Install
$ agentstack add skill-mathews-tom-armory-env-validator ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Env Validator
Validates environment variable configurations by cross-referencing .env files against project requirements. Catches missing variables, type errors, insecure defaults, and orphaned entries before they cause runtime failures.
Reference Files
| File | Contents | Load When | | ------------------------------------ | ------------------------------------------------- | ---------------------- | | references/validation-rules.md | Built-in validation rules and severity definitions | Always |
Prerequisites
- A
.envfile (or equivalent) in the project - Optionally:
.env.example,docker-compose.yml, or deployment manifests for cross-referencing
Workflow
Phase 1: Discovery
Locate environment configuration sources in the project:
- Primary file: Find
.envin the project root. If absent, check for.env.local,.env.development,.env.production - Schema file: Find
.env.exampleor.env.template— this defines the expected variables - Code references: Grep for
os.environ,process.env,env::var,os.Getenvpatterns to find variables referenced in code - Deployment manifests: Check
docker-compose.yml,Dockerfile,k8s/manifests for${VAR}orENV VARpatterns
Report what was found before proceeding.
Phase 2: Schema Extraction
Build the expected variable schema from discovered sources:
For each variable found across all sources, record:
| Field | Source | | ----------- | --------------------------------------------------------- | | Name | Variable name (e.g., DATABASE_URL) | | Required | Present in code references or marked required in example | | Type hint | Inferred from usage (URL, integer, boolean, string, path) | | Default | Value in .env.example if present | | Used in | List of files that reference this variable |
Phase 3: Validation
Run these checks against the primary .env file:
- Missing required variables (CRITICAL)
- Variable referenced in code but absent from
.env - Variable in
.env.examplewithout a default but absent from.env
- Type mismatches (HIGH)
PORT=abcwhen code doesint(os.environ["PORT"])DEBUG=yeswhen code expects boolean (true/false)- URL variables without valid URL format
- Insecure defaults (HIGH)
SECRET_KEY=changeme,PASSWORD=password,API_KEY=xxxDEBUG=trueorDEBUG=1in production-targeted files- Empty values for security-critical variables
- Unreferenced variables (MEDIUM)
- Variables in
.envnot referenced anywhere in code or manifests - May indicate stale configuration
- Format issues (LOW)
- Lines without
KEY=VALUEformat - Trailing whitespace in values
- Inconsistent quoting (mixing single/double/no quotes)
- Duplicate variable definitions (last wins, but likely a mistake)
See references/validation-rules.md for the complete rule catalog.
Phase 4: Report
Produce a structured validation report:
# Environment Validation Report
**File:** `.env`
**Schema:** `.env.example` + code references
**Verdict:** PASS | FAIL
## Summary
| Severity | Count |
|----------|-------|
| CRITICAL | N |
| HIGH | N |
| MEDIUM | N |
| LOW | N |
## CRITICAL
### [ENV-001] Missing required variable: DATABASE_URL
- **Referenced in:** `src/db.py:12`, `docker-compose.yml:8`
- **Expected type:** URL (postgresql://...)
- **Fix:** Add `DATABASE_URL=postgresql://user:pass@localhost:5432/dbname` to `.env`
## HIGH
...
## Unreferenced Variables
| Variable | In .env | In Code | In Manifests | Status |
|-----------------|---------|---------|--------------|--------------|
| LEGACY_API_KEY | Yes | No | No | Unreferenced |
## Recommendations
1. [Highest priority fix]
2. [Second fix]
Error Handling
| Error | Resolution | | --------------------------------- | ----------------------------------------------------- | | No .env file found | Report absence; check for alternative env sources | | No .env.example or schema | Validate based on code references only | | Binary or very large .env | Skip; report as unsupported format | | No code references found | Validate format and security only; skip completeness |
Limitations
- Cannot validate runtime-injected variables (from vault, AWS SSM, etc.)
- Type inference is heuristic — may misclassify complex values
- Does not check variable values against external services (e.g., valid API key format)
- Production vs. development distinction requires file naming conventions
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: Mathews-Tom
- Source: Mathews-Tom/armory
- License: MIT
- Homepage: https://mathews-tom.github.io/armory/
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.