Agent skill

Exposed Secret Rotation

by avelikiy in avelikiy/great_cto

Turns a leaked key, token or password into one tracked rotation task the moment it's spotted, instead of a reminder repeated every session.

MITAuto-check: notesSecurity

Install Exposed Secret Rotation

skills CLI
$ npx skills add avelikiy/great_cto --skill secrets-rotation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install avelikiy/great_cto secrets-rotation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/avelikiy/great_cto.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/secrets-rotation .claude/skills/secrets-rotation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secrets-rotation
GitHub stars
102
Token cost
~884 tokens
SKILL.md length
383 words
Files
1
Skills in repo
27
Repo updated
First seen
Licence
MIT

At a glance

Turns a leaked key, token or password into one tracked rotation task the moment it's spotted, instead of a reminder repeated every session.

  • Works in 4 steps: Never repeat the value. Not in your… → Say it plainly, first line: this key is… → Open one task, not a note — in Beads if… → …
  • Spotting an API key, password or token pasted into chat or a log
  • SKILL.md covers The moment you see one, Done means the old value is… and Carrying it forward
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

The premise is that an exposed secret is already compromised: deleting the message, rewriting git history or redacting a log doesn't undo the exposure, since the transcript, remote, backup and the provider's own logs already hold it, so only revoking it and issuing a new value actually fixes it. The skill exists because real projects kept rewriting the same reminder across many session logs instead of someone owning the rotation itself.

On sighting a secret, the value is never repeated, only its kind and where it was seen; one tracked task is opened rather than a note, with top priority for a production credential or anything that moves money, and the agent rotates it directly when it owns that system or hands the operator the exact click needed otherwise. A rotation only counts as done once the new value lives in the real secret store, every consumer has redeployed onto it, and a call made with the old value is actually rejected; a task still open after 48 hours is resurfaced at the top of the next report rather than quietly re-logged as new.

When your agent uses it

  • Spotting an API key, password or token pasted into chat or a log
  • Finding a secret committed to a repository by mistake
  • Following up on a rotation task that's been open for a while

Example prompts

  • “I just saw an API key pasted in the chat, handle the rotation.”
  • “We committed a .env file with a database password, what now?”
  • “Check whether that monitoring token rotation from last week ever closed.”

Requirements

  • Pre-approved tools (allowed-tools): Read, Bash, Grep

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Never repeat the value. Not in your answer, not in a task title, not in a log, not
  2. Say it plainly, first line: this key is compromised; revoking it is the only fix.
  3. Open one task, not a note — in Beads if the project has it
  4. If you can rotate it, rotate it — the operator asked you to handle it, or your

What it can do on your machine

Read from SKILL.md and the folder at commit 97dd037. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Exposed Secret Rotation loads about 884 tokens when it runs. Until then it costs about 118 tokens; SKILL.md has 383 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~118
When it runs · the whole SKILL.md, loaded when a task matches
~884

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:3
    юч в чате", "токен в логах", "закоммитил .env"). Loaded by security-officer, l3-support, devops.
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Bash, Grep

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from avelikiy/great_cto at commit 97dd037, republished under its MIT licence (© avelikiy). 383 words, ~884 tokens.

Download SKILL.mdSave it as .claude/skills/secrets-rotation/SKILL.md (or your agent's skills folder).
name
secrets-rotation
description
What to do the moment a secret is exposed — pasted into chat, committed, logged, shown in a transcript or a screenshot. The secret is compromised; only revoking and rotating it helps. Turns it into one tracked task with an escalation, not a reminder repeated every session. Use when you see a key, token, password or private key anywhere it should not be ("ключ в чате", "токен в логах", "закоммитил .env"). Loaded by security-officer, l3-support, devops.
allowed-tools
Read, Bash, Grep
when_to_use
Apply when: - a key, token, password or private key appears in a message, a commit, a log, a transcript, a screenshot or a context file - the operator pastes…
effort
low

secrets-rotation — an exposed secret is spent

Deleting the message, rewriting git history or redacting the log does not un-expose a secret: the transcript, the remote, the backup and the provider's own logs already hold it. The only fix is to make the exposed value worthless — revoke it and issue a new one.

