# Sops Encrypt

> >-

- **Type:** Skill
- **Install:** `agentstack add skill-joaquimscosta-arkhe-claude-plugins-sops-encrypt`
- **Verified:** Yes — security-reviewed for prompt injection and unsafe behavior
- **Seller:** [joaquimscosta](https://agentstack.voostack.com/s/joaquimscosta)
- **Installs:** 0
- **Category:** [AI & ML](https://agentstack.voostack.com/c/ai-and-ml)
- **Latest version:** 0.1.0
- **License:** MIT
- **Upstream author:** [joaquimscosta](https://github.com/joaquimscosta)
- **Source:** https://github.com/joaquimscosta/arkhe-claude-plugins/tree/main/plugins/devtools/skills/sops-encrypt

## Install

```sh
agentstack add skill-joaquimscosta-arkhe-claude-plugins-sops-encrypt
```

Requires the [AgentStack CLI](https://agentstack.voostack.com/docs/cli). Works with Claude Code, Cursor, and any MCP-compatible agent.

## About

# SOPS Encrypt

Encrypt `.env` files by converting to YAML and encrypting with SOPS + age.

**Why YAML?** SOPS dotenv store has a [known bug (#1435)](https://github.com/getsops/sops/issues/1435) that corrupts backslash and `\n` sequences. The helper script converts dotenv→YAML before encryption.

## Workflow

1. **Detect current state**:
   ```bash
   python3 ${CLAUDE_SKILL_DIR}/../sops-setup/scripts/detect_sops.py 
   ```

2. **Verify prerequisites**:
   - `tools.sops.installed` must be true — if not, tell user to run `/devtools:sops-setup`
   - `project.sops_yaml.exists` must be true — if not, tell user to run `/devtools:sops-setup`
   - `age_key.exists` must be true — if not, tell user to run `/devtools:sops-setup`

3. **Show unencrypted .env files** from `project.env_files`. If empty, report "No .env files found to encrypt" and exit.

4. **Use `AskUserQuestion`** (multiSelect: true) — which files to encrypt. List each `.env*` file. If a corresponding `.enc.yaml` file already exists, note it will be overwritten.

5. **Encrypt each selected file** (convert dotenv→YAML, then encrypt):
   ```bash
   python3 ${CLAUDE_SKILL_DIR}/../sops-setup/scripts/dotenv_yaml.py to-yaml  > .enc.yaml.tmp
   sops --encrypt .enc.yaml.tmp > .enc.yaml
   rm .enc.yaml.tmp
   ```
   Example: `.env.local` → `.env.local.enc.yaml`

6. **Verify** each encrypted file exists and is non-empty.

7. **Summary**:
   ```
   | File | Encrypted To | Status |
   |------|-------------|--------|
   | .env.local | .env.local.enc.yaml | done |
   | .env.production | .env.production.enc.yaml | done |
   ```
   Remind user to commit the `.enc.yaml` files.

## Key Rules

- Always verify `.sops.yaml` exists before attempting encryption
- Always convert dotenv→YAML before encrypting (use the helper script)
- Warn if an `.enc.yaml` file will be overwritten
- Never delete the original `.env` file — only create the `.enc.yaml` copy
- Clean up `.tmp` files even if encryption fails

## Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

- **Author:** [joaquimscosta](https://github.com/joaquimscosta)
- **Source:** [joaquimscosta/arkhe-claude-plugins](https://github.com/joaquimscosta/arkhe-claude-plugins)
- **License:** MIT

Install and usage instructions live in the source repository linked above.

## Pricing

- **Free** — Free

## Security capabilities

Automated source analysis of v0.1.0 — what this tool can access:

- **Network access:** no
- **Filesystem access:** no
- **Shell / process execution:** no
- **Environment & secrets:** yes
- **Dynamic code execution:** no

*"Yes" means the capability is present in the source — more access means more to trust, not that it is unsafe.*


## Versions

- **0.1.0** — security scan: passed — Imported from the upstream source.

## Links

- Listing page: https://agentstack.voostack.com/l/skill-joaquimscosta-arkhe-claude-plugins-sops-encrypt
- Seller: https://agentstack.voostack.com/s/joaquimscosta
- Browse the marketplace: https://agentstack.voostack.com/browse

---
Listed on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Creators keep 70%.
