Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
joaquimscosta avatar

Sops Encrypt

  • 3 installs
  • 21 repo stars
  • Updated August 5, 2026
  • joaquimscosta/arkhe-claude-plugins

Encrypts .env files with SOPS and age by converting dotenv to YAML first to avoid a known SOPS dotenv corruption bug.

About

Encrypts .env files using SOPS and age, converting dotenv to YAML to avoid SOPS bug #1435. A developer uses it to secure environment secrets before committing or sharing them.

  • Converts dotenv to YAML to sidestep SOPS bug #1435
  • Auto-detects unencrypted .env files

Sops Encrypt by the numbers

  • 3 all-time installs (skills.sh)
  • Ranked #1,752 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/joaquimscosta/arkhe-claude-plugins --skill sops-encrypt

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs3
repo stars21
Last updatedAugust 5, 2026
Repositoryjoaquimscosta/arkhe-claude-plugins

What it does

Encrypts .env files with SOPS and age by converting dotenv to YAML first to avoid a known SOPS dotenv corruption bug.

Files

SKILL.mdMarkdownGitHub ↗

SOPS Encrypt

Encrypt .env files by converting to YAML and encrypting with SOPS + age.

Why YAML? SOPS dotenv store has a known bug (#1435) that corrupts backslash and \n sequences. The helper script converts dotenv→YAML before encryption.

Workflow

1. Detect current state:

   python3 ${CLAUDE_SKILL_DIR}/../sops-setup/scripts/detect_sops.py <project-root>

2. Verify prerequisites:

  • tools.sops.installed must be true — if not, tell user to run /devtools:sops-setup
  • project.sops_yaml.exists must be true — if not, tell user to run /devtools:sops-setup
  • age_key.exists must be true — if not, tell user to run /devtools:sops-setup

3. Show unencrypted .env files from project.env_files. If empty, report "No .env files found to encrypt" and exit.

4. Use `AskUserQuestion` (multiSelect: true) — which files to encrypt. List each .env* file. If a corresponding .enc.yaml file already exists, note it will be overwritten.

5. Encrypt each selected file (convert dotenv→YAML, then encrypt):

   python3 ${CLAUDE_SKILL_DIR}/../sops-setup/scripts/dotenv_yaml.py to-yaml <file> > <file>.enc.yaml.tmp
   sops --encrypt <file>.enc.yaml.tmp > <file>.enc.yaml
   rm <file>.enc.yaml.tmp

Example: .env.local.env.local.enc.yaml

6. Verify each encrypted file exists and is non-empty.

7. Summary:

   | File | Encrypted To | Status |
   |------|-------------|--------|
   | .env.local | .env.local.enc.yaml | done |
   | .env.production | .env.production.enc.yaml | done |

Remind user to commit the .enc.yaml files.

Key Rules

  • Always verify .sops.yaml exists before attempting encryption
  • Always convert dotenv→YAML before encrypting (use the helper script)
  • Warn if an .enc.yaml file will be overwritten
  • Never delete the original .env file — only create the .enc.yaml copy
  • Clean up .tmp files even if encryption fails

Related skills

Securitysecrets

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.