Agent skill

Hashicorp Vault

by BagelHole in BagelHole/DevOps-Security-Agent-Skills

Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

MITAuto-check passedDevOps & Cloud

Install Hashicorp Vault

skills CLI
$ npx skills add BagelHole/DevOps-Security-Agent-Skills --skill hashicorp-vault -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install BagelHole/DevOps-Security-Agent-Skills hashicorp-vault --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/BagelHole/DevOps-Security-Agent-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/security/secrets/hashicorp-vault .claude/skills/hashicorp-vault && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
hashicorp-vault
GitHub stars
1.2k
Token cost
~2k tokens
SKILL.md length
168 words
Files
7 (incl. scripts, references, assets)
Skills in repo
44
Repo updated
First seen
Licence
MIT

At a glance

Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

  • Implementing centralized secrets management
  • SKILL.md covers When to Use This Skill, Prerequisites, Quick Start and Secret Engines, plus 6 more sections
  • Runs Shell scripts from its folder; calls vault; reaches kubernetes.default.svc and accounts.google.com; needs VAULT_TOKEN and DB_PASSWORD
  • Dynamic credentials

What it does

Hashicorp Vault is an agent skill from BagelHole/DevOps-Security-Agent-Skills. Manage secrets and PKI with HashiCorp Vault. Configure secret engines, authentication methods, and policies. Use when implementing centralized secrets management, dynamic credentials, or certificate management.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts, reference files and assets (for example `assets/kubernetes-auth.yaml`, `references/secrets-engines.md` and `references/vault-policies.md`).

It sits in DevOps & Cloud, covering Cryptography, Secrets management and Container orchestration. It works with HashiCorp Vault, Kubernetes and Amazon Web Services. The repository describes itself as: Agent-ready DevOps, security, infrastructure, and compliance knowledge base with 80+ skills across Kubernetes, Terraform, AWS/Azure/GCP, AI platform operations, container… The licence is MIT.

When your agent uses it

  • Implementing centralized secrets management
  • Dynamic credentials
  • Certificate management

Example prompts

  • “/hashicorp-vault”

Requirements

  • Python 3
  • A Bash shell
  • A credential in VAULT_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit 0365f57. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • vault

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • kubernetes.default.svc
    • accounts.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • VAULT_TOKEN
    • DB_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Hashicorp Vault loads about 2k tokens when it runs, and up to ~3.3k if it reads all its reference files. Until then it costs about 57 tokens; SKILL.md has 168 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~57
When it runs · the whole SKILL.md, loaded when a task matches
~2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from BagelHole/DevOps-Security-Agent-Skills at commit 0365f57, republished under its MIT licence (© BagelHole). 168 words, ~1,982 tokens.

Download SKILL.mdSave it as .claude/skills/hashicorp-vault/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
hashicorp-vault
description
Manage secrets and PKI with HashiCorp Vault. Configure secret engines, authentication methods, and policies. Use when implementing centralized secrets management, dynamic credentials, or certificate management.
license
MIT
metadata.author
devops-skills
metadata.version
1.0

HashiCorp Vault

Centrally manage secrets, encryption, and access with HashiCorp Vault.

When to Use This Skill

Use this skill when:

  • Centralizing secrets management
  • Implementing dynamic credentials
  • Managing PKI and certificates
  • Encrypting sensitive data
  • Meeting compliance requirements

Prerequisites

  • Vault server (dev or production)
  • Vault CLI installed
  • Network access to Vault

Quick Start

Development Server
bash
# Start dev server
vault server -dev

# Set environment
export VAULT_ADDR='http://127.0.0.1:8200'
export VAULT_TOKEN='root'

# Verify connection
vault status
Production Deployment
hcl
# config.hcl
storage "raft" {
  path = "/opt/vault/data"
  node_id = "vault-1"
}

listener "tcp" {
  address = "0.0.0.0:8200"
  tls_cert_file = "/opt/vault/tls/vault.crt"
  tls_key_file = "/opt/vault/tls/vault.key"
}

api_addr = "https://vault.example.com:8200"
cluster_addr = "https://vault.example.com:8201"

ui = true
bash
# Initialize Vault
vault operator init -key-shares=5 -key-threshold=3

# Unseal (run 3 times with different keys)
vault operator unseal <key-1>
vault operator unseal <key-2>
vault operator unseal <key-3>

