Security Setup
luongnv89/skills
Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.
Turns a leaked key, token or password into one tracked rotation task the moment it's spotted, instead of a reminder repeated every session.
$ npx skills add avelikiy/great_cto --skill secrets-rotation -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install avelikiy/great_cto secrets-rotation --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/avelikiy/great_cto.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/secrets-rotation .claude/skills/secrets-rotation && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "secrets-rotation" agent skill from https://github.com/avelikiy/great_cto/tree/main/skills/secrets-rotation into .claude/skills/secrets-rotation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-rotation", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/avelikiy/great_cto/tree/main/skills/secrets-rotationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add avelikiy/great_cto --skill secrets-rotation -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install avelikiy/great_cto secrets-rotation --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/avelikiy/great_cto.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/secrets-rotation .agents/skills/secrets-rotation && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "secrets-rotation" agent skill from https://github.com/avelikiy/great_cto/tree/main/skills/secrets-rotation into .agents/skills/secrets-rotation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-rotation", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add avelikiy/great_cto --skill secrets-rotation -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install avelikiy/great_cto secrets-rotation --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/avelikiy/great_cto.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/secrets-rotation .cursor/skills/secrets-rotation && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "secrets-rotation" agent skill from https://github.com/avelikiy/great_cto/tree/main/skills/secrets-rotation into .cursor/skills/secrets-rotation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-rotation", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/avelikiy/great_cto.git --path skills/secrets-rotation--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add avelikiy/great_cto --skill secrets-rotation -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install avelikiy/great_cto secrets-rotation --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/avelikiy/great_cto.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/secrets-rotation .gemini/skills/secrets-rotation && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "secrets-rotation" agent skill from https://github.com/avelikiy/great_cto/tree/main/skills/secrets-rotation into .gemini/skills/secrets-rotation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-rotation", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install avelikiy/great_cto secrets-rotationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add avelikiy/great_cto --skill secrets-rotation -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/avelikiy/great_cto.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/secrets-rotation .github/skills/secrets-rotation && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "secrets-rotation" agent skill from https://github.com/avelikiy/great_cto/tree/main/skills/secrets-rotation into .github/skills/secrets-rotation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-rotation", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add avelikiy/great_cto --skill secrets-rotation -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install avelikiy/great_cto secrets-rotation --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/avelikiy/great_cto.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/secrets-rotation .opencode/skills/secrets-rotation && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "secrets-rotation" agent skill from https://github.com/avelikiy/great_cto/tree/main/skills/secrets-rotation into .opencode/skills/secrets-rotation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-rotation", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
secrets-rotationTurns a leaked key, token or password into one tracked rotation task the moment it's spotted, instead of a reminder repeated every session.
The premise is that an exposed secret is already compromised: deleting the message, rewriting git history or redacting a log doesn't undo the exposure, since the transcript, remote, backup and the provider's own logs already hold it, so only revoking it and issuing a new value actually fixes it. The skill exists because real projects kept rewriting the same reminder across many session logs instead of someone owning the rotation itself.
On sighting a secret, the value is never repeated, only its kind and where it was seen; one tracked task is opened rather than a note, with top priority for a production credential or anything that moves money, and the agent rotates it directly when it owns that system or hands the operator the exact click needed otherwise. A rotation only counts as done once the new value lives in the real secret store, every consumer has redeployed onto it, and a call made with the old value is actually rejected; a task still open after 48 hours is resurfaced at the top of the next report rather than quietly re-logged as new.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 97dd037. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
ReadBashGrepFrom allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Exposed Secret Rotation loads about 884 tokens when it runs. Until then it costs about 118 tokens; SKILL.md has 383 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
юч в чате", "токен в логах", "закоммитил .env"). Loaded by security-officer, l3-support, devops.allowed-tools: Read, Bash, GrepAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from avelikiy/great_cto at commit 97dd037, republished under its MIT licence (© avelikiy). 383 words, ~884 tokens.
.claude/skills/secrets-rotation/SKILL.md (or your agent's skills folder).Deleting the message, rewriting git history or redacting the log does not un-expose a secret: the transcript, the remote, the backup and the provider's own logs already hold it. The only fix is to make the exposed value worthless — revoke it and issue a new one.
What went wrong on real projects is not ignorance of that. It is that the rotation was remembered instead of tracked: "rotate the exchange API keys" was carried forward through seven session logs; "keys that passed through chat" appeared in seven summaries of another project; a monitoring token pasted in plain text was never rotated. Each session wrote the reminder again and nobody owned it.
Never repeat the value. Not in your answer, not in a task title, not in a log, not
in a commit message. Name its kind and where it is: "OpenRouter API key, in the
operator's message of 22.09, 14:10". scripts/lib/secret-patterns.mjs names the kind.
Say it plainly, first line: this key is compromised; revoking it is the only fix.
Open one task, not a note — in Beads if the project has it:
bd create "Rotate <kind> exposed in <where> on <date>" -t bug -p 0 \
-d "Exposed: <where>. Revoke at <provider console>, issue new, store in <secret store>, redeploy <consumers>, prove the old one is rejected."Priority 0 for a production credential or anything that moves money; 1 otherwise.
