Overview
Secure Environment Variables is wrsmith108/varlock-claude-skill, an MIT-licensed Claude Code skill built on Varlock, an open-source environment variable tool by DMNO. The problem it addresses: while an agent works in your terminal, secrets can leak into command output, the model's input and output context, logs, or git diffs. The skill's core rule is that secret values must never appear in Claude's context, and it gives Claude safe replacements for the commands that usually leak them.
How It Works
| Never do | Safe alternative |
|---|---|
cat .env | cat .env.schema |
echo $SECRET | varlock load |
printenv | grep API | varlock load | grep API |
You describe variables in a .env.schema file with annotations. @sensitive masks a value in all output, @sensitive=false shows it (for public keys), @required makes it mandatory, and @type= adds validation such as string(startsWith=sk_), url, or an enum(...). A header like # @defaultSensitive=true makes everything sensitive unless you say otherwise.
The skill also tells Claude how to respond to common requests: check whether a key is set with varlock load | grep API_KEY, debug auth with varlock load, show the schema instead of .env, and decline to update secrets, asking you to change them yourself.
Quick Start
# Install the Varlock CLI
curl -sSfL https://varlock.dev/install.sh | sh -s -- --force-no-brew
export PATH="$HOME/.varlock/bin:$PATH"
# Install the skill
mkdir -p ~/.claude/skills/varlock && curl -sSL \
https://raw.githubusercontent.com/wrsmith108/varlock-claude-skill/main/skills/varlock/SKILL.md \
-o ~/.claude/skills/varlock/SKILL.md
varlock load # validate, values masked
varlock run -- npm start # run with secrets injected
Use Cases
- Letting an agent debug a failing API integration without ever printing the key.
- Enforcing required, typed configuration before a service starts.
- Teams that screen-share or record agent sessions.
Limitations
- It is guidance for the agent plus the Varlock CLI, not a sandbox. It does not technically stop a command from reading
.env. - You need to write and maintain a
.env.schema.
FAQ
Does this encrypt my secrets?
The skill does not add encryption. It keeps values masked in output and out of the conversation by using Varlock's schema and load/run commands.
Can Claude change a secret for me?
By design it declines and asks you to update the value manually.
Alternatives
- CC Safety Net is a PreToolUse hook that blocks destructive commands and secret access before they run.
- Claude Code Hooks let you enforce your own rules deterministically.
- mise loads project env vars from
mise.toml, without the masking focus.
More in Skills and the security tag.
Comments
No comments yet. Be the first to comment!
Related Tools
Related Insights

Anthropic Subagent: The Multi-Agent Architecture Revolution
Deep dive into Anthropic multi-agent architecture design. Learn how Subagents break through context window limitations, achieve 90% performance improvements, and real-world applications in Claude Code.
Skills + Hooks + Plugins: How Anthropic Redefined AI Coding Tool Extensibility
An in-depth analysis of Claude Code's trinity architecture of Skills, Hooks, and Plugins. Explore why this design is more advanced than GitHub Copilot and Cursor, and how it redefines AI coding tool extensibility through open standards.

Claude Code account precautions: before you spend $200, do these six things
Gmail plus Apple private sign-in, Cliproxy residential routing for CC and emulators, IP/DNS checks, gradual upgrades, and history-preserving sign-out. Includes a profile and script.