Agent skill

Secrets Manager

by FerroxLabs in FerroxLabs/wayland

Secrets management expertise covering HashiCorp Vault, AWS Secrets Manager, rotation strategies, zero-trust secrets architecture, envelope encryption, secret injection patterns, least-privilege…

Apache-2.0Auto-check passedDevOps & Cloud

Install Secrets Manager

skills CLI
$ npx skills add FerroxLabs/wayland --skill secrets-manager -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install FerroxLabs/wayland secrets-manager --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/devops-cloud/secrets-manager .claude/skills/secrets-manager && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secrets-manager
GitHub stars
608
Token cost
~2.9k tokens
SKILL.md length
649 words
Files
1
Skills in repo
1,194
Repo updated
First seen
Licence
Apache-2.0

At a glance

Secrets management expertise covering HashiCorp Vault, AWS Secrets Manager, rotation strategies, zero-trust secrets architecture, envelope encryption, secret injection patterns, least-privilege…

  • Works in 5 steps: Never store secrets in code or Git. Git… → Secrets must be rotatable without… → Least privilege. Every service gets only… → …
  • The user asks about secrets manager
  • SKILL.md covers Secrets Management Principles, Solution Comparison, HashiCorp Vault and Envelope Encryption, plus 10 more sections
  • Calls vault, gitleaks and aws

What it does

Secrets Manager is an agent skill from FerroxLabs/wayland. Secrets management expertise covering HashiCorp Vault, AWS Secrets Manager, rotation strategies, zero-trust secrets architecture, envelope encryption, secret injection patterns, least-privilege access, and secrets lifecycle management. Use when the user asks about secrets manager, secrets manager best practices, or needs guidance on secrets manager implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Secrets management. It works with Amazon Web Services and HashiCorp Vault. The repository describes itself as: Wayland - The AI Agent That Perceives. Reasons. Acts. Evolves. The licence is Apache-2.0.

When your agent uses it

  • The user asks about secrets manager
  • Secrets manager best practices
  • Needs guidance on secrets manager implementation
  • The user needs a different specialized skill

Example prompts

  • “Use the secrets-manager skill to secret management expertise covering HashiCorp Vault, AWS Secrets Manager, rotation strategies, zero-trust secrets…”
  • “/secrets-manager”

Requirements

  • Docker

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Never store secrets in code or Git. Git history is forever.
  2. Secrets must be rotatable without downtime. If rotation requires a deployment, it will be delayed.
  3. Least privilege. Every service gets only the secrets it needs.
  4. Audit everything. Every secret access must be logged.
  5. Encrypt at rest and in transit. Decrypted only at point of use.

What it can do on your machine

Read from SKILL.md and the folder at commit 4c030c7. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • vault
    • gitleaks
    • aws
    • mysql

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secrets Manager loads about 2.9k tokens when it runs. Until then it costs about 124 tokens; SKILL.md has 649 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~124
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from FerroxLabs/wayland at commit 4c030c7, republished under its Apache-2.0 licence (© FerroxLabs). 649 words, ~2,863 tokens.

Download SKILL.mdSave it as .claude/skills/secrets-manager/SKILL.md (or your agent's skills folder).
name
secrets-manager
description
Secrets management expertise covering HashiCorp Vault, AWS Secrets Manager, rotation strategies, zero-trust secrets architecture, envelope encryption, secret injection patterns, least-privilege access, and secrets lifecycle management. Use when the user asks about secrets manager, secrets manager best practices, or needs guidance on secrets manager implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.
license
Apache-2.0
metadata.author
foundry-skills
metadata.version
1.0.0
metadata.tags
devops cloud security
metadata.category
devops-cloud
metadata.subcategory
cloud-infrastructure
metadata.disclaimer
none
metadata.difficulty
intermediate

Secrets Manager

You are an expert in secrets management for production systems. Secrets -- API keys, database credentials, encryption keys, certificates, tokens -- are the keys to your kingdom. If secrets management is an afterthought, you are one leaked config-file file or one compromised CI pipeline away from a breach.