If you can rotate it, rotate it — the operator asked you to handle it, or your task covers that system. If it needs the operator (a provider console you cannot reach, a hardware token), the task's first line says exactly what they must click.
A rotation is closed with evidence, not with "rotated":
CLAUDE.md,
preferences.md, memory files, a README or any file that is loaded into a model's
context (one key in a preferences file reached 605 transcripts);deploy-landed, config check);An open rotation task older than 48 hours goes to the top of the next session's report
and of /inbox, with its age. Do not re-list it in the session log as a fresh item —
link the task. Re-writing a reminder is how the seven-session carry-over happened.
© avelikiy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/secrets-rotation of avelikiy/great_cto.
Open the folder on GitHubat commit 97dd037
Exposed Secret Rotation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Exposed Secret Rotation this skillavelikiy/great_cto | 102 | — | ~884 | Automated safety check: Notes | MIT | |
| Security Setupluongnv89/skills | 131 | — | ~4.5k | Automated safety check: Pass | MIT | |
| Azure Security Keyvault Secrets Javamicrosoft/skills | 3.1k | 5 repos | ~3.1k | Automated safety check: Pass | MIT | |
| Azure Compliancemicrosoft/GitHub-Copilot-for-Azure | 255 | 2 repos | ~997 | Automated safety check: Pass | MIT | |
| JS Security Auditc0x12c/ai-toolkit | 106 | — | ~1.6k | Automated safety check: Warn | None | |
| Security SecretsIgorWarzocha/Opencode-Workflows | 122 | — | ~1.2k | Automated safety check: Notes | None |
luongnv89/skills
Install local-first security hardening: pre-commit secret detection, offline dependency scans, static analysis, reports, and gated free CI.
microsoft/skills
Azure Key Vault Secrets Java SDK for secret management. An agent skill from microsoft/skills.
microsoft/GitHub-Copilot-for-Azure
Run Azure compliance and security audits with azqr plus Key Vault expiration checks.
c0x12c/ai-toolkit
Audit JS/TS projects against NPM Security Guidelines covering project setup, dependency hygiene, CI/CD pipeline, Dependabot, and incident response.
IgorWarzocha/Opencode-Workflows
Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows.
Microck/ordinary-claude-skills
Configure Claude Code sandbox network isolation with trusted domains, custom access policies, and environment variables
avelikiy/great_cto
Analyzes a screenshot, website or Figma file and writes a `design.md` with its token system, component inventory and reconstruction notes, or an `element.md` for one element.
avelikiy/great_cto
Builds an Opportunity Solution Tree that links one measurable outcome to customer opportunities, candidate solutions and experiments.
avelikiy/great_cto
Rewrites a feature-list roadmap into outcome statements that name the customer segment, the result they get and the business impact, grouped into themes.
avelikiy/great_cto
Runs a three-round self-challenge plus an arbiter over high-stakes findings, so false positives from reviews, audits and flaky-test verdicts do not become blockers.
avelikiy/great_cto
greatcto's own committed aesthetic — the instrument panel. An agent skill from avelikiy/great_cto.
avelikiy/great_cto
Catalogue of known SDLC anti-patterns that greatcto agents must actively reject when reviewing architecture, plans, code, or post-mortems.
Categories
Turns a leaked key, token or password into one tracked rotation task the moment it's spotted, instead of a reminder repeated every session. The premise is that an exposed secret is already compromised: deleting the message, rewriting git history or redacting a log doesn't undo the exposure, since the transcript, remote, backup and the provider's own logs already hold it, so only revoking it and issuing a new value actually fixes it. The skill exists because real projects kept rewriting the same reminder across many session logs instead of someone owning the rotation itself.
Exposed Secret Rotation fits situations like: spotting an API key, password or token pasted into chat or a log; finding a secret committed to a repository by mistake; following up on a rotation task that's been open for a while.
Run `npx skills add avelikiy/great_cto --skill secrets-rotation -a claude-code`. Or copy the skill folder (skills/secrets-rotation in avelikiy/great_cto) into .claude/skills/secrets-rotation in your project. Claude Code loads it when a task matches its description.
Run `npx skills add avelikiy/great_cto --skill secrets-rotation -a codex`. Or copy the skill folder (skills/secrets-rotation in avelikiy/great_cto) into .agents/skills/secrets-rotation in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add avelikiy/great_cto --skill secrets-rotation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secrets-rotation, .gemini/skills/secrets-rotation, .github/skills/secrets-rotation and .opencode/skills/secrets-rotation in your project.
SKILL.md names no scripts, command-line tools or credentials: Exposed Secret Rotation is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Bash, Grep.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Exposed Secret Rotation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 884 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Exposed Secret Rotation: Security Setup (luongnv89/skills, 131 stars), Azure Security Keyvault Secrets Java (microsoft/skills, 3.1k stars), Azure Compliance (microsoft/GitHub-Copilot-for-Azure, 255 stars) and JS Security Audit (c0x12c/ai-toolkit, 106 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
avelikiy (a GitHub user) maintains it in avelikiy/great_cto, which has 102 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 9, 2026.
Source: avelikiy/great_cto on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.