What went wrong on real projects is not ignorance of that. It is that the rotation was remembered instead of tracked: "rotate the exchange API keys" was carried forward through seven session logs; "keys that passed through chat" appeared in seven summaries of another project; a monitoring token pasted in plain text was never rotated. Each session wrote the reminder again and nobody owned it.

The moment you see one

  1. Never repeat the value. Not in your answer, not in a task title, not in a log, not in a commit message. Name its kind and where it is: "OpenRouter API key, in the operator's message of 22.09, 14:10". scripts/lib/secret-patterns.mjs names the kind.

  2. Say it plainly, first line: this key is compromised; revoking it is the only fix.

  3. Open one task, not a note — in Beads if the project has it:

    bash
    bd create "Rotate <kind> exposed in <where> on <date>" -t bug -p 0 \
      -d "Exposed: <where>. Revoke at <provider console>, issue new, store in <secret store>, redeploy <consumers>, prove the old one is rejected."

    Priority 0 for a production credential or anything that moves money; 1 otherwise.

  4. If you can rotate it, rotate it — the operator asked you to handle it, or your task covers that system. If it needs the operator (a provider console you cannot reach, a hardware token), the task's first line says exactly what they must click.

Show full SKILL.md (129 more words)Show less

Done means the old value is refused

A rotation is closed with evidence, not with "rotated":

  • the new value is in the secret store the code reads — never in CLAUDE.md, preferences.md, memory files, a README or any file that is loaded into a model's context (one key in a preferences file reached 605 transcripts);
  • every consumer was redeployed and uses it (deploy-landed, config check);
  • a call with the old value fails — 401/403 from the provider. That is the proof.

Carrying it forward

An open rotation task older than 48 hours goes to the top of the next session's report and of /inbox, with its age. Do not re-list it in the session log as a fresh item — link the task. Re-writing a reminder is how the seven-session carry-over happened.

© avelikiy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/secrets-rotation of avelikiy/great_cto.

Open the folder on GitHubat commit 97dd037

Compare with similar skills

Exposed Secret Rotation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Exposed Secret Rotation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Exposed Secret Rotation this skillavelikiy/great_cto102—~884Automated safety check: NotesMIT
Security Setupluongnv89/skills131—~4.5kAutomated safety check: PassMIT
Azure Security Keyvault Secrets Javamicrosoft/skills3.1k5 repos~3.1kAutomated safety check: PassMIT
Azure Compliancemicrosoft/GitHub-Copilot-for-Azure2552 repos~997Automated safety check: PassMIT
JS Security Auditc0x12c/ai-toolkit106—~1.6kAutomated safety check: WarnNone
Security SecretsIgorWarzocha/Opencode-Workflows122—~1.2kAutomated safety check: NotesNone

Similar skills

  • Security Setup

    luongnv89/skills

    Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.

    131 GitHub stars~4.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Official

    Azure Key Vault Secrets Java SDK for secret management. An agent skill from microsoft/skills.

    3.1k GitHub starsUsed in 5 repos~3.1k tokens
    SecurityAuto-check passed
  • Azure Compliance

    microsoft/GitHub-Copilot-for-Azure

    Official

    Run Azure compliance and security audits with azqr plus Key Vault expiration checks.

    255 GitHub starsUsed in 2 repos~997 tokens
    SecurityAuto-check passed
  • JS Security Audit

    c0x12c/ai-toolkit

    Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response.

    106 GitHub stars~1.6k tokensUpdated 3 mo ago
    SecurityAuto-check: warnings
  • Security Secrets

    IgorWarzocha/Opencode-Workflows

    Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows.

