Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Set up op CLI, sign in, and read or inject secrets.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-12 | ✗→✓ | ▲ Improved | 85% | 0% |
| case-13 | ✗→✓ | ▲ Improved | 299% | 0% |
| case-01 | ✓→✗ | ▼ Worse | 6% | 0% |
| case-02 | ✓→✓ | = Same ✓ | 194% | 0% |
| case-03 | ✓→✓ | = Same ✓ | 83% | 0% |
Use this skill when the user wants secrets managed through 1Password instead of plaintext env vars or files.
op) installedOP_SERVICE_ACCOUNT_TOKEN), or Connect servertmux available for stable authenticated sessions during Hermes terminal calls (desktop app flow only)op signinop://Vault/Item/fieldop injectop runSet OP_SERVICE_ACCOUNT_TOKEN in ${HERMES_HOME:-~/.hermes}/.env (the skill will prompt for this on first load). No desktop app needed. Supports op read, op inject, op run.
bashexport OP_SERVICE_ACCOUNT_TOKEN="your-token-here" op whoami # verify — should show Type: SERVICE_ACCOUNT
op signin and approve the biometric promptbashexport OP_CONNECT_HOST="http://localhost:8080" export OP_CONNECT_TOKEN="your-connect-token"
bash# macOS brew install 1password-cli # Linux (official package/install docs) # See references/get-started.md for distro-specific links. # Windows (winget) winget install AgileBits.1Password.CLI
bashop --version
Hermes terminal commands are non-interactive by default and can lose auth context between calls. For reliable op use with desktop app integration, run sign-in and secret operations inside a dedicated tmux session.
Note: This is NOT needed when using OP_SERVICE_ACCOUNT_TOKEN — the token persists across terminal calls automatically.
bashSOCKET_DIR="${TMPDIR:-/tmp}/hermes-tmux-sockets" mkdir -p "$SOCKET_DIR" SOCKET="$SOCKET_DIR/hermes-op.sock" SESSION="op-auth-$(date +%Y%m%d-%H%M%S)" tmux -S "$SOCKET" new -d -s "$SESSION" -n shell # Sign in (approve in desktop app when prompted) tmux -S "$SOCKET" send-keys -t "$SESSION":0.0 -- "eval \"\$(op signin --account my.1password.com)\"" Enter # Verify auth tmux -S "$SOCKET" send-keys -t "$SESSION":0.0 -- "op whoami" Enter # Example read tmux -S "$SOCKET" send-keys -t "$SESSION":0.0 -- "op read 'op://Private/Npmjs/one-time password?attribute=otp'" Enter # Capture output when needed tmux -S "$SOCKET" capture-pane -p -J -t "$SESSION":0.0 -S -200 # Cleanup tmux -S "$SOCKET" kill-session -t "$SESSION"
bashop read "op://app-prod/db/password"
bashop read "op://app-prod/npm/one-time password?attribute=otp"
bashecho "db_password: {{ op://app-prod/db/password }}" | op inject
bashexport DB_PASSWORD="op://app-prod/db/password" op run -- sh -c '[ -n "$DB_PASSWORD" ] && echo "DB_PASSWORD is set" || echo "DB_PASSWORD missing"'
op run / op inject instead of writing secrets into files.op signin again in the same tmux session.For non-interactive use, authenticate with OP_SERVICE_ACCOUNT_TOKEN and avoid interactive op signin. Service accounts require CLI v2.18.0+.
references/get-started.mdreferences/cli-examples.mdOther measured skills in the registry, with their headline benchmark lift.