
Sops Encrypt
- 3 installs
- 21 repo stars
- Updated August 5, 2026
- joaquimscosta/arkhe-claude-plugins
Encrypts .env files with SOPS and age by converting dotenv to YAML first to avoid a known SOPS dotenv corruption bug.
About
Encrypts .env files using SOPS and age, converting dotenv to YAML to avoid SOPS bug #1435. A developer uses it to secure environment secrets before committing or sharing them.
- Converts dotenv to YAML to sidestep SOPS bug #1435
- Auto-detects unencrypted .env files
Sops Encrypt by the numbers
- 3 all-time installs (skills.sh)
- Ranked #1,752 of 2,203 Security skills by installs in the Skillselion catalog
- Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/joaquimscosta/arkhe-claude-plugins --skill sops-encryptAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 3 |
|---|---|
| repo stars | ★ 21 |
| Last updated | August 5, 2026 |
| Repository | joaquimscosta/arkhe-claude-plugins ↗ |
What it does
Encrypts .env files with SOPS and age by converting dotenv to YAML first to avoid a known SOPS dotenv corruption bug.
Files
SOPS Encrypt
Encrypt .env files by converting to YAML and encrypting with SOPS + age.
Why YAML? SOPS dotenv store has a known bug (#1435) that corrupts backslash and \n sequences. The helper script converts dotenv→YAML before encryption.
Workflow
1. Detect current state:
python3 ${CLAUDE_SKILL_DIR}/../sops-setup/scripts/detect_sops.py <project-root>2. Verify prerequisites:
tools.sops.installedmust be true — if not, tell user to run/devtools:sops-setupproject.sops_yaml.existsmust be true — if not, tell user to run/devtools:sops-setupage_key.existsmust be true — if not, tell user to run/devtools:sops-setup
3. Show unencrypted .env files from project.env_files. If empty, report "No .env files found to encrypt" and exit.
4. Use `AskUserQuestion` (multiSelect: true) — which files to encrypt. List each .env* file. If a corresponding .enc.yaml file already exists, note it will be overwritten.
5. Encrypt each selected file (convert dotenv→YAML, then encrypt):
python3 ${CLAUDE_SKILL_DIR}/../sops-setup/scripts/dotenv_yaml.py to-yaml <file> > <file>.enc.yaml.tmp
sops --encrypt <file>.enc.yaml.tmp > <file>.enc.yaml
rm <file>.enc.yaml.tmpExample: .env.local → .env.local.enc.yaml
6. Verify each encrypted file exists and is non-empty.
7. Summary:
| File | Encrypted To | Status |
|------|-------------|--------|
| .env.local | .env.local.enc.yaml | done |
| .env.production | .env.production.enc.yaml | done |Remind user to commit the .enc.yaml files.
Key Rules
- Always verify
.sops.yamlexists before attempting encryption - Always convert dotenv→YAML before encrypting (use the helper script)
- Warn if an
.enc.yamlfile will be overwritten - Never delete the original
.envfile — only create the.enc.yamlcopy - Clean up
.tmpfiles even if encryption fails