Agent skill

Env Secrets Manager

by alirezarezvani in alirezarezvani/claude-skills

Manage environment-variable hygiene and secrets safety across local development and production.

MITAuto-check: notesDevOps & Cloud

Install Env Secrets Manager

skills CLI
$ npx skills add alirezarezvani/claude-skills --skill env-secrets-manager -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alirezarezvani/claude-skills env-secrets-manager --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alirezarezvani/claude-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/engineering/skills/env-secrets-manager .claude/skills/env-secrets-manager && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
env-secrets-manager
GitHub stars
28k
Token cost
~2.7k tokens
SKILL.md length
1,151 words
Files
4 (incl. scripts, references)
Skills in repo
342
Repo updated
First seen
Licence
MIT

At a glance

Manage environment-variable hygiene and secrets safety across local development and production.

  • Works in 3 steps: Detection → Rotation → Automation
  • Auditing .env files for committed secrets
  • SKILL.md covers Overview, Core Capabilities, When to Use and Quick Start, plus 10 more sections
  • Runs Python scripts from its folder; calls python3, gitleaks and brew; reaches github.com

What it does

Env Secrets Manager is an agent skill from alirezarezvani/claude-skills. Manage environment-variable hygiene and secrets safety across local development and production. Practical auditing, drift awareness, rotation readiness. Use when auditing .env files for committed secrets, planning a credential rotation, debugging missing-env-var production incidents, or hardening a new project against secrets leakage.

Its SKILL.md is about 2.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including scripts and reference files (for example `references/secret-patterns.md`, `references/validation-detection-rotation.md` and `scripts/env_auditor.py`).

It sits in DevOps & Cloud, covering Secrets management. The repository describes itself as: 380 Claude Code skills & agent skills & plugins (30+ Agents, 70+ custom commands, 380+ skills, customizable references, scripts)for Claude Code, Codex, Gemini CLI, Cursor, and 8… The licence is MIT.

When your agent uses it

  • Auditing .env files for committed secrets
  • Planning a credential rotation
  • Debugging missing-env-var production incidents
  • Hardening a new project against secrets leakage

Example prompts

  • “/env-secrets-manager”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Detection
  2. Rotation
  3. Automation

What it can do on your machine

Read from SKILL.md and the folder at commit 19392f7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • gitleaks
    • brew

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Env Secrets Manager loads about 2.7k tokens when it runs, and up to ~5.3k if it reads all its reference files. Until then it costs about 89 tokens; SKILL.md has 1,151 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:3
    s, rotation readiness. Use when auditing .env files for committed secrets, planning a credential rotation, debugging mis
  • NoteMentions a .env fileSKILL.md:20
    - `.env` and `.env.example` lifecycle guidance
  • NoteMentions a .env fileSKILL.md:84
    ications should never read secrets from `.env` files or environment variables baked into container images. Use a dedicat

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from alirezarezvani/claude-skills at commit 19392f7, republished under its MIT licence (© alirezarezvani). 1,151 words, ~2,668 tokens.

Download SKILL.mdSave it as .claude/skills/env-secrets-manager/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
env-secrets-manager
description
Manage environment-variable hygiene and secrets safety across local development and production. Practical auditing, drift awareness, rotation readiness. Use when auditing .env files for committed secrets, planning a credential rotation, debugging missing-env-var production incidents, or hardening a new project against secrets leakage.

Env & Secrets Manager

Tier: POWERFUL Category: Engineering Domain: Security / DevOps / Configuration Management


Overview

Manage environment-variable hygiene and secrets safety across local development and production workflows. This skill focuses on practical auditing, drift awareness, and rotation readiness.

Core Capabilities

  • .env and .env.example lifecycle guidance
  • Secret leak detection for repository working trees
  • Severity-based findings for likely credentials
  • Operational pointers for rotation and containment
  • Integration-ready outputs for CI checks

When to Use

  • Before pushing commits that touched env/config files
  • During security audits and incident triage
  • When onboarding contributors who need safe env conventions
  • When validating that no obvious secrets are hardcoded

Quick Start

bash
# Scan a repository for likely secret leaks
python3 scripts/env_auditor.py /path/to/repo

# JSON output for CI pipelines
python3 scripts/env_auditor.py /path/to/repo --json

  1. Run scripts/env_auditor.py on the repository root.
  2. Prioritize critical and high findings first.
  3. Rotate real credentials and remove exposed values.
  4. Update .env.example and .gitignore as needed.
  5. Add or tighten pre-commit/CI secret scanning gates.

