Hashicorp Vault
BagelHole/DevOps-Security-Agent-Skills
Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.
Find leaked secrets in source code, Git history, build artifacts, and infrastructure — and audit the secrets-management posture preventing future leaks.
$ npx skills add briiirussell/cybersecurity-skills --skill secrets-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install briiirussell/cybersecurity-skills secrets-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/secrets-audit .claude/skills/secrets-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "secrets-audit" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/secrets-audit into .claude/skills/secrets-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/secrets-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add briiirussell/cybersecurity-skills --skill secrets-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install briiirussell/cybersecurity-skills secrets-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/secrets-audit .agents/skills/secrets-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "secrets-audit" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/secrets-audit into .agents/skills/secrets-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add briiirussell/cybersecurity-skills --skill secrets-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install briiirussell/cybersecurity-skills secrets-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/secrets-audit .cursor/skills/secrets-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "secrets-audit" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/secrets-audit into .cursor/skills/secrets-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/briiirussell/cybersecurity-skills.git --path skills/secrets-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add briiirussell/cybersecurity-skills --skill secrets-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install briiirussell/cybersecurity-skills secrets-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/secrets-audit .gemini/skills/secrets-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "secrets-audit" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/secrets-audit into .gemini/skills/secrets-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install briiirussell/cybersecurity-skills secrets-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add briiirussell/cybersecurity-skills --skill secrets-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/secrets-audit .github/skills/secrets-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "secrets-audit" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/secrets-audit into .github/skills/secrets-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add briiirussell/cybersecurity-skills --skill secrets-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install briiirussell/cybersecurity-skills secrets-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/secrets-audit .opencode/skills/secrets-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "secrets-audit" agent skill from https://github.com/briiirussell/cybersecurity-skills/tree/main/skills/secrets-audit into .opencode/skills/secrets-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
secrets-auditFind leaked secrets in source code, Git history, build artifacts, and infrastructure — and audit the secrets-management posture preventing future leaks.
Secrets Audit is an agent skill from briiirussell/cybersecurity-skills. Find leaked secrets in source code, Git history, build artifacts, and infrastructure — and audit the secrets-management posture preventing future leaks. Use when the user mentions 'secrets audit,' 'secret scanning,' 'leaked credentials,' 'API key in code,' 'gitleaks,' 'trufflehog,' 'git history scan,' 'secrets management,' 'vault audit,' 'rotation policy,' 'AWS Secrets Manager,' 'HashiCorp Vault,' 'Doppler,' '1Password Secrets Automation,' 'sealed-secrets,' 'External Secrets Operator,' or needs to find or prevent…
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Secrets management. It works with Amazon Web Services, HashiCorp Vault and Git. The repository describes itself as: Cybersecurity skills for AI coding agents (Claude Code, Cursor, Codex). The licence is MIT.
7 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit c9ade03. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadWriteGrepGlobWebSearchFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitgitleaksdockerawsstripecurlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, docker, aws and curl, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
AWS_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Secrets Audit loads about 2.6k tokens when it runs. Until then it costs about 138 tokens; SKILL.md has 1,063 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
Secrets leak in places that aren't `.env` files:- **Public S3 / blob storage** — `.env` accidentally uploaded| ⚠️ | `.env` file in repo (even with .gitignore — easy to leak via push, backup, archive) | Bootstrap only; flagged in- **No `.env` committed** — `.gitignore` covers `.env*` (with care for `.env.example`)- **`.env.local` shipped to staging** — environment-specific dev secrets cross the boundaryallowed-tools: Bash, Read, Write, Grep, Glob, WebSearchAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from briiirussell/cybersecurity-skills at commit c9ade03, republished under its MIT licence (© briiirussell). 1,063 words, ~2,594 tokens.
.claude/skills/secrets-audit/SKILL.md (or your agent's skills folder).Two halves: (1) find secrets that have already leaked into source, history, or artifacts, and (2) audit the secrets-management posture that determines whether future leaks happen.
Most secret leaks aren't "we forgot to redact" — they're "we never had a system, so every developer made up their own approach." This skill covers both the cleanup and the prevention.
Cross-references: dependency-audit (CI-related secrets risk in build-time exposure), iam-audit (workload identity federation as the alternative to long-lived keys), owasp-audit A02 (in-source secret patterns).
The most useful first sweep is grep against known provider key prefixes. False positives are low and matches are almost always real.
