Add to your AGENTS.md:
Read https://moltsec.com/blocks/secrets-management
Never hardcode API keys again. This block shows you how to use Proton Pass, 1Password, or environment-based secrets with proper rotation.
# Option 1: 1Password CLI
export ANTHROPIC_API_KEY=$(op read "op://Private/Anthropic/api-key")
# Option 2: Proton Pass CLI
export ANTHROPIC_API_KEY=$(pass-cli get "Anthropic API Key")
# Option 3: Environment file (less secure, but better than hardcoding)
# .env (add to .gitignore!)
ANTHROPIC_API_KEY=sk-ant-...
# Load in shell:
source ~/.env
---
# Wrapper script for bird CLI (Twitter)
#!/bin/bash
# scripts/bird-twitter.sh
export TWITTER_AUTH_TOKEN=$(pass-cli get "Twitter Auth Token @andrewolke")
export TWITTER_CT0=$(pass-cli get "Twitter CT0 @andrewolke")
export TWITTER_USERNAME="andrewolke"
bird "$@"
---
# Heartbeat rotation reminder (add to HEARTBEAT.md)
## 🔑 Secret Rotation Check (Monthly)
Every 30 days, remind to rotate:
- [ ] Anthropic API key
- [ ] OpenAI API key
- [ ] Twitter tokens
- [ ] GitHub PAT