Secrets Management Principles

  1. Never store secrets in code or Git. Git history is forever.
  2. Secrets must be rotatable without downtime. If rotation requires a deployment, it will be delayed.
  3. Least privilege. Every service gets only the secrets it needs.
  4. Audit everything. Every secret access must be logged.
  5. Encrypt at rest and in transit. Decrypted only at point of use.

Solution Comparison

FeatureHashiCorp VaultAWS Secrets ManagerAzure Key VaultGCP Secret Manager
Self-hostedYesNoNoNo
Dynamic secretsYesNoNoNo
Auto-rotationVia policiesBuilt-in (Lambda)Built-inVia Cloud Functions
CostFree (OSS)$0.40/secret/month$0.03/10K ops$0.06/10K ops
ComplexityHighLowLowLow
When to Choose What
Small team, single cloud provider
  -> Use your cloud provider's secrets manager

Multi-cloud or hybrid
  -> HashiCorp Vault

Need dynamic secrets (short-lived, per-request credentials)
  -> HashiCorp Vault

Kubernetes-native
  -> External Secrets Operator + any backend

HashiCorp Vault

Core Concepts
Vault Architecture:
  Auth Methods:   AppRole, Kubernetes, AWS IAM, OIDC
  Secrets Engines: KV (key-value), Database, PKI, Transit, AWS/Azure/GCP
  Policies (ACL):  Which auth role can access which secrets path
  Audit Log:       Every request logged
Basic Usage
shell
# Enable KV secrets engine
vault secrets enable -path=secret kv-v2

# Store a secret
vault kv put secret/my-app/database \
  url="postgresql://user:pass@db:5432/mydb" \
  password="YOUR_SECURE_PASSWORD_HERE"  # CHANGE THIS

# Create a policy
vault policy write my-app-policy - <<EOF
path "secret/data/my-app/*" {
  capabilities = ["read", "list"]
}
path "database/creds/my-app-role" {
  capabilities = ["read"]
}
EOF

# Enable AppRole auth
vault auth enable approle
vault write auth/approle/role/my-app \
  token_policies="my-app-policy" \
  token_ttl=1h \
  token_max_ttl=4h
Dynamic Database Credentials
shell
vault secrets enable database

vault write database/config/mydb \
  plugin_name=postgresql-database-plugin \
  connection_url="postgresql://{{username}}:{{password}}@db:5432/mydb" \
  allowed_roles="my-app-role" \
  username="vault-admin" \
  password="YOUR_VAULT_PASSWORD_HERE"  # CHANGE THIS

vault write database/roles/my-app-role \
  db_name=mydb \
  creation_statements="CREATE ROLE \"{{name}}\" WITH LOGIN PASSWORD '{{password}}' \
    VALID UNTIL '{{expiration}}'; \
    GRANT SELECT, INSERT, UPDATE ON ALL TABLES IN SCHEMA public TO \"{{name}}\";" \
  default_ttl="1h" \
  max_ttl="24h"

# Application gets unique, short-lived credentials on demand
vault read database/creds/my-app-role
# Returns: { username: "v-approle-my-app-a1b2c3", password: "random", lease: 3600s }

Envelope Encryption

Master Key (KEK) -- stored in KMS/Vault, never leaves secure boundary
    |
    | encrypts/decrypts
    v
Data Key (DEK) -- generated per record, encrypted copy stored with data
    |
    | encrypts/decrypts
    v
Your Actual Data -- encrypted at rest

ENCRYPT:
  1. KMS generates data key -> returns plaintext DEK + encrypted DEK
  2. Encrypt data with plaintext DEK
  3. Store: encrypted data + encrypted DEK
  4. Discard plaintext DEK

DECRYPT:
  1. Send encrypted DEK to KMS for decryption
  2. Decrypt data with returned plaintext DEK
  3. Discard plaintext DEK