    122 GitHub stars~1.2k tokensUpdated 8 mo ago
    SecurityAuto-check: notes
  • Network Security Setup

    Microck/ordinary-claude-skills

    Configure Claude Code sandbox network isolation with trusted domains, custom access policies, and environment variables

    404 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check: notes

More from avelikiy/great_cto

All 27 skills in this repo
  • AnyDesign Design Analyzer

    avelikiy/great_cto

    Analyzes a screenshot, website or Figma file and writes a `design.md` with its token system, component inventory and reconstruction notes, or an `element.md` for one element.

    102 GitHub starsUsed in 1 repo~3.2k tokens
    Auto-check passed
  • Opportunity Solution Tree

    avelikiy/great_cto

    Builds an Opportunity Solution Tree that links one measurable outcome to customer opportunities, candidate solutions and experiments.

    102 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check passed
  • Rewrites a feature-list roadmap into outcome statements that name the customer segment, the result they get and the business impact, grouped into themes.

    102 GitHub stars~1.3k tokensUpdated yesterday
    Auto-check passed
  • Skeptical Triage

    avelikiy/great_cto

    Runs a three-round self-challenge plus an arbiter over high-stakes findings, so false positives from reviews, audits and flaky-test verdicts do not become blockers.

    102 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check: notes
  • Aesthetic Instrument

    avelikiy/great_cto

    greatcto's own committed aesthetic — the instrument panel. An agent skill from avelikiy/great_cto.

    102 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Anti Patterns

    avelikiy/great_cto

    Catalogue of known SDLC anti-patterns that greatcto agents must actively reject when reviewing architecture, plans, code, or post-mortems.

    102 GitHub stars~1.7k tokensUpdated yesterday
    Auto-check passed

Questions about Exposed Secret Rotation

What does Exposed Secret Rotation do?

Turns a leaked key, token or password into one tracked rotation task the moment it's spotted, instead of a reminder repeated every session. The premise is that an exposed secret is already compromised: deleting the message, rewriting git history or redacting a log doesn't undo the exposure, since the transcript, remote, backup and the provider's own logs already hold it, so only revoking it and issuing a new value actually fixes it. The skill exists because real projects kept rewriting the same reminder across many session logs instead of someone owning the rotation itself.

When should I use Exposed Secret Rotation?

Exposed Secret Rotation fits situations like: spotting an API key, password or token pasted into chat or a log; finding a secret committed to a repository by mistake; following up on a rotation task that's been open for a while.

How do I install Exposed Secret Rotation in Claude Code?

Run `npx skills add avelikiy/great_cto --skill secrets-rotation -a claude-code`. Or copy the skill folder (skills/secrets-rotation in avelikiy/great_cto) into .claude/skills/secrets-rotation in your project. Claude Code loads it when a task matches its description.

How do I install Exposed Secret Rotation in Codex?

Run `npx skills add avelikiy/great_cto --skill secrets-rotation -a codex`. Or copy the skill folder (skills/secrets-rotation in avelikiy/great_cto) into .agents/skills/secrets-rotation in your project. Codex loads it when a task matches its description.

Can I use Exposed Secret Rotation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add avelikiy/great_cto --skill secrets-rotation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secrets-rotation, .gemini/skills/secrets-rotation, .github/skills/secrets-rotation and .opencode/skills/secrets-rotation in your project.

What does Exposed Secret Rotation need to run?

SKILL.md names no scripts, command-line tools or credentials: Exposed Secret Rotation is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Bash, Grep.

Does Exposed Secret Rotation access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Exposed Secret Rotation safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Exposed Secret Rotation use?

Exposed Secret Rotation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Exposed Secret Rotation use?

About 884 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Exposed Secret Rotation?

Skills that share tags, products or a category with Exposed Secret Rotation: Security Setup (luongnv89/skills, 131 stars), Azure Security Keyvault Secrets Java (microsoft/skills, 3.1k stars), Azure Compliance (microsoft/GitHub-Copilot-for-Azure, 255 stars) and JS Security Audit (c0x12c/ai-toolkit, 106 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Exposed Secret Rotation?

avelikiy (a GitHub user) maintains it in avelikiy/great_cto, which has 102 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 9, 2026.

Source: avelikiy/great_cto on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.