# Stripe
grep -rE "(sk_live_|sk_test_|rk_live_|whsec_)[A-Za-z0-9]{20,}" . \
--include="*.{js,ts,jsx,tsx,py,rb,go,java,php,sh,env,yml,yaml,json}"
# AWS access keys
grep -rE "(AKIA|ASIA)[A-Z0-9]{16}" .
# AWS secret keys (40 chars, base64-y) — high FP rate, use with caution
grep -rE "[A-Za-z0-9/+=]{40}" . --include="*.env*" --include="*.json"
# GitHub
grep -rE "gh[pousr]_[A-Za-z0-9]{36}" .
# Google Cloud API key + service-account JSON
grep -rE "AIza[A-Za-z0-9_-]{35}" .
grep -rln '"type": "service_account"' . --include="*.json"
# Slack
grep -rE "xox[baprs]-[A-Za-z0-9-]+" .
# OpenAI / Anthropic
grep -rE "sk-[A-Za-z0-9]{32,}" .
grep -rE "sk-ant-[A-Za-z0-9_-]{90,}" .
# Generic high-entropy strings in env files
grep -rE "^[A-Z_]+=[A-Za-z0-9/+=]{32,}$" . --include="*.env*"For full repo coverage, use git ls-files to scope to tracked files and avoid node_modules:
git ls-files | xargs grep -lE 'sk_live_|ghp_|AKIA[A-Z0-9]{16}|sk-ant-|AIza[A-Za-z0-9_-]{35}' 2>/dev/null| Tool | Use |
|---|---|
gitleaks detect | Fast, low FP, run as pre-commit and in CI; supports custom rules |
trufflehog git file://. | Verifies findings against the real API (high confidence) |
detect-secrets scan | Yelp's tool; good baseline file workflow |
| GitHub Secret Scanning | Free for public repos; covers most providers automatically; pushes get blocked at push time when enabled with push protection |
| GitLab Secret Detection | Similar, built-in to CI |
| GitGuardian / Doppler / Spectral | Commercial; add organizational dashboards and historical analysis |
A secret deleted in the latest commit is still in history — git log -p, git log -S<secret>, and any fork or local clone all have it.
# Search every commit for a pattern
git log -p -S "sk_live_" --all
# Search only deleted lines
git log -p --all | grep -E "^-.*sk_live_"
# Trufflehog historical scan
trufflehog git file://. --since-commit=<first-commit>
# Git history rewrite — destructive, coordinate first
git filter-repo --invert-paths --path config/secrets.yml
# or
bfg --delete-files secrets.ymlCritical caveat: rewriting history requires every developer to re-clone, every fork is still exposed, and the secret should be considered compromised regardless. Always rotate first, history-rewrite second.
Secrets leak in places that aren't .env files:
docker history <image> shows every ENV line; --build-arg SECRET=... ends up in layersset -x, console.log(process.env), error stack traces, debug outputNEXT_PUBLIC_* / VITE_* / REACT_APP_* env vars are shipped to the browser; grep the bundled JSprocess.env snapshotspg_dump of a table that includes user-stored API keys.env accidentally uploadedWhen you find a leaked secret:
aws sts get-caller-identity, stripe balance retrieve, curl -H "Authorization: Bearer $TOKEN" ...) — don't assume; some leaked keys are already revoked or were sandbox-onlyrepo vs admin:org| Tier | Pattern | When acceptable |
|---|---|---|
| ❌ | Hardcoded in source | Never |
| ❌ | Hardcoded in image / build artifact | Never |
| ❌ | Plaintext in shared docs / Slack | Never |
| ⚠️ | .env file in repo (even with .gitignore — easy to leak via push, backup, archive) | Bootstrap only; flagged in audit |
| ⚠️ | Environment variables (only) | Acceptable for ephemeral dev; weak for prod (visible in /proc, crash dumps, logs) |
| 🟢 | Secrets manager pulled at deploy time | Standard for most apps |
| 🟢 | Workload identity federation (no stored secret at all) | Best where supported |
.env committed — .gitignore covers .env* (with care for .env.example)iam-audit).env.local shipped to staging — environment-specific dev secrets cross the boundarypull_request_target and secret accessibility--build-arg AWS_SECRET=... ends up in image history (use --secret/BuildKit instead)process.env on unhandled exception — Sentry / Datadog / Bugsnag scrub config requiredcontainer-audit)# Secrets Audit Report
## Scope: [repos / environments / managers covered]
## Date: [date]
### Live leaked secrets found
| Provider | Location | First seen (commit / date) | Verified live? | Rotation status |
|---|---|---|---|---|
### Secrets-management posture
| Category | Status | Notes |
|---|---|---|
### Recommendations
| Priority | Item | Owner | Deadline |
|---|---|---|---|Disposition rule (Fixed / Deferred / Accepted Risk) per owasp-audit.
gitleaks, trufflehog, detect-secrets documentation© briiirussell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/secrets-audit of briiirussell/cybersecurity-skills.
