{"id":18971,"plugin_id":"plugins_6a8f9d0180648191a781fc7d2351bf34","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:15:07.101Z","digest":"28454214d234c8fc5627cfd15a44d4d16ccf6151e58c26167a013072951a2ff2","against":null,"payload":{"name":"1password-environments","description":"Manage 1Password Developer Environments and local .env mounts through the local 1Password MCP server, without exposing secret values. Use when the user asks to set up environment variables for a repo, store or configure API keys and secrets in 1Password, mount or create a local .env file from 1Password, inspect 1Password Environment variable names, or work with the 1Password MCP server.","included_files":[{"relative_path":"agents/openai.yaml","size_in_bytes":314},{"relative_path":"assets/icon.svg","size_in_bytes":3027},{"relative_path":"assets/logo.png","size_in_bytes":5488}],"skill_md_contents":"---\nname: 1password-environments\ndescription: Manage 1Password Developer Environments and local .env mounts through the local 1Password MCP server, without exposing secret values. Use when the user asks to set up environment variables for a repo, store or configure API keys and secrets in 1Password, mount or create a local .env file from 1Password, inspect 1Password Environment variable names, or work with the 1Password MCP server.\nlicense: MIT\ncompatibility: Requires the 1Password desktop app (macOS, Windows, or Linux) with the MCP server enabled in Developer settings, and a client configured to run the local 1password-mcp MCP server. Local .env mounts are supported on macOS and Linux only.\n---\n\n# 1Password Environments\n\nUse the local 1Password MCP server for all environment variable configuration. Its tools return variable names, never secret values, so secrets stay in 1Password.\n\n## Use When\n\n- The user mentions 1Password Environments, 1Password Developer Environments, the 1Password MCP server, or local `.env` files from 1Password.\n- The user asks to set up, mount, create, or sync a project `.env` file from a secret manager and 1Password is available.\n- The user asks to configure repo environment variables, API keys, tokens, credentials, or secrets securely with 1Password.\n- The user wants to list or compare Environment variable names without exposing secret values.\n\nDo not use this skill for unrelated password-manager tasks, arbitrary local `.env` file parsing, or non-1Password secret stores unless the user asks to migrate that configuration into 1Password.\n\n## Requirements\n\nThis skill depends on the local 1Password MCP server. If its tools are not available in the current session, help the user finish setup instead of improvising:\n\n1. Install the 1Password desktop app and enable the MCP server in Settings > Developer. On business accounts, the setting is unavailable until an administrator enables the feature in the \"Sharing & Permissions\" policies section of the admin dashboard.\n2. The desktop app installs the `1password-mcp` alias on the `PATH` (supported on macOS, Windows, and Linux).\n3. Configure the client to launch `1password-mcp` as a local MCP server. For Codex, add this to `~/.codex/config.toml`:\n\n   ```toml\n   [mcp_servers.1password]\n   command = \"1password-mcp\"\n   ```\n\nThe 1Password desktop app asks the user to approve each client connection, and environment access can require additional approval.\n\n## Tools\n\nThe local server exposes these tools:\n\n- `authenticate`: authenticate with the 1Password desktop app and return the account ID.\n- `list_environments`: list Developer Environments for an account.\n- `create_environment`: create a new Developer Environment.\n- `rename_environment`: rename an existing Developer Environment.\n- `list_variables`: list variable names in an Environment without returning values.\n- `append_variables`: add or update Environment variables.\n- `create_local_env_file`: mount an Environment as a local `.env` file on macOS or Linux.\n- `list_local_env_files`: list local `.env` mounts for an Environment.\n\nIt also exposes these documentation resources:\n\n- `1password://docs/getting-started`\n- `1password://docs/environments-guide`\n\n## Workflow\n\n1. Call `authenticate` first when you do not already have an account ID for this turn. The 1Password desktop app will ask the user to approve the connection.\n2. Use `accountId` for subsequent calls. Server docs may spell the returned value as `account_id`; MCP tool calls use camelCase parameters such as `accountId` and `environmentId`.\n3. Call `list_environments` with the returned `accountId` before operating on an Environment, unless the user already provided a current `environmentId`.\n4. If the target Environment is ambiguous, ask the user which Environment to use instead of guessing.\n5. Use the `environmentId` returned by the server for environment-level calls.\n6. Prefer `list_variables` when the user wants to inspect an Environment. It returns names only, not secret values.\n7. Use `append_variables` only when the user explicitly asks to add or update variables.\n8. Use `create_local_env_file` for local `.env` mounts on macOS or Linux, and pass the absolute `mountPath` the user wants.\n9. Use `list_local_env_files` to check existing local mounts before creating a duplicate.\n\n## Common Flows\n\n### Mount 1Password as this repo's `.env`\n\n1. Call `authenticate`.\n2. Call `list_environments`.\n3. Ask the user to choose an Environment if the request does not identify one clearly.\n4. Call `list_local_env_files` for the selected Environment to avoid duplicate mounts.\n5. If the user says \"here\", \"this repo\", or \"this project\", use the current workspace's absolute `.env` path as `mountPath`.\n6. Call `create_local_env_file` with `accountId`, `environmentId`, `environmentName`, and the absolute `mountPath`.\n7. Report the mount path and Environment name, but do not read the mounted `.env` file to verify it.\n\n### Inspect variables\n\n1. Call `authenticate`.\n2. Call `list_environments` unless the user already gave an `environmentId`.\n3. Use the `environmentId` returned by the server for environment-level calls.\n4. Call `list_variables` and summarize variable names only.\n\n### Add or update variables\n\n1. Confirm the user explicitly wants to create or update variables, and collect any missing names or values.\n2. Call `authenticate` and resolve the target Environment.\n3. Prefer calling `list_variables` first so you can tell whether the requested variable names already exist.\n4. Call `append_variables` using the active MCP tool schema exactly as exposed in the current session.\n5. When the active schema accepts structured variable objects, use `{ \"name\": \"API_KEY\", \"value\": \"...\", \"concealed\": true }` for secrets and `concealed: false` only for non-sensitive values such as URLs or feature flags.\n6. When the active schema exposes `variables` as `string[]`, do not send unsupported object fields. Use the string format required by that schema, and ask for clarification if the user's requested variable format is ambiguous.\n\n## Error Handling\n\n- If authentication or environment access fails, tell the user the 1Password desktop app may need approval, unlocking, or account access.\n- If the MCP tools are unavailable, follow the Requirements section above to help the user enable and configure the local MCP server.\n- Local `.env` mounts are documented for macOS and Linux only.\n\n## Safety\n\n- Do not reveal, log, or echo secret values.\n- Do not read a mounted `.env` file just to verify it exists; use the MCP tools instead.\n- Ask before creating or modifying Environment variables unless the user's request is already explicit.\n- Treat local `.env` mounts as sensitive even though 1Password does not persist plaintext secret contents to disk.\n- If a user pasted a secret into the chat, avoid repeating it back; refer to it by variable name.\n\n## Notes\n\n- Official docs: https://www.1password.dev/environments and https://www.1password.dev/environments/mcp-codex-server\n- This skill is also distributed as part of the 1Password Codex plugin (https://github.com/1Password/1password-codex-plugin), which configures the MCP server automatically.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}