Secret Injection Patterns

PatternHowProsCons
Environment variablesSECRET=value in pod specSimple, universalVisible in process list
File mountSecret written to volumeMore secure than env varsApp must read file
SidecarVault Agent injects secretsDynamic, auto-renewedMore infrastructure
SDKApp calls Vault API directlyMost controlCode dependency
External Secrets OperatorCRD syncs to k8s SecretGitOps-friendlyExtra operator
Vault Agent Sidecar (Kubernetes)
yaml
apiVersion: apps/v1
kind: Deployment
metadata:
  name: my-api
spec:
  template:
    metadata:
      annotations:
        vault.hashicorp.com/agent-inject: "true"
        vault.hashicorp.com/role: "my-app"
        vault.hashicorp.com/agent-inject-secret-db.txt: "secret/data/my-app/database"
        vault.hashicorp.com/agent-inject-template-db.txt: |
          {{- with secret "secret/data/my-app/database" -}}
          DATABASE_URL={{ .Data.data.url }}
          {{- end }}
    spec:
      serviceAccountName: my-app
      containers:
        - name: my-api
          image: my-api:latest
          # Secret at /vault/secrets/db.txt, auto-renewed

Rotation Strategies

Dual-Credential Rotation (Static Secrets)
Step 1: Generate new credential (B)
Step 2: Update app to accept BOTH old (A) and new (B)
Step 3: Deploy application
Step 4: Update external system to use credential B
Step 5: Remove credential A from config
Step 6: Revoke credential A
Dynamic Credentials (Vault)

No rotation needed. Credentials are generated on demand, short-lived (1h TTL), and auto-expired. New credentials requested before old ones expire.

AWS Secrets Manager Auto-Rotation

Configure a Lambda function with four steps: createSecret (generate new), setSecret (update the target system), testSecret (verify it works), finishSecret (promote to current).

Zero-Trust Secrets Architecture

LAYER 1: Network    - Secrets manager on private network only, mTLS
LAYER 2: AuthN      - Platform identity (K8s SA, IAM role), no static creds
LAYER 3: AuthZ      - Per-service policies, no wildcard access
LAYER 4: Encryption - Secrets encrypted at rest (KMS-backed)
LAYER 5: Audit      - Every read/write logged, unusual access alerting
LAYER 6: Rotation   - All secrets have max lifetime, automated rotation
Anti-Patterns
Anti-PatternRiskFix
Shared secrets across servicesOne compromise exposes allUnique secrets per service
Long-lived API keysExtended blast radiusShort TTLs, auto-rotation
Secrets in CI/CD variablesCI compromise = all secretsOIDC federation, no static secrets in CI
config-file files in developmentAccidentally committed.config.example + secrets manager
Secrets in Docker imagesImage pull = secret accessInject at runtime only
Hardcoded in source codeGit history foreverPre-commit hooks to detect

Secret Scanning

Pre-Commit Detection
yaml
# .pre-commit-config.yaml
repos:
  - repo: [reference URL]
    rev: v8.18.0
    hooks:
      - id: gitleaks
shell
# Scan existing repo history
gitleaks detect --source . --verbose

# CI integration: scan only new commits
gitleaks protect --staged --verbose
Patterns to Detect
AWS Access Key:    AKIA[0-9A-Z]{16}
GitHub Token:      gh[ps]_[a-zA-Z0-9]{36}
Private Key:       -----BEGIN (RSA )?PRIVATE KEY-----
Connection string: (postgres|mysql|mongodb)://[^:]+:[^@]+@

Emergency Response

Secret Compromise Runbook
IMMEDIATE (0-15 min):
  1. Rotate the compromised secret
  2. Revoke all sessions/tokens issued with old secret
  3. Check: is the secret used elsewhere? Rotate those too
  4. Enable enhanced audit logging

INVESTIGATION (15 min - 4 hours):
  5. How was the secret exposed?
  6. Check audit logs for unauthorized access
  7. Assess blast radius
  8. If customer data at risk: involve legal/compliance

REMEDIATION (4-48 hours):
  9. Fix root cause
  10. If in Git: use git-filter-repo to remove
  11. Scan all repos for similar exposures
  12. Update pre-commit hooks
  13. Post-mortem within 48 hours
Show full SKILL.md (264 more words)Show less

Secrets Management Checklist

  • No secrets in source code, Git history, or Docker images
  • Centralized secrets manager deployed
  • Per-service access policies (least privilege)
  • Secrets encrypted at rest and in transit
  • Automated rotation for all secrets
  • Rotation tested and verified
  • Secret scanning in CI pipeline
  • Pre-commit hooks prevent secret commits
  • Audit logging for all secret access
  • Emergency rotation runbook documented and tested
  • Developer onboarding includes secrets management training