# Login
vault login <root-token>

Secret Engines

KV Secrets
bash
# Enable KV v2
vault secrets enable -path=secret kv-v2

# Write secret
vault kv put secret/myapp/config \
  username="admin" \
  password="s3cr3t"

# Read secret
vault kv get secret/myapp/config
vault kv get -field=password secret/myapp/config

# Update secret
vault kv put secret/myapp/config \
  username="admin" \
  password="new-password"

# List secrets
vault kv list secret/

# Delete secret
vault kv delete secret/myapp/config

# Version history
vault kv metadata get secret/myapp/config
Database Secrets
bash
# Enable database engine
vault secrets enable database

# Configure PostgreSQL connection
vault write database/config/postgresql \
  plugin_name=postgresql-database-plugin \
  connection_url="postgresql://{{username}}:{{password}}@localhost:5432/mydb" \
  allowed_roles="readonly,readwrite" \
  username="vault" \
  password="vault-password"

# Create role
vault write database/roles/readonly \
  db_name=postgresql \
  creation_statements="CREATE ROLE \"{{name}}\" WITH LOGIN PASSWORD '{{password}}' VALID UNTIL '{{expiration}}'; \
    GRANT SELECT ON ALL TABLES IN SCHEMA public TO \"{{name}}\";" \
  default_ttl="1h" \
  max_ttl="24h"

# Get credentials
vault read database/creds/readonly
AWS Secrets
bash
# Enable AWS engine
vault secrets enable aws

# Configure root credentials
vault write aws/config/root \
  access_key=AKIA... \
  secret_key=secret... \
  region=us-east-1

# Create role
vault write aws/roles/deploy \
  credential_type=iam_user \
  policy_document=-<<EOF
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": ["s3:*"],
      "Resource": ["arn:aws:s3:::my-bucket/*"]
    }
  ]
}
EOF

# Get credentials
vault read aws/creds/deploy
PKI Secrets
bash
# Enable PKI engine
vault secrets enable pki
vault secrets tune -max-lease-ttl=87600h pki

# Generate root CA
vault write -field=certificate pki/root/generate/internal \
  common_name="example.com" \
  ttl=87600h > ca_cert.crt

# Configure URLs
vault write pki/config/urls \
  issuing_certificates="https://vault.example.com:8200/v1/pki/ca" \
  crl_distribution_points="https://vault.example.com:8200/v1/pki/crl"

# Create role
vault write pki/roles/web-server \
  allowed_domains="example.com" \
  allow_subdomains=true \
  max_ttl="720h"

# Issue certificate
vault write pki/issue/web-server \
  common_name="web.example.com" \
  ttl="24h"

Authentication Methods

AppRole
bash
# Enable AppRole
vault auth enable approle

# Create role
vault write auth/approle/role/myapp \
  token_policies="myapp-policy" \
  token_ttl=1h \
  token_max_ttl=4h \
  secret_id_ttl=10m

# Get role ID
vault read auth/approle/role/myapp/role-id

# Generate secret ID
vault write -f auth/approle/role/myapp/secret-id

# Login
vault write auth/approle/login \
  role_id=<role-id> \
  secret_id=<secret-id>
Kubernetes
bash
# Enable Kubernetes auth
vault auth enable kubernetes

# Configure
vault write auth/kubernetes/config \
  kubernetes_host="https://kubernetes.default.svc" \
  kubernetes_ca_cert=@/var/run/secrets/kubernetes.io/serviceaccount/ca.crt

# Create role
vault write auth/kubernetes/role/myapp \
  bound_service_account_names=myapp \
  bound_service_account_namespaces=default \
  policies=myapp-policy \
  ttl=1h
OIDC
bash
# Enable OIDC auth
vault auth enable oidc

# Configure
vault write auth/oidc/config \
  oidc_discovery_url="https://accounts.google.com" \
  oidc_client_id="your-client-id" \
  oidc_client_secret="your-client-secret" \
  default_role="default"

# Create role
vault write auth/oidc/role/default \
  bound_audiences="your-client-id" \
  allowed_redirect_uris="http://localhost:8250/oidc/callback" \
  user_claim="sub" \
  policies="default"

Policies

Policy Definition
hcl
# myapp-policy.hcl
# Read secrets
path "secret/data/myapp/*" {
  capabilities = ["read", "list"]
}

