AI Agent Hub
Back to skills
1Password CLI Operations icon

1Password CLI Operations

IT Ops & Security Updated 2026.08.30

Paste the following prompt into your AI chat to install this skill:

Install @user_8f5e9358/1password-fork-hq using https://skillhub.cn/install/skillhub.md.

About this skill

Problem

When agents call the 1Password CLI from a non-interactive shell, op can fail because each command gets a fresh TTY, the desktop app is locked, account selection is ambiguous, or sign-in state is lost. Printing secrets into logs, chat, or code also creates security noise. This skill targets the operational path of installing, integrating, signing in, and reading values safely according to the official CLI guidance.

How It Works

The workflow first checks OS and shell, then verifies op --version and confirms desktop app integration is enabled and the app is unlocked. The key constraint is that all op commands run inside a dedicated tmux session with a fresh socket/session name, not in transient command shells. It then signs in inside tmux, authorizes in the desktop app, and requires op whoami to succeed before any secret read. If multiple accounts are present, use --account or OP_ACCOUNT explicitly.

Boundaries

It fits secure CLI-driven IT operations where secrets must not be written to disk, chat, logs, or code. If tmux is unavailable, the skill stops and asks instead of bypassing isolation. Without desktop integration, an op account add path may be needed, but the same secret-handling guardrails apply.

Use Cases

  • Read deployment secrets in a local shell without writing them to logs or disk, using tmux for `op` sign-in, `whoami`, and `op run` injection.
  • When `op` shows an unsigned-in account, rerun `op signin` inside tmux, authorize in the desktop app, and verify with `op whoami`.
  • Select service-account secrets in a multi-account environment using `--account` or `OP_ACCOUNT` to avoid reading the wrong team secret.
  • Before first 1Password CLI use, verify shell, CLI version, desktop integration, and app unlock state before calling `op` securely.

Best For

  • Ops engineers running release scripts who need to read 1Password secrets in a controlled shell without writing them to disk.
  • Security administrators managing multiple 1Password accounts who need explicit account switching and sign-in verification.
  • Automation engineers integrating agent CLI tools who need stable TTY behavior for `op signin`, `op whoami`, and secret reads.
  • SREs debugging `op` sign-in failures who need to rerun `op signin` inside tmux and confirm desktop app authorization.