private-context-bootstrap
Bootstrap private, remote-backed user context onto a fresh machine for opportunity workflows without committing personal data to public repositories.
How do I install this agent skill?
npx skills add https://github.com/arthurzakirov/opportunityos --skill private-context-bootstrapIs this agent skill safe to install?
- Gen Agent Trust Hubwarn
The skill establishes a workflow for bootstrapping sensitive user information, such as identity profiles and legal documents, from remote repositories into local storage. While it promotes security best practices like encryption and secret management, it creates a potential attack surface by instructing the agent to handle highly sensitive PII and execute external scripts from remote sources.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
Private Context Bootstrap
Purpose
Use this skill when an agent needs private user data that must be available across machines, but must not be hardcoded into public skills, prompts, logs, or repositories.
This skill defines how to locate, clone, decrypt, validate, and materialize private local files from remote storage.
Core Principle
Skills are public process definitions. Private data lives outside public skill folders.
Architecture
Use three layers:
- Public skill repository: generic skills, schemas, fake examples, scripts, and documentation. No real personal values.
- Private remote data repository: private YAML, JSONL logs, document manifests, criteria, and optionally PDFs. Prefer file-level encryption.
- Secret manager: bootstrap secrets and encryption keys.
Recommended default:
- Private Git repository for versioned private data.
age+sopsfor encrypted YAML/JSON files.- Git LFS or encrypted archive for PDFs if PDFs are stored in Git.
- Bitwarden Secrets Manager stores the private repo URL if needed, the
ageprivate key, optional access tokens, and optional bootstrap environment variables.
Do not rely on untracked local files as the only source of truth.
Environment Variables
Support these variables:
SELF_SOURCE_REMOTE=""
SELF_SOURCE_HOME="$HOME/.config/self-source"
SELF_SOURCE_REPO="$HOME/.local/share/self-source/repo"
AGENTDESK_PROFILE_PATH="$SELF_SOURCE_HOME/job-applications/application-profile.yaml"
AGENTDESK_DOCUMENT_MANIFEST_PATH="$SELF_SOURCE_HOME/job-applications/document-manifest.yaml"
AGENTDESK_FIELD_POLICY_PATH="$SELF_SOURCE_HOME/job-applications/field-answer-policy.yaml"
AGENTDESK_APPLICATION_LOG_PATH="$SELF_SOURCE_HOME/job-applications/application-log.jsonl"
If variables are absent, use the defaults above.
Bootstrap Workflow
On a fresh machine:
- Check whether
SELF_SOURCE_HOMEexists. - Check whether required private files exist.
- If missing, locate the remote source from
SELF_SOURCE_REMOTE, the configured secret manager, or the user. - Clone or sync the private remote source into
SELF_SOURCE_REPO. - If files are encrypted, decrypt them into
SELF_SOURCE_HOME. - If PDFs are stored remotely, download or sync them.
- Validate all required files against schemas.
- Verify referenced documents exist.
- Refuse to run workflows until validation passes.
Use scripts/bootstrap-private-context.sh from the OpportunityOS repo when available. It coordinates clone/sync, materialization, validation, and the readiness report.
Never Do This
- Never commit decrypted private files to a public repository.
- Never print full private profiles into terminal logs unless explicitly requested.
- Never paste secrets, personal data, or private PDFs into public files.
- Never assume files exist on a fresh machine.
- Never invent missing private values.
- Never silently overwrite private data without making a backup.
Expected Local Layout
After bootstrap:
$SELF_SOURCE_HOME/
shared/
personal-profile.yaml
job-applications/
application-profile.yaml
document-manifest.yaml
field-answer-policy.yaml
application-log.jsonl
documents/
resume.pdf
degree.pdf
transcript.pdf
references.pdf
supporting-bundle.pdf
shared/personal-profile.yaml must follow the bitwarden-personal-profile schema. Domain folders reference it instead of duplicating identity, contact, address, employment, housing, or generic form facts.
Filenames may differ. Agents must use references and manifests, not hardcoded filenames.
Required Checks
Before any workflow uses private data:
- Confirm profile file exists.
- Confirm shared personal profile exists and follows the Bitwarden personal profile shape.
- Confirm document manifest exists.
- Confirm field policy exists.
- Confirm referenced document paths exist if needed.
- Validate schemas.
- Report missing files clearly.
Output
Return private home path, private repo path, profile file status, document manifest status, field policy status, document availability summary, validation errors, and next manual action.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/arthurzakirov/opportunityos/private-context-bootstrap">View private-context-bootstrap on skillZs</a>