Reference Docs

  • references/validation-detection-rotation.md
  • references/secret-patterns.md

Common Pitfalls

  • Committing real values in .env.example
  • Rotating one system but missing downstream consumers
  • Logging secrets during debugging or incident response
  • Treating suspected leaks as low urgency without validation

Best Practices

  1. Use a secret manager as the production source of truth.
  2. Keep dev env files local and gitignored.
  3. Enforce detection in CI before merge.
  4. Re-test application paths immediately after credential rotation.

Cloud Secret Store Integration

Production applications should never read secrets from .env files or environment variables baked into container images. Use a dedicated secret store instead.

Provider Comparison
ProviderBest ForKey Feature
HashiCorp VaultMulti-cloud / hybridDynamic secrets, policy engine, pluggable backends
AWS Secrets ManagerAWS-native workloadsNative Lambda/ECS/EKS integration, automatic RDS rotation
Azure Key VaultAzure-native workloadsManaged HSM, Azure AD RBAC, certificate management
GCP Secret ManagerGCP-native workloadsIAM-based access, automatic replication, versioning
Selection Guidance
  • Single cloud provider — use the cloud-native secret manager. It integrates tightly with IAM, reduces operational overhead, and costs less than self-hosting.
  • Multi-cloud or hybrid — use HashiCorp Vault. It provides a uniform API across environments and supports dynamic secret generation (database credentials, cloud IAM keys) that expire automatically.
  • Kubernetes-heavy — combine External Secrets Operator with any backend above to sync secrets into K8s Secret objects without hardcoding.
Application Access Patterns
  1. SDK/API pull — application fetches secret at startup or on-demand via provider SDK.
  2. Sidecar injection — a sidecar container (e.g., Vault Agent) writes secrets to a shared volume or injects them as environment variables.
  3. Init container — a Kubernetes init container fetches secrets before the main container starts.
  4. CSI driver — secrets mount as a filesystem volume via the Secrets Store CSI Driver.

Cross-reference: See engineering/secrets-vault-manager for production vault infrastructure patterns, HA deployment, and disaster recovery procedures.


Secret Rotation Workflow

Stale secrets are a liability. Rotation ensures that even if a credential leaks, its useful lifetime is bounded.

Phase 1: Detection
  • Track secret creation and expiry dates in your secret store metadata.
  • Set alerts at 30, 14, and 7 days before expiry.
  • Use scripts/env_auditor.py to flag secrets with no recorded rotation date.
Phase 2: Rotation
  1. Generate a new credential (API key, database password, certificate).
  2. Deploy the new credential to all consumers (apps, services, pipelines) in parallel.
  3. Verify each consumer can authenticate using the new credential.
  4. Revoke the old credential only after all consumers are confirmed healthy.
  5. Update metadata with the new rotation timestamp and next rotation date.
Phase 3: Automation
  • AWS Secrets Manager — use built-in Lambda-based rotation for RDS, Redshift, and DocumentDB.
  • HashiCorp Vault — configure dynamic secrets with TTLs; credentials are generated on-demand and auto-expire.
  • Azure Key Vault — use Event Grid notifications to trigger rotation functions.
  • GCP Secret Manager — use Pub/Sub notifications tied to Cloud Functions for rotation logic.
Emergency Rotation Checklist

When a secret is confirmed leaked:

  1. Immediately revoke the compromised credential at the provider level.
  2. Generate and deploy a replacement credential to all consumers.
  3. Audit access logs for unauthorized usage during the exposure window.
  4. Scan git history, CI logs, and artifact registries for the leaked value.
  5. File an incident report documenting scope, timeline, and remediation steps.
  6. Review and tighten detection controls to prevent recurrence.

CI/CD Secret Injection

Secrets in CI/CD pipelines require careful handling to avoid exposure in logs, artifacts, or pull request contexts.

Show full SKILL.md (460 more words)Show less
GitHub Actions
  • Use repository secrets or environment secrets via ${{ secrets.SECRET_NAME }}.
  • Prefer OIDC federation (aws-actions/configure-aws-credentials with role-to-assume) over long-lived access keys.
  • Environment secrets with required reviewers add approval gates for production deployments.
  • GitHub automatically masks secrets in logs, but avoid echo or toJSON() on secret values.
GitLab CI
  • Store secrets as CI/CD variables with the masked and protected flags enabled.
  • Use HashiCorp Vault integration (secrets:vault) for dynamic secret injection without storing values in GitLab.
  • Scope variables to specific environments (production, staging) to enforce least privilege.
Universal Patterns
  • Never echo or print secret values in pipeline output, even for debugging.
  • Use short-lived tokens (OIDC, STS AssumeRole) instead of static credentials wherever possible.
  • Restrict PR access — do not expose secrets to pipelines triggered by forks or untrusted branches.
  • Rotate CI secrets on the same schedule as application secrets; pipeline credentials are attack vectors too.
  • Audit pipeline logs periodically for accidental secret exposure that masking may have missed.

