Install
$ agentstack add skill-encoredev-skills-go-secret ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Encore Go Secrets
Instructions
Secrets are encrypted, environment-scoped values managed by Encore. Declare them as a package-level secrets struct — Encore reads the field names and resolves each to the right value at runtime.
package email
var secrets struct {
SendGridAPIKey string
SMTPPassword string
}
func sendEmail() error {
apiKey := secrets.SendGridAPIKey
// Use the secret...
return nil
}
Secret keys are globally unique across the application — SendGridAPIKey resolves to the same value regardless of which package declares it.
Setting values
# Set per environment type
encore secret set --type prod SendGridAPIKey
encore secret set --type dev SendGridAPIKey
encore secret set --type local SendGridAPIKey
Environment types: production (alias prod), development (alias dev), preview (alias pr), local.
Local overrides
For local development without going through encore secret set, create a .secrets.local.cue file at the repo root (gitignore it):
SendGridAPIKey: "SG.local-test-key"
GitHubAPIToken: "ghp_local_..."
Common usage patterns
package github
import (
"context"
"net/http"
)
var secrets struct {
GitHubAPIToken string
}
func callGitHub(ctx context.Context) error {
req, _ := http.NewRequestWithContext(ctx, "GET", "https://api.github.com/user", nil)
req.Header.Set("Authorization", "token "+secrets.GitHubAPIToken)
resp, err := http.DefaultClient.Do(req)
if err != nil {
return err
}
defer resp.Body.Close()
return nil
}
package webhooks
var secrets struct {
StripeWebhookSecret string
}
// Verify Stripe signature using secrets.StripeWebhookSecret in a raw endpoint.
Guidelines
- Declare secrets as a package-level
secretsstruct, not as individualsecret(...)calls. - Field names must exactly match the secret name set via
encore secret set. - Set distinct values per environment via
encore secret set --type. - Never commit secret values; use
.secrets.local.cuefor local overrides and gitignore it. - For webhook signature secrets specifically, see also the
encore-go-webhookskill.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: encoredev
- Source: encoredev/skills
- License: Apache-2.0
- Homepage: https://encore.dev
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.