スキル一覧に戻る
danwag06

receive-secret

by danwag06

P2P encrypted secret sharing.

2🍴 1📅 2026年1月20日
GitHubで見るManusで実行

SKILL.md


Receive Secret

Receive P2P encrypted secrets from send-secret links. Secrets are decrypted and saved directly to files, keeping sensitive content out of the agent's context.

Security Model for Agentic Use

Critical constraint: The agent must NEVER display or read received secret content.

ActionSafeReason
send-secret -r "url" -o ./file.txtYesSaves to file, agent sees only path
send-secret -r "url"NOText secrets display in terminal
Read on saved fileNOWould load secret into context
cat saved fileNOWould display secret to agent

Key insight: Without -o, text secrets display in terminal. The -o flag requires a specific filename, not a directory path.

URL Recognition

send-secret URLs have this pattern:

https://<random>.trycloudflare.com/s/<id>#key=<64-hex-chars>

Example:

https://abc-xyz-123.trycloudflare.com/s/k7m2p#key=9f86d081884c7d659a2feaa0c55ad015a3bf4f1b2b0b822cd15d6c15b0f00a08

The #key=... fragment is essential - it contains the 256-bit decryption key.

Command Reference

# Save to specific file (REQUIRED - must be a filename, not directory)
npx send-secret -r "<url>" -o ./received-secret.txt

# Save with descriptive filename
npx send-secret -r "<url>" -o ./credentials.json

# Save to subdirectory (create dir first, then specify full path)
mkdir -p ./secrets && npx send-secret -r "<url>" -o ./secrets/received.txt

# Alternative syntax
npx send-secret receive "<url>" -o ./secret.txt

Important: The -o flag requires a specific filename. Using a directory path like -o ./ or -o ./secrets/ will fail with "EISDIR: illegal operation on a directory".

Always quote the URL - it contains special characters (#, =).

Workflow

  1. Recognize URL in user message (trycloudflare.com + #key=)
  2. Determine save location:
    • If user specifies a path, use it (ensure it's a filename, not directory)
    • Otherwise, default to ./received-secret.txt
  3. Create parent directory if needed: mkdir -p ./secrets/
  4. Run receive command with -o <filename> (must be a file path, not directory)
  5. Report file location from CLI output
  6. Do not read or display the saved file - task is complete

Output Parsing

Successful receive shows:

◐ Fetching secret...
✔ Secret retrieved

✔ File saved. View with:
  cat "/Users/you/project/credentials.json"

Extract the file path from the output. Report this path to the user. Never execute the suggested cat command.

For text secrets (no filename):

◐ Fetching secret...
✔ Secret retrieved

✔ Saved to ./received-secret.txt

Default Behavior Without -o

Secret TypeWithout -oWith -o
FileSaves to ~/.send-secret/received/ with timestampSaves to specified path
TextDisplays in terminal (UNSAFE)Saves to specified file

Always use -o to maintain control and prevent accidental exposure.

Error Handling

ErrorCauseResolution
"EISDIR: illegal operation on a directory"-o path is a directory, not fileUse specific filename like -o ./secret.txt
"This secret has already been viewed"Single-use link consumedRequest new link from sender
"Failed to fetch: 530"Sender closed terminal/tunnel expiredAsk sender to reshare
"Missing decryption key in URL"URL truncated, missing #key=Get complete URL
"Invalid decryption key format"Key corrupted or incompleteVerify full 64 hex chars
Connection refused/timeoutSender closed terminalAsk sender to reshare
"Failed to fetch: 404"Invalid secret IDVerify URL is correct

Example Interactions

Basic receive

User: "Can you get this secret? https://abc.trycloudflare.com/s/xyz#key=abc123..."

npx send-secret -r "https://abc.trycloudflare.com/s/xyz#key=abc123..." -o ./received-secret.txt

Response: "Secret received and saved to ./received-secret.txt"

Receive to specific file

User: "Download this to credentials.json: [url]"

npx send-secret -r "[url]" -o ./credentials.json

Response: "Secret received and saved to ./credentials.json"

Receive to subdirectory

User: "Download this to my secrets folder: [url]"

mkdir -p ./secrets && npx send-secret -r "[url]" -o ./secrets/received.txt

Response: "Secret received and saved to ./secrets/received.txt"

What NOT To Do

# NEVER use a directory path with -o (causes EISDIR error)
npx send-secret -r "url" -o ./           # WRONG: ./ is a directory
npx send-secret -r "url" -o ./secrets/   # WRONG: ./secrets/ is a directory

# NEVER omit -o for text secrets
npx send-secret -r "url"  # WRONG: may display in terminal

# NEVER read the saved file
cat ./received-secret.json  # WRONG: exposes content
Read ./received-secret.json  # WRONG: loads into context

# NEVER store URL in variable then expand
url="https://..." && npx send-secret -r $url  # May break on special chars

# NEVER commit received secret files to git
git add ./received-secret.txt  # WRONG: exposes secret in repo history
git add .                       # WRONG: may include secret files

After Receiving

Do not commit secret files. After receiving, remind the user:

  • Add the file to .gitignore if it should stay in the project
  • Move it outside the repo if it's temporary
  • Never use git add . which may accidentally include secrets
  • send-secret-file - For sending files securely
  • send-secret-clipboard - For sharing clipboard contents (macOS)

スコア

総合スコア

60/100

リポジトリの品質指標に基づく評価

SKILL.md

SKILL.mdファイルが含まれている

+20
LICENSE

ライセンスが設定されている

+10
説明文

100文字以上の説明がある

0/10
人気

GitHub Stars 100以上

0/15
最近の活動

3ヶ月以内に更新がある

0/10
フォーク

10回以上フォークされている

0/5
Issue管理

オープンIssueが50未満

+5
言語

プログラミング言語が設定されている

+5
タグ

1つ以上のタグが設定されている

0/5

レビュー

💬

レビュー機能は近日公開予定です