Hashicorp Vault
BagelHole/DevOps-Security-Agent-Skills
Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.
Managing secrets (API keys, database credentials, certificates) with Vault, cloud providers, and Kubernetes.
$ npx skills add ancoleman/ai-design-components --skill managing-secrets -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ancoleman/ai-design-components managing-secrets --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/secret-management .claude/skills/managing-secrets && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "managing-secrets" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/secret-management into .claude/skills/managing-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "managing-secrets", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ancoleman/ai-design-components/tree/main/skills/secret-managementType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ancoleman/ai-design-components --skill managing-secrets -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ancoleman/ai-design-components managing-secrets --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/secret-management .agents/skills/managing-secrets && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "managing-secrets" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/secret-management into .agents/skills/managing-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "managing-secrets", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ancoleman/ai-design-components --skill managing-secrets -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ancoleman/ai-design-components managing-secrets --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/secret-management .cursor/skills/managing-secrets && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "managing-secrets" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/secret-management into .cursor/skills/managing-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "managing-secrets", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ancoleman/ai-design-components.git --path skills/secret-management--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ancoleman/ai-design-components --skill managing-secrets -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ancoleman/ai-design-components managing-secrets --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/secret-management .gemini/skills/managing-secrets && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "managing-secrets" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/secret-management into .gemini/skills/managing-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "managing-secrets", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ancoleman/ai-design-components managing-secretsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ancoleman/ai-design-components --skill managing-secrets -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/secret-management .github/skills/managing-secrets && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "managing-secrets" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/secret-management into .github/skills/managing-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "managing-secrets", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ancoleman/ai-design-components --skill managing-secrets -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ancoleman/ai-design-components managing-secrets --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ancoleman/ai-design-components.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/secret-management .opencode/skills/managing-secrets && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "managing-secrets" agent skill from https://github.com/ancoleman/ai-design-components/tree/main/skills/secret-management into .opencode/skills/managing-secrets/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "managing-secrets", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
managing-secretsManaging secrets (API keys, database credentials, certificates) with Vault, cloud providers, and Kubernetes.
Managing Secrets is an agent skill from ancoleman/ai-design-components. Managing secrets (API keys, database credentials, certificates) with Vault, cloud providers, and Kubernetes. Use when storing sensitive data, rotating credentials, syncing secrets to Kubernetes, implementing dynamic secrets, or scanning code for leaked secrets.
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 21 other files, including scripts and reference files (for example `examples/dynamic-db-credentials/python-hvac.py`, `examples/dynamic-db-credentials/typescript-node-vault.ts` and `examples/vault-eso-setup/external-secrets-operator.yaml`).
It sits in DevOps & Cloud, covering Secrets management and Container orchestration. It works with Kubernetes, HashiCorp Vault and Amazon Web Services. The repository describes itself as: Comprehensive UI/UX and Backend component design skills for AI-assisted development with Claude. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 76551b7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Go, Python and TypeScript, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
vaultbrewgitleaksFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Managing Secrets loads about 2.9k tokens when it runs, and up to ~25k if it reads all its reference files. Until then it costs about 70 tokens; SKILL.md has 941 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ancoleman/ai-design-components at commit 76551b7, republished under its MIT licence (© ancoleman). 941 words, ~2,858 tokens.
.claude/skills/managing-secrets/SKILL.md (or your agent's skills folder). This skill also uses 16 other files; get the full folder from GitHub.Secure storage, rotation, and delivery of secrets (API keys, database credentials, TLS certificates) for applications and infrastructure.
Use when:
| Scenario | Primary Choice | Alternative |
|---|---|---|
| Kubernetes + Multi-Cloud | Vault + ESO | Cloud Secret Manager + ESO |
| Kubernetes + Single Cloud | Cloud Secret Manager + ESO | Vault + ESO |
| Serverless (AWS Lambda) | AWS Secrets Manager | AWS Parameter Store |
| Multi-Cloud Enterprise | HashiCorp Vault | Doppler (SaaS) |
| Small Team (<10 apps) | Doppler, Infisical | 1Password Secrets Automation |
| GitOps-Centric | SOPS (git-encrypted) | Sealed Secrets (K8s-only) |
Decision Tree:
| Secret Type | Use Dynamic? | TTL | Solution |
|---|---|---|---|
| Database credentials | YES | 1 hour | Vault DB engine |
| Cloud IAM (AWS/GCP) | YES | 15 min | Vault cloud engine |
| SSH/RDP access | YES | 5 min | Vault SSH engine |
| TLS certificates | YES | 24 hours | Vault PKI / cert-manager |
| Third-party API keys | NO | Quarterly | Vault KV v2 (manual rotation) |
| Method | Use Case | Rotation | Restart Required |
|---|---|---|---|
| External Secrets Operator | Static secrets, periodic sync | Polling (1h) | Yes |
| Secrets Store CSI Driver | File-based, watch rotation | inotify | No |
| Vault Secrets Operator | Vault-specific, dynamic | Automatic renewal | Optional |
# Create secret
vault kv put secret/myapp/config api_key=sk_live_EXAMPLE
# Read secret
vault kv get secret/myapp/config
# List versions
vault kv metadata get secret/myapp/config# Configure PostgreSQL
vault write database/config/postgres \
plugin_name=postgresql-database-plugin \
connection_url="postgresql://{{username}}:{{password}}@postgres:5432/mydb"
# Create role
vault write database/roles/app-role \
db_name=postgres \
creation_statements="CREATE ROLE \"{{name}}\"..." \
default_ttl="1h"
# Generate credentials
vault read database/creds/app-roleFor detailed Vault architecture, see references/vault-architecture.md.