When to Use

Use this skill when:

  • Designing or implementing secrets manager solutions
  • Reviewing or improving existing secrets manager approaches
  • Making architectural or implementation decisions about secrets manager
  • Learning secrets manager patterns and best practices
  • Troubleshooting secrets manager-related issues

Do NOT use this skill when:

  • The question is about a fundamentally different technology domain
  • A more specific sibling skill covers the exact topic needed
  • The user needs a complete hands-on tutorial rather than expert guidance

Output Format

markdown
# Secrets Manager Analysis

## Context Assessment
[Situation summary and constraints]

## Recommended Approach
[Primary recommendation with rationale]

## Implementation Steps
1. [Step with specific details]
2. [Step with specific details]
3. [Step with specific details]

## Trade-offs and Considerations
- [Key trade-off 1]
- [Key trade-off 2]

## Next Steps
- [Immediate action item]
- [Follow-up action item]

Example

Input: "Help me implement secrets manager for a medium-scale production application"

Output: A structured analysis covering current state assessment, recommended secrets manager approach with specific patterns, implementation roadmap with milestones, and risk mitigation strategies tailored to the application scale and constraints.

Edge Cases

  • Legacy system integration: When secrets manager must coexist with legacy approaches, provide a gradual migration path rather than a complete rewrite
  • Scale mismatch: When the solution complexity exceeds the project scale, recommend a simpler approach and note when to revisit
  • Team skill gaps: When the team lacks experience with the recommended approach, include learning resources and simpler alternatives
  • Conflicting requirements: When constraints conflict (e.g., performance vs. maintainability), explicitly state the trade-off and recommend based on stated priorities

© FerroxLabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in src/process/resources/skills-library/bodies/skills/devops-cloud/secrets-manager of FerroxLabs/wayland.

Open the folder on GitHubat commit 4c030c7

Compare with similar skills

Secrets Manager next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secrets Manager compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secrets Manager this skillFerroxLabs/wayland608—~2.9kAutomated safety check: PassApache-2.0
Hashicorp VaultBagelHole/DevOps-Security-Agent-Skills1.1k—~2kAutomated safety check: PassMIT
Secrets Managementdavila7/claude-code-templates32k11 repos~2kAutomated safety check: PassMIT
Secrets Vault Manageralirezarezvani/claude-skills28k1 repos~3.6kAutomated safety check: NotesMIT
Managing Secretsancoleman/ai-design-components526—~2.9kAutomated safety check: PassMIT
Secrets Auditbriiirussell/cybersecurity-skills412—~2.6kAutomated safety check: NotesMIT

Similar skills

  • Hashicorp Vault

    BagelHole/DevOps-Security-Agent-Skills

    Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~2k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed
  • Secrets Management

    davila7/claude-code-templates

    Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools.

    32k GitHub starsUsed in 11 repos~2k tokens
    DevOps & CloudAuto-check passed
  • Secrets Vault Manager

    alirezarezvani/claude-skills

    A skill your agent uses when the user asks to set up secret management infrastructure, integrate HashiCorp Vault, configure cloud secret stores (AWS Secrets Manager, Azure Key Vault, GCP Secret…

    28k GitHub starsUsed in 1 repo~3.6k tokens
    DevOps & CloudAuto-check: notes
  • Managing Secrets

    ancoleman/ai-design-components

    Managing secrets (API keys, database credentials, certificates) with Vault, cloud providers, and Kubernetes.

    526 GitHub stars~2.9k tokensUpdated 10 mo ago
    DevOps & CloudAuto-check passed
  • Secrets Audit

    briiirussell/cybersecurity-skills

    Find leaked secrets in source code, Git history, build artifacts, and infrastructure — and audit the secrets-management posture preventing future leaks.

    412 GitHub stars~2.6k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check: notes
  • Tsh Managing Secrets

    TheSoftwareHouse/copilot-collections

    Secrets management patterns for cloud and Kubernetes environments.

    284 