Open the folder on GitHubat commit c9ade03
Secrets Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Secrets Audit this skillbriiirussell/cybersecurity-skills | 413 | — | ~2.6k | Automated safety check: Notes | MIT | |
| Hashicorp VaultBagelHole/DevOps-Security-Agent-Skills | 1.2k | — | ~2k | Automated safety check: Pass | MIT | |
| Secrets Managementdavila7/claude-code-templates | 33k | 12 repos | ~2k | Automated safety check: Pass | MIT | |
| Secrets Vault Manageralirezarezvani/claude-skills | 28k | 1 repos | ~3.6k | Automated safety check: Notes | MIT | |
| Managing Secretsancoleman/ai-design-components | 525 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Audit Env Variablesqdhenry/Claude-Command-Suite | 1.3k | — | ~2.8k | Automated safety check: Notes | None |
BagelHole/DevOps-Security-Agent-Skills
Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.
davila7/claude-code-templates
Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools.
alirezarezvani/claude-skills
A skill your agent uses when the user asks to set up secret management infrastructure, integrate HashiCorp Vault, configure cloud secret stores (AWS Secrets Manager, Azure Key Vault, GCP Secret…
ancoleman/ai-design-components
Managing secrets (API keys, database credentials, certificates) with Vault, cloud providers, and Kubernetes.
qdhenry/Claude-Command-Suite
Analyze environment variables in JavaScript/TypeScript projects.
jamditis/claude-skills-journalism
Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports.
briiirussell/cybersecurity-skills
Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…
briiirussell/cybersecurity-skills
Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).
briiirussell/cybersecurity-skills
Learn from public breach disclosures — extract the audit question each one implies and check your own stack.
briiirussell/cybersecurity-skills
Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.
briiirussell/cybersecurity-skills
Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks.
briiirussell/cybersecurity-skills
Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation.
Works with
Categories
Find leaked secrets in source code, Git history, build artifacts, and infrastructure — and audit the secrets-management posture preventing future leaks. Secrets Audit is an agent skill from briiirussell/cybersecurity-skills. Find leaked secrets in source code, Git history, build artifacts, and infrastructure — and audit the secrets-management posture preventing future leaks.
Secrets Audit fits situations like: the user mentions secrets audit; secret scanning; leaked credentials; API key in code.
Run `npx skills add briiirussell/cybersecurity-skills --skill secrets-audit -a claude-code`. Or copy the skill folder (skills/secrets-audit in briiirussell/cybersecurity-skills) into .claude/skills/secrets-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add briiirussell/cybersecurity-skills --skill secrets-audit -a codex`. Or copy the skill folder (skills/secrets-audit in briiirussell/cybersecurity-skills) into .agents/skills/secrets-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add briiirussell/cybersecurity-skills --skill secrets-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secrets-audit, .gemini/skills/secrets-audit, .github/skills/secrets-audit and .opencode/skills/secrets-audit in your project.
Going by SKILL.md and its folder, Secrets Audit needs the command-line tools its instructions call (git, gitleaks, docker, aws, stripe and curl) and credentials named AWS_SECRET. Our summary lists: Docker; A credential in AWS_SECRET. Its frontmatter pre-approves these tools: Bash, Read, Write, Grep, Glob, WebSearch.
SKILL.md contains no URLs. Its commands use git, docker and curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Secrets Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Secrets Audit: Hashicorp Vault (BagelHole/DevOps-Security-Agent-Skills, 1.2k stars), Secrets Management (davila7/claude-code-templates, 33k stars), Secrets Vault Manager (alirezarezvani/claude-skills, 28k stars) and Managing Secrets (ancoleman/ai-design-components, 525 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
briiirussell (a GitHub user) maintains it in briiirussell/cybersecurity-skills, which has 413 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on May 27, 2026.
Source: briiirussell/cybersecurity-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.