# Database credentials
path "database/creds/myapp-db" {
  capabilities = ["read"]
}

# PKI certificates
path "pki/issue/web-server" {
  capabilities = ["create", "update"]
}

# Deny access to other secrets
path "secret/data/other/*" {
  capabilities = ["deny"]
}
bash
# Create policy
vault policy write myapp myapp-policy.hcl

# List policies
vault policy list

# Read policy
vault policy read myapp

Application Integration

Python
python
import hvac

# Initialize client
client = hvac.Client(url='http://localhost:8200')

# AppRole authentication
client.auth.approle.login(
    role_id='role-id',
    secret_id='secret-id'
)

# Read secret
secret = client.secrets.kv.v2.read_secret_version(
    path='myapp/config',
    mount_point='secret'
)
password = secret['data']['data']['password']

# Get database credentials
db_creds = client.secrets.database.generate_credentials(
    name='myapp-db'
)
Kubernetes Sidecar
yaml
apiVersion: v1
kind: Pod
metadata:
  name: myapp
  annotations:
    vault.hashicorp.com/agent-inject: "true"
    vault.hashicorp.com/role: "myapp"
    vault.hashicorp.com/agent-inject-secret-config: "secret/data/myapp/config"
    vault.hashicorp.com/agent-inject-template-config: |
      {{- with secret "secret/data/myapp/config" -}}
      export DB_PASSWORD="{{ .Data.data.password }}"
      {{- end }}
spec:
  serviceAccountName: myapp
  containers:
    - name: myapp
      image: myapp:latest
      command: ["/bin/sh", "-c", "source /vault/secrets/config && ./start.sh"]

Common Issues

Issue: Sealed Vault

Problem: Vault is sealed after restart Solution: Implement auto-unseal with cloud KMS or HSM

Issue: Token Expired

Problem: Application token has expired Solution: Implement token renewal, use shorter-lived tokens

Issue: Permission Denied

Problem: Cannot access secrets Solution: Review policies, check token capabilities

Best Practices

  • Use short-lived tokens
  • Implement auto-unseal
  • Enable audit logging
  • Use namespaces for isolation
  • Rotate root tokens regularly
  • Implement least-privilege policies
  • Use dynamic secrets where possible
  • Regular backup and DR testing

© BagelHole, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references, assets) in security/secrets/hashicorp-vault of BagelHole/DevOps-Security-Agent-Skills.

  • SKILL.md
  • assets/kubernetes-auth.yaml
  • assets/vault-config.hcl
  • references/secrets-engines.md
  • references/vault-policies.md
  • scripts/vault-backup.sh
  • scripts/vault-init.sh

Open the folder on GitHubat commit 0365f57

Compare with similar skills

Hashicorp Vault next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Hashicorp Vault compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Hashicorp Vault this skillBagelHole/DevOps-Security-Agent-Skills1.2k—~2kAutomated safety check: PassMIT
Implementing Secrets Management With Vaultmukul975/Anthropic-Cybersecurity-Skills34k—~3.2kAutomated safety check: PassApache-2.0
Managing Secretsancoleman/ai-design-components525—~2.9kAutomated safety check: PassMIT
LangBot Deployment Guidelangbot-app/LangBot18k—~1.5kAutomated safety check: NotesApache-2.0
Provider Bug Reviewmondoohq/mql412—~2.9kAutomated safety check: PassCustom licence
Kcli Cluster Deploymentkarmab/kcli653—~1.5kAutomated safety check: PassApache-2.0

Similar skills

  • Implementing Secrets Management With Vault

    mukul975/Anthropic-Cybersecurity-Skills

    Deploy HashiCorp Vault for centralized secrets management, covering dynamic secret generation for databases and cloud providers, transit encryption, PKI certificate management, and Kubernetes…

    34k GitHub stars~3.2k tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Managing Secrets

    ancoleman/ai-design-components

    Managing secrets (API keys, database credentials, certificates) with Vault, cloud providers, and Kubernetes.

    525 GitHub stars~2.9k tokensUpdated 10 mo ago
    DevOps & CloudAuto-check passed
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Deep static code review of an mql provider for logic errors, nil-handling bugs, pagination truncation, caching/id collisions, and other defects that silently give users wrong data.

    412 GitHub stars~2.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Guides deployment and management of Kubernetes clusters with kcli.

