- Home
- Skills
- Code Quality & Review
- env-doctor-advanced-pro
More screenshots
Works with the AI tools you already use
Env Doctor Advanced Pro
Find configuration drift across a repository fleet, produce reviewable remediation artifacts, and gate CI secret coverage with machine-readable reports.
$5
env-doctor-advanced-pro
Example session with this skill installed
** Audit env health across my api/ and worker/ services before Friday's deploy.
- Read your context and instructions
- Compiled the env-doctor-advanced-pro
**
Fleet scan (2 repos): worker/.env TRACKED by git [CRITICAL], 2 undocumented vars, DATABASE_URL missing locally. api/.env.example TRACKED [CRITICAL].
CI secret sync: DATABASE_URL missing from GitHub Actions (source: gh).
Artifacts written: .env.example.sync.patch, gitignore.fix.patch, secret-rotation-runbook.md.
Gate: EXIT 2 — rotate the suspect credential, fix the GitHub secret, commit the ignore changes, re-run until clean.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Find configuration drift across a repository fleet, produce reviewable remediation artifacts, and gate CI secret coverage with machine-readable reports.
Free vs Pro
Free covers single-project diagnosis (missing variables, secret exposure, version mismatches, path issues). Pro adds the fleet layer: multi-repo aggregate scan, generated remediation artifacts, GitHub Actions secret-name sync, JSON and exit-code CI gating, and the pre-commit drift re-audit workflow.
Upgrade Path
Install the free skill for a focused audit of one repository. Upgrade to Pro when the same variables must stay aligned across services, CI, and developer machines. Start with env_fleet_scan.py, then use secret_sweep.py and env_gap_report.py as release checks.
Upgrade to Pro: env-doctor-advanced-pro
Tags: environment security secrets ci-cd github-actions devops git
Version: 1.0.0
The Problem
The free Environment Doctor is strong for a single project, but teams rarely ship one project. With 9 installs, the free skill has already proven demand for environment diagnosis; the next failure happens between repositories: one service has a variable that another omits, CI secrets drift from .env.example, and a secret removed from the working tree remains in git history. Manual comparison is slow and easy to under-report.
What You Get
- Multi-repository fleet scan with per-repo findings and aggregate dashboard counts.
- Secret sweep that creates
.env.examplesync guidance,.gitignorefixes, and a tailored rotation/purge runbook. - GitHub Actions secret-sync checker using
gh secret list, with explicit offline status when GitHub cannot be queried. - JSON reports and findings exit codes for CI gates, plus baseline drift diff.
- Pre-commit hook installer pattern that blocks commits until findings are reviewed.
Why This Beats Prompting It Yourself
Free gives a single-project diagnosis and explains what to inspect. Pro operationalizes the result across N repositories, generates artifacts you can review in a pull request, checks the actual GitHub secret-name inventory, and returns stable machine-readable evidence for CI. It still preserves the free version's safety boundary: no values are printed, no secrets are rotated, and no history is rewritten automatically.
Example Session
Scenario: An engineer runs the free skill on
api/and gets a useful report, but misses thatworker/has a tracked.envand thatDATABASE_URLis absent from GitHub Actions. Free attempt: single project checked, worker/ not included — FAILING for the fleet gate.
You: Audit env health across my api/ and worker/ services before Friday's deploy.
Agent: Fleet scan (2 repos): worker/.env TRACKED by git [CRITICAL], 2 undocumented vars, DATABASE_URL missing locally. api/.env.example TRACKED [CRITICAL]. CI secret sync: DATABASE_URL missing from GitHub Actions (source: gh). Artifacts written: .env.example.sync.patch, gitignore.fix.patch, secret-rotation-runbook.md. Gate: EXIT 2 — rotate the suspect credential, fix the GitHub secret, commit the ignore changes, re-run until clean.
Use Cases
- Platform teams onboarding a fleet of microservices.
- Release engineers proving required variables exist in GitHub Actions before deployment.
- Security teams responding to a suspected committed secret.
- Teams maintaining a pre-commit control for configuration hygiene.
Known Limitations
gh secret listchecks names only and requires authentication; it cannot validate secret values or organization/environment scope automatically.- Generated patches are review artifacts, not automatic edits.
- Historical purge commands require git filter-repo or BFG, coordination, and a force-push decision.
- Source-code variable discovery is intentionally conservative; application-specific loaders may need manual additions.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 6 days ago
- Passed all security checks, Safe to install