Syncs secrets from 30+ providers to Kubernetes Secrets.
apiVersion: external-secrets.io/v1beta1
kind: SecretStore
metadata:
name: vault-backend
spec:
provider:
vault:
server: "https://vault.example.com"
auth:
kubernetes:
role: "app-role"apiVersion: external-secrets.io/v1beta1
kind: ExternalSecret
metadata:
name: database-credentials
spec:
refreshInterval: 1h
secretStoreRef:
name: vault-backend
target:
name: db-credentials
data:
- secretKey: password
remoteRef:
key: secret/data/database/configKubernetes-native Vault integration with automatic lease renewal.
apiVersion: secrets.hashicorp.com/v1beta1
kind: VaultDynamicSecret
metadata:
name: postgres-creds
spec:
vaultAuthRef: vault-auth
mount: database
path: creds/app-role
renewalPercent: 67 # Renew at 67% of TTL
destination:
name: dynamic-db-credsFor ESO vs CSI vs VSO comparison, see references/kubernetes-integration.md.
Vault auto-generates credentials with short TTL:
Using cert-manager + Vault PKI:
For detailed rotation workflows, see references/rotation-patterns.md.
import hvac
client = hvac.Client(url='https://vault.example.com')
client.auth.kubernetes(role='app-role', jwt=jwt)
# Fetch dynamic credentials
response = client.secrets.database.generate_credentials(name='postgres-role')
username = response['data']['username']
password = response['data']['password']import vault "github.com/hashicorp/vault/api"
client, _ := vault.NewClient(vault.DefaultConfig())
k8sAuth, _ := auth.NewKubernetesAuth("app-role")
client.Auth().Login(context.Background(), k8sAuth)
secret, _ := client.Logical().Read("database/creds/postgres-role")import vault from 'node-vault';
const client = vault({ endpoint: 'https://vault.example.com' });
await client.kubernetesLogin({ role: 'app-role', jwt });
const response = await client.read('database/creds/postgres-role');For complete examples, see examples/dynamic-db-credentials/.
# Install Gitleaks
brew install gitleaks
# Run on staged files
gitleaks protect --staged --verbosePre-commit hook prevents secrets from being committed.
For setup, see examples/secret-scanning/pre-commit.
# GitHub Actions
- name: Run Gitleaks
uses: gitleaks/gitleaks-action@v2When a secret is leaked:
For detailed remediation, see references/secret-scanning.md.
User password → PBKDF2 → encryption key → encrypt secret → send to server
Server stores only encrypted blobs (cannot decrypt).
Split secret into N shares, require M to reconstruct (e.g., 3 of 5).
# Initialize Vault with Shamir shares
vault operator init -key-shares=5 -key-threshold=3
# Unseal requires 3 of 5 key shares
vault operator unseal <KEY_1>
vault operator unseal <KEY_2>
vault operator unseal <KEY_3>For implementations, see references/zero-knowledge.md.
| Library | Use Case | Trust Score |
|---|---|---|
| HashiCorp Vault | Enterprise, multi-cloud | High (73.3/100) |
| External Secrets Operator | Kubernetes integration | High (85.0/100) |
| AWS Secrets Manager | AWS workloads | High |
| GCP Secret Manager | GCP workloads | High |
| Azure Key Vault | Azure workloads | High |
| Library | Use Case | Trust Score |
|---|---|---|
| Gitleaks | Pre-commit, CI/CD | High (89.9/100) |
| TruffleHog | Git history scanning | Medium |
| Language | Library | Version |
|---|---|---|
| Python | hvac | 2.2.0+ |
| Go | vault/api | Latest |
| TypeScript | node-vault | 0.10.2+ |
| Rust | vaultrs | 0.7+ |
For step-by-step guide, see examples/vault-eso-setup/.
For implementation, see examples/dynamic-db-credentials/.
For setup, see examples/secret-scanning/.
Environment variables visible in process lists. Solution: Use file-based secrets (Kubernetes volumes, CSI driver).
Base64 is not encryption. Solution: Use External Secrets Operator.
Stale credentials increase breach risk. Solution: Use dynamic secrets or automate rotation.