    653 GitHub stars~1.5k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Logfire Infrastructure

    pydantic/skills

    Official

    Monitor hosts, Docker containers, Kubernetes clusters, database/queue/cache servers, and cloud-provider metrics with Pydantic Logfire — no application code required.

    140 GitHub stars~1.8k tokensUpdated 10 days ago
    DevOps & CloudAuto-check passed

More from BagelHole/DevOps-Security-Agent-Skills

All 44 skills in this repo
  • Incident Response

    BagelHole/DevOps-Security-Agent-Skills

    Handle security incidents with IR playbooks and procedures. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.2k GitHub stars~4.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Kubernetes Ops

    BagelHole/DevOps-Security-Agent-Skills

    Deploy, scale, and manage Kubernetes workloads. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.2k GitHub stars~2.3k tokensUpdated 4 mo ago
    Auto-check passed
  • Linux Hardening

    BagelHole/DevOps-Security-Agent-Skills

    Apply CIS benchmarks and secure Linux servers. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.2k GitHub stars~662 tokensUpdated 4 mo ago
    Auto-check: notes
  • Prometheus Grafana

    BagelHole/DevOps-Security-Agent-Skills

    Set up metrics collection and visualization with Prometheus and Grafana.

    1.2k GitHub stars~2.5k tokensUpdated 4 mo ago
    Auto-check passed
  • Vulnerability Scanning

    BagelHole/DevOps-Security-Agent-Skills

    Scan systems and dependencies for CVEs and security vulnerabilities.

    1.2k GitHub stars~2.4k tokensUpdated 4 mo ago
    Auto-check passed
  • Argocd Gitops

    BagelHole/DevOps-Security-Agent-Skills

    Implement GitOps with ArgoCD for declarative Kubernetes deployments.

    1.2k GitHub stars~2.4k tokensUpdated 4 mo ago
    Auto-check passed

Categories

Questions about Hashicorp Vault

What does Hashicorp Vault do?

Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills. Hashicorp Vault is an agent skill from BagelHole/DevOps-Security-Agent-Skills. Manage secrets and PKI with HashiCorp Vault.

When should I use Hashicorp Vault?

Hashicorp Vault fits situations like: implementing centralized secrets management; dynamic credentials; certificate management.

How do I install Hashicorp Vault in Claude Code?

Run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill hashicorp-vault -a claude-code`. Or copy the skill folder (security/secrets/hashicorp-vault in BagelHole/DevOps-Security-Agent-Skills) into .claude/skills/hashicorp-vault in your project. Claude Code loads it when a task matches its description.

How do I install Hashicorp Vault in Codex?

Run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill hashicorp-vault -a codex`. Or copy the skill folder (security/secrets/hashicorp-vault in BagelHole/DevOps-Security-Agent-Skills) into .agents/skills/hashicorp-vault in your project. Codex loads it when a task matches its description.

Can I use Hashicorp Vault in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add BagelHole/DevOps-Security-Agent-Skills --skill hashicorp-vault -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/hashicorp-vault, .gemini/skills/hashicorp-vault, .github/skills/hashicorp-vault and .opencode/skills/hashicorp-vault in your project.

What does Hashicorp Vault need to run?

Going by SKILL.md and its folder, Hashicorp Vault needs a shell for the scripts in its folder, the command-line tools its instructions call (vault) and credentials named VAULT_TOKEN and DB_PASSWORD. Our summary lists: Python 3; A Bash shell; A credential in VAULT_TOKEN.

Does Hashicorp Vault access the network?

SKILL.md names 2 domains. In commands or code: kubernetes.default.svc and accounts.google.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Hashicorp Vault safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Hashicorp Vault use?

Hashicorp Vault is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Hashicorp Vault use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.3k tokens, read only when the agent opens those files.

What are the alternatives to Hashicorp Vault?

Skills that share tags, products or a category with Hashicorp Vault: Implementing Secrets Management With Vault (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Managing Secrets (ancoleman/ai-design-components, 525 stars), LangBot Deployment Guide (langbot-app/LangBot, 18k stars) and Provider Bug Review (mondoohq/mql, 412 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Hashicorp Vault?

BagelHole (a GitHub user) maintains it in BagelHole/DevOps-Security-Agent-Skills, which has 1,152 GitHub stars. The repository holds 44 skills in this directory. The repository was last updated on May 22, 2026.

Source: BagelHole/DevOps-Security-Agent-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.