Pre-Commit Secret Detection

Catching secrets before they reach version control is the most cost-effective defense. Two leading tools cover this space.

gitleaks
toml
# .gitleaks.toml — minimal configuration
[extend]
useDefault = true

[[rules]]
id = "custom-internal-token"
description = "Internal service token pattern"
regex = '''INTERNAL_TOKEN_[A-Za-z0-9]{32}'''
secretGroup = 0
  • Install: brew install gitleaks or download from GitHub releases.
  • Pre-commit hook: gitleaks git --pre-commit --staged
  • Baseline scanning: gitleaks detect --source . --report-path gitleaks-report.json
  • Manage false positives in .gitleaksignore (one fingerprint per line).
detect-secrets
bash
# Generate baseline
detect-secrets scan --all-files > .secrets.baseline

# Pre-commit hook (via pre-commit framework)
# .pre-commit-config.yaml
repos:
  - repo: https://github.com/Yelp/detect-secrets
    rev: v1.5.0
    hooks:
      - id: detect-secrets
        args: ['--baseline', '.secrets.baseline']
  • Supports custom plugins for organization-specific patterns.
  • Audit workflow: detect-secrets audit .secrets.baseline interactively marks true/false positives.
False Positive Management
  • Maintain .gitleaksignore or .secrets.baseline in version control so the whole team shares exclusions.
  • Review false positive lists during security audits — patterns may mask real leaks over time.
  • Prefer tightening regex patterns over broadly ignoring files.

Audit Logging

Knowing who accessed which secret and when is critical for incident investigation and compliance.

Cloud-Native Audit Trails
ProviderServiceWhat It Captures
AWSCloudTrailEvery GetSecretValue, DescribeSecret, RotateSecret API call
AzureActivity Log + Diagnostic LogsKey Vault access events, including caller identity and IP
GCPCloud Audit LogsData access logs for Secret Manager with principal and timestamp
VaultAudit BackendFull request/response logging (file, syslog, or socket backend)
Alerting Strategy
  • Alert on access from unknown IP ranges or service accounts outside the expected set.
  • Alert on bulk secret reads (more than N secrets accessed within a time window).
  • Alert on access outside deployment windows when no CI/CD pipeline is running.
  • Feed audit logs into your SIEM (Splunk, Datadog, Elastic) for correlation with other security events.
  • Review audit logs quarterly as part of access recertification.

Cross-References

This skill covers env hygiene and secret detection. For deeper coverage of related domains, see:

SkillPathRelationship
Secrets Vault Managerengineering/secrets-vault-managerProduction vault infrastructure, HA deployment, DR
Senior SecOpsengineering/senior-secopsSecurity operations perspective, incident response
CI/CD Pipeline Builderengineering/ci-cd-pipeline-builderPipeline architecture, secret injection patterns
Infrastructure as Codeengineering/infrastructure-as-codeTerraform/Pulumi secret backend configuration
Container Orchestrationengineering/container-orchestrationKubernetes secret mounting, sealed secrets

© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (scripts, references) in engineering/skills/env-secrets-manager of alirezarezvani/claude-skills.

  • SKILL.md
  • references/secret-patterns.md
  • references/validation-detection-rotation.md
  • scripts/env_auditor.py

Open the folder on GitHubat commit 19392f7

Compare with similar skills

Env Secrets Manager next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Env Secrets Manager compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Env Secrets Manager this skillalirezarezvani/claude-skills28k—~2.7kAutomated safety check: NotesMIT
Iron Proxy Gateway for NanoClawnanocoai/nanoclaw31k—~4.6kAutomated safety check: NotesMIT
LangBot Deployment Guidelangbot-app/LangBot18k—~1.2kAutomated safety check: NotesApache-2.0
Env Var Conventionssgl-project/sglang37k2 repos~2.9kAutomated safety check: PassApache-2.0
Mac Fleet Maintenancesteipete/agent-scripts7.3k—~4.8kAutomated safety check: PassMIT
Add Config Env Varbaserow/baserow6.1k—~1.1kAutomated safety check: PassCustom licence

Similar skills

  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.2k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Env Var Conventions

    sgl-project/sglang

    Conventions for SGLang environment variables — where to define, how to access, how to name, and how to deprecate.

    37k GitHub starsUsed in 2 repos~2.9k tokens
    DevOps & CloudAuto-check passed
  • Mac Fleet Maintenance

    steipete/agent-scripts

    Inventories and maintains a fleet of Macs from a desired-state file: package updates, repo and Xcode sync, and disk, backup and security health reports.

    7.3k GitHub stars~4.8k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Add Config Env Var

    baserow/baserow

    Add a Baserow configuration environment variable for the backend, frontend, or both, and propagate it through settings, Nuxt runtime config, Docker Compose, documentation, consumers, and tests as…

    6.1k GitHub stars~1.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Edgeone Makers CLI

    TencentEdgeOne/edgeone-makers-tools

    EdgeOne Makers CLI command reference. An agent skill from TencentEdgeOne/edgeone-makers-tools.

    1.9k GitHub starsUsed in 1 repo~739 tokens
    DevOps & CloudAuto-check: notes

More from alirezarezvani/claude-skills

All 342 skills in this repo
  • Agile Product Owner

    alirezarezvani/claude-skills

    Writes INVEST-checked user stories with acceptance criteria, splits epics, plans sprints from velocity and ranks the backlog with a weighted score.

    28k GitHub starsUsed in 3 repos~3.2k tokens
    Auto-check passed
  • Product Strategist

    alirezarezvani/claude-skills

    OKR cascade toolkit for product leaders: generates aligned company-to-team OKRs from five strategy types and scores how well they line up.

    28k GitHub starsUsed in 2 repos~1.8k tokens
    Auto-check passed
  • App Store Optimization

    alirezarezvani/claude-skills

    App Store Optimization (ASO) toolkit for researching keywords, analyzing competitor rankings, generating metadata suggestions, and improving app visibility on Apple App Store and Google Play Store.

    28k GitHub starsUsed in 1 repo~4.2k tokens
    Auto-check passed
  • AWS Solution Architect

    alirezarezvani/claude-skills

    Design AWS architectures for startups using serverless patterns and IaC templates.

    28k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Campaign Analytics

    alirezarezvani/claude-skills

    Calculates attribution, funnel and ROI figures for marketing campaigns with three Python scripts that need only the standard library.

    28k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Code to PRD

    alirezarezvani/claude-skills

    Reverse-engineers a frontend, backend or fullstack codebase into a product requirements document with per-page docs, an enum dictionary and an API inventory.

    28k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed

Categories

Questions about Env Secrets Manager

What does Env Secrets Manager do?

Manage environment-variable hygiene and secrets safety across local development and production. Env Secrets Manager is an agent skill from alirezarezvani/claude-skills. Manage environment-variable hygiene and secrets safety across local development and production.

When should I use Env Secrets Manager?

Env Secrets Manager fits situations like: auditing .env files for committed secrets; planning a credential rotation; debugging missing-env-var production incidents; hardening a new project against secrets leakage.

How do I install Env Secrets Manager in Claude Code?

Run `npx skills add alirezarezvani/claude-skills --skill env-secrets-manager -a claude-code`. Or copy the skill folder (engineering/skills/env-secrets-manager in alirezarezvani/claude-skills) into .claude/skills/env-secrets-manager in your project. Claude Code loads it when a task matches its description.

How do I install Env Secrets Manager in Codex?

Run `npx skills add alirezarezvani/claude-skills --skill env-secrets-manager -a codex`. Or copy the skill folder (engineering/skills/env-secrets-manager in alirezarezvani/claude-skills) into .agents/skills/env-secrets-manager in your project. Codex loads it when a task matches its description.

Can I use Env Secrets Manager in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-skills --skill env-secrets-manager -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/env-secrets-manager, .gemini/skills/env-secrets-manager, .github/skills/env-secrets-manager and .opencode/skills/env-secrets-manager in your project.

What does Env Secrets Manager need to run?

Going by SKILL.md and its folder, Env Secrets Manager needs Python for the scripts in its folder and the command-line tools its instructions call (python3, gitleaks and brew). Our summary lists: Python 3.

Does Env Secrets Manager access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Env Secrets Manager safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Env Secrets Manager use?

Env Secrets Manager is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Env Secrets Manager use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.6k tokens, read only when the agent opens those files.

What are the alternatives to Env Secrets Manager?

Skills that share tags, products or a category with Env Secrets Manager: Iron Proxy Gateway for NanoClaw (nanocoai/nanoclaw, 31k stars), LangBot Deployment Guide (langbot-app/LangBot, 18k stars), Env Var Conventions (sgl-project/sglang, 37k stars) and Mac Fleet Maintenance (steipete/agent-scripts, 7.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Env Secrets Manager?

alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-skills, which has 27,891 GitHub stars. The repository holds 342 skills in this directory. The repository was last updated on August 30, 2026.

Source: alirezarezvani/claude-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.