Unlimited permissions. Solution: Use auth methods with least privilege policies.
references/vault-architecture.md - Vault internals, HA setup, policiesreferences/kubernetes-integration.md - ESO, CSI driver, VSO comparisonreferences/rotation-patterns.md - Detailed rotation workflowsreferences/secret-scanning.md - Gitleaks, remediation proceduresreferences/zero-knowledge.md - E2EE, Shamir's secret sharingreferences/cloud-providers.md - AWS, GCP, Azure secret managersexamples/vault-eso-setup/ - Complete Kubernetes setupexamples/dynamic-db-credentials/ - Multi-language examplesexamples/secret-scanning/ - Pre-commit hooks, CI/CDscripts/setup_vault.sh - Automated Vault installation© ancoleman, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 16 other files (scripts, references) in skills/secret-management of ancoleman/ai-design-components.
Open the folder on GitHubat commit 76551b7
Managing Secrets next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Managing Secrets this skillancoleman/ai-design-components | 526 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Hashicorp VaultBagelHole/DevOps-Security-Agent-Skills | 1.1k | — | ~2k | Automated safety check: Pass | MIT | |
| Implementing Secrets Management With Vaultmukul975/Anthropic-Cybersecurity-Skills | 34k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | |
| LangBot Deployment Guidelangbot-app/LangBot | 18k | — | ~1.2k | Automated safety check: Notes | Apache-2.0 | |
| Provider Bug Reviewmondoohq/mql | 411 | — | ~2.9k | Automated safety check: Pass | Custom licence | |
| Kcli Cluster Deploymentkarmab/kcli | 653 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 |
BagelHole/DevOps-Security-Agent-Skills
Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.
mukul975/Anthropic-Cybersecurity-Skills
Deploy HashiCorp Vault for centralized secrets management, covering dynamic secret generation for databases and cloud providers, transit encryption, PKI certificate management, and Kubernetes…
langbot-app/LangBot
Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.
mondoohq/mql
Deep static code review of an mql provider for logic errors, nil-handling bugs, pagination truncation, caching/id collisions, and other defects that silently give users wrong data.
karmab/kcli
Guides deployment and management of Kubernetes clusters with kcli.
pydantic/skills
Monitor hosts, Docker containers, Kubernetes clusters, database/queue/cache servers, and cloud-provider metrics with Pydantic Logfire — no application code required.
ancoleman/ai-design-components
Builds AI chat interfaces and conversational UI with streaming responses, context management, and multi-modal support.
ancoleman/ai-design-components
Builds form components and data collection interfaces including contact forms, registration flows, checkout processes, surveys, and settings pages.
ancoleman/ai-design-components
Builds tables and data grids for displaying tabular information, from simple HTML tables to complex enterprise data grids.
ancoleman/ai-design-components
Creates comprehensive dashboard and analytics interfaces that combine data visualization, KPI cards, real-time updates, and interactive layouts.
ancoleman/ai-design-components
Designs layout systems and responsive interfaces including grid systems, flexbox patterns, sidebar layouts, and responsive breakpoints.
ancoleman/ai-design-components
Displays chronological events and activity through timelines, activity feeds, Gantt charts, and calendar interfaces.
Categories
Managing secrets (API keys, database credentials, certificates) with Vault, cloud providers, and Kubernetes. Managing Secrets is an agent skill from ancoleman/ai-design-components. Managing secrets (API keys, database credentials, certificates) with Vault, cloud providers, and Kubernetes.
Managing Secrets fits situations like: storing sensitive data; rotating credentials; syncing secrets to Kubernetes; implementing dynamic secrets.
Run `npx skills add ancoleman/ai-design-components --skill managing-secrets -a claude-code`. Or copy the skill folder (skills/secret-management in ancoleman/ai-design-components) into .claude/skills/managing-secrets in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ancoleman/ai-design-components --skill managing-secrets -a codex`. Or copy the skill folder (skills/secret-management in ancoleman/ai-design-components) into .agents/skills/managing-secrets in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ancoleman/ai-design-components --skill managing-secrets -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/managing-secrets, .gemini/skills/managing-secrets, .github/skills/managing-secrets and .opencode/skills/managing-secrets in your project.
Going by SKILL.md and its folder, Managing Secrets needs Go, Python and TypeScript for the scripts in its folder and the command-line tools its instructions call (vault, brew and gitleaks). Our summary lists: Python 3; Node.js.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Managing Secrets is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 22k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Managing Secrets: Hashicorp Vault (BagelHole/DevOps-Security-Agent-Skills, 1.1k stars), Implementing Secrets Management With Vault (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), LangBot Deployment Guide (langbot-app/LangBot, 18k stars) and Provider Bug Review (mondoohq/mql, 411 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ancoleman (a GitHub user) maintains it in ancoleman/ai-design-components, which has 526 GitHub stars. The repository holds 75 skills in this directory. The repository was last updated on December 11, 2025.
Source: ancoleman/ai-design-components on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.