skill is built, graded, and how it runs
at a glance- the short version
what's inside - the parts that make up a skill 2/4 present
A skill is just a few plain-text files. Only the main one is required. The rest are optional, added as the work needs them. This is what the skill is made of; how it runs is just below.
state/skills/sync-creds/SKILL.md
present
state/lib/sync-creds.ts
not present
state/bin/sync-creds/
not present
state/skills/sync-creds/AGENTS.md
present
how it's graded - what counts as a good run 4 criteria · 4 deterministic
Each row is one thing a good run has to get right. deterministic means a quick check decides, pass or fail. judge means the AI reads the result and rates it. Grading each piece on its own (instead of one overall score) shows exactly where a run fell short, so the fix is obvious.
how it runs - the shared frame every skill uses 2/5 present
Every skill runs the same way. One part does the work, a separate part checks it, and a short loader hands the AI exactly what it needs for the job. Anything this skill doesn't use shows a one-line note saying why, on purpose, not by accident.
This skill doesn't fix its own gaps yet.
state/log/evals.ndjson - NEVER commit .env.cache to git - .gitignore blocks it, but the rule is a hard line, not a safety net.
- NEVER log actual credential values. Log only key names and presence (e.g., verified_keys: 12, never ANTHROPIC_API_KEY=sk-...).
- ALWAYS chmod 600 ~/projects/snappy-os/.env.cache after writing.
- The canonical path is ~/projects/snappy-os/.env.cache. The kernel path ~/.claude/skills/snappy-settings/.env.cache is a back-compat symlink - do not write through it.
- Source preference order: 1Password CLI → Doppler → Tailscale rsync. 1Password is the durable answer; rsync requires knowing which machine is "authoritative".
what it has learned - fixes written back in over time sample
When a run hits something this skill didn't handle, the fix gets written back into the skill so it doesn't happen again. FIXED means it was corrected on the spot. LOGGED means it's queued for a bigger rewrite. Either way, the skill gets a little better and never makes the same mistake twice.
- Loading feedback rows…
how the work flows- step by step
# On the target machine, pull from the authoritative machine:
what this step does
op read "op://snappy-os/env-cache" > ~/projects/snappy-os/.env.cache
what this step does
doppler secrets download --project snappy-os --no-file > ~/projects/snappy-os/.env.cache
SKILL.md- the skill, written out in plain English
sync-creds
The "make a new machine work" skill. snappy-os owns .env.cache at the repo root (not the kernel path - see program.md Credentials section). But that file is .gitignored because it contains secrets, so pulling the repo alone doesn't give you credentials. This skill closes that gap.
When to run this
- New machine setup: clone the repo, run this skill, every credential-using
skill works immediately.
- After rotating a key on one machine: run this on every other machine to
propagate.
- Daily on the Mac Mini: cron entry keeps the Mac Mini in sync with the
laptop without manual intervention.
Sources (pick one, documented in order of preference)
1. Tailscale + rsync (the simplest working default)
If both machines are on Tailscale and have SSH keys set up:
# On the target machine, pull from the authoritative machine:
rsync -av macbook-pro:~/projects/snappy-os/.env.cache ~/projects/snappy-os/.env.cache
chmod 600 ~/projects/snappy-os/.env.cache
This is what runs today. Requires knowing which machine is "authoritative" (the one you most recently rotated keys on).
2. 1Password CLI (the durable answer)
Once op://snappy-os/env-cache is populated:
op read "op://snappy-os/env-cache" > ~/projects/snappy-os/.env.cache
chmod 600 ~/projects/snappy-os/.env.cache
No concept of "authoritative machine" - 1Password is the source. Every machine pulls the latest. Requires one-time op signin.
3. Doppler (if you prefer a devops-style secret store)
doppler secrets download --project snappy-os --no-file > ~/projects/snappy-os/.env.cache
Steps
- Detect source: check which source is available (1Password CLI, Doppler
CLI, Tailscale peer reachable).
- Pull: execute the source-specific command.
- Chmod:
chmod 600- the file contains secrets. - Verify: check that a critical key (e.g.,
ANTHROPIC_API_KEY) is present:
grep -q "^ANTHROPIC_API_KEY=" ~/projects/snappy-os/.env.cache || echo "MISSING"
- Log: append a row to
state/log/evals.ndjsonwith the source used and
the key count.
Eval
score("sync-creds", run_id, {
score:
verified_keys >= 10 && expected_keys.every(k => present.includes(k))
? 1.0
: verified_keys > 0
? 0.5
: 0.0,
source_used,
verified_keys,
missing_expected: expected_keys.filter(k => !present.includes(k)),
primary_issue:
verified_keys === 0 ? "fetch-failed" :
!expected_keys.every(k => present.includes(k)) ? "key-missing" :
null,
});
Expected keys (baseline for any machine running snappy-os):
ANTHROPIC_API_KEYOPENAI_API_KEYGEMINI_API_KEYOPENROUTER_API_KEYSNAPPY_MASTER_KEYLINKEDIN_CLIENT_IDDO_SPACES_KEY
Hard rules
- Never commit
.env.cacheto git. The repo's.gitignoreblocks it. - Never log the actual credential values - only their names and presence.
- Always
chmod 600after writing. - If the source is 1Password or Doppler, never cache the decrypted content
anywhere other than ~/projects/snappy-os/.env.cache.
Bootstrap on a fresh machine
git clone github.com/snappyai/snappy-os ~/projects/snappy-os
cd ~/projects/snappy-os
npm install -g snappy-skills
snappy-skills install
# Wire the PID self-improvement loop into the machine's Stop hook so skills
# regenerate automatically when eval trends drop:
mkdir -p ~/.claude/hooks
cat > ~/.claude/hooks/auto-regen-skills.sh <<'HOOK'
#!/usr/bin/env bash
set -euo pipefail
SNAPPY_OS="${HOME}/projects/snappy-os"
[ -x "$SNAPPY_OS/state/bin/auto-regen.sh" ] && "$SNAPPY_OS/state/bin/auto-regen.sh" || true
exit 0
HOOK
chmod +x ~/.claude/hooks/auto-regen-skills.sh
# Now run this skill:
# (from Claude Code: "skill: sync-creds")
# (from any shell: invoke the sync-creds verb via state/lib/env.ts loader)
After those commands, the machine has: the code, the hooks, the PID loop, the credentials. Every skill works. No further setup.
Rubric
criteria:
- name: env_cache_file_created
kind: deterministic
check: "The file `~/projects/snappy-os/.env.cache` exists."
- name: env_cache_permissions
kind: deterministic
check: "The file `~/projects/snappy-os/.env.cache` has permissions `600`."
- name: critical_keys_present
kind: deterministic
check: "The `.env.cache` file contains `ANTHROPIC_API_KEY`, `OPENAI_API_KEY`, and `SNAPPY_MASTER_KEY`."
- name: eval_log_entry_created
kind: deterministic
check: "A log entry for 'sync-creds' exists in `state/log/evals.ndjson` with 'source_used' and 'verified_keys' fields."AGENTS.md- what the AI loads when this skill comes up
sync-creds - loader
Per-turn rules for the sync-creds skill. Full reference: state/skills/sync-creds/SKILL.md. Do not skip these.
Critical Rules
- NEVER commit
.env.cacheto git -.gitignoreblocks it, but the rule is a hard line, not a safety net. - NEVER log actual credential values. Log only key names and presence (e.g.,
verified_keys: 12, neverANTHROPIC_API_KEY=sk-...). - ALWAYS
chmod 600 ~/projects/snappy-os/.env.cacheafter writing. - The canonical path is
~/projects/snappy-os/.env.cache. The kernel path~/.claude/skills/snappy-settings/.env.cacheis a back-compat symlink - do not write through it. - Source preference order: 1Password CLI → Doppler → Tailscale rsync. 1Password is the durable answer; rsync requires knowing which machine is "authoritative".
Commands
| ui model | live composition via compose_inline, persisted as artifact lang_body, reopened with OpenArtifact | |invoke (1password): op read "op://snappy-os/env-cache" > ~/projects/snappy-os/.env.cache && chmod 600 ~/projects/snappy-os/.env.cache |invoke (rsync): rsync -av macbook-pro:~/projects/snappy-os/.env.cache ~/projects/snappy-os/.env.cache && chmod 600 ~/projects/snappy-os/.env.cache |invoke (doppler): doppler secrets download --project snappy-os --no-file > ~/projects/snappy-os/.env.cache |verify: grep -q "^ANTHROPIC_API_KEY=" ~/projects/snappy-os/.env.cache || echo "MISSING" |eval log: state/log/evals.ndjson (skill: "sync-creds") - fields: source_used, verified_keys, missing_expected
Known Pitfalls
- Expected baseline keys:
ANTHROPIC_API_KEY,OPENAI_API_KEY,GEMINI_API_KEY,OPENROUTER_API_KEY,SNAPPY_MASTER_KEY,LINKEDIN_CLIENT_ID,DO_SPACES_KEY. Missing any → score 0.5 withkey-missing. - Score 0.0 only when
verified_keys === 0(fetch-failed) - partial pulls land at 0.5. - If using 1Password/Doppler, never cache decrypted content anywhere other than
~/projects/snappy-os/.env.cache. - After running, every credential-using skill should work immediately - no further setup.
Self-Test
An agent reading this should correctly:
- [ ] Refuse to commit
.env.cache - [ ] Run
chmod 600after writing the file - [ ] Detect source automatically (try
op→doppler→tailscalereachability)
Found a gap? Edit this file. <!-- footer-injection-point -->
api.ts- the code it can call
⚠ no api.ts - this skill has no typed action surface
scripts- helper scripts it can run
prose-only skill - 6 inline code blocks live in SKILL.md above (no state/bin/ sidecar yet).
how we check it- the checks, plus the last 10 runs
no recent runs logged - the eval contract is declared but nothing has been graded yet