Why would you have "production secrets" in a .env file in the first place? I feel like that's the real problem here.
What are people doing that requires something like this?
The idea seems nice with a simple yet effective implementation. While I think I currently have a shell script syntax highlight plugin reading env files, it's definitely overkill. Now if only this could protect from random npm packages reading your env files...