AI Agent Hub
Back to skills
1Password CLI Secure Ops Assistant icon

1Password CLI Secure Ops Assistant

IT Ops & Security Updated 2026.08.30

Paste the following prompt into your AI chat to install this skill:

Please install @user_8f5e9358/1password-fork-hq3 by following the guide at https://skillhub.cn/install/skillhub.md.

About this skill

Problem It Solves

When agents or scripts call op, failures often come from unstable session state rather than the command itself: each shell command may get a fresh TTY, causing repeated sign-in prompts, op whoami failures, and interrupted secret access. A second risk is copying secret values into logs, chat, code, or temporary files, which increases exposure.

How The Skill Works

The skill turns 1Password CLI usage into a repeatable workflow. It first follows the official get-started path to check the OS and shell, confirm op --version is available, and ensure desktop app integration is enabled and the app is unlocked. It then requires a fresh tmux session for all op commands, avoiding reused socket or session names. Inside tmux, it runs op signin, completes authorization in the 1Password app, and verifies success with op whoami; only after that verification does it proceed to reading or executing workflows. For multiple accounts, it selects the target account with --account or OP_ACCOUNT.

It also points to two references: installation and app integration, plus real op examples. The safety boundary is explicit: do not paste secrets into logs, chat, or code, and prefer op run or op inject so secrets stay in the process environment rather than being written to disk. If a command reports account is not signed in, the workflow returns to tmux, re-runs op signin, and authorizes in the app. If tmux is unavailable, it stops and asks rather than running op directly.

Scope: the skill focuses on 1Password CLI, desktop app integration, or account authorization flows. It does not replace 1Password policy, audit, or permission management, nor does it automatically fix missing CLI installation or insufficient account permissions.

Use Cases

  • Verify op --version and establish a fresh tmux session before running any 1Password CLI sign-in flow.
  • Select the correct 1Password account with --account or OP_ACCOUNT before reading secrets in multi-account setups.
  • Use op run or op inject during local CI debugging to keep credentials out of logs and temp files.
  • Recover from account is not signed in by rerunning op signin inside tmux and authorizing in the app.

Best For

  • DevOps engineers maintaining 1Password app integration who need to avoid repeated sign-in prompts in scripted shells.
  • SREs writing local deployment scripts who need op run or op inject to keep credentials out of disk and logs.
  • Platform engineers managing multiple 1Password accounts who need op whoami validation before secret access.
  • Engineers reviewing agent safety who need op confined to tmux and secret values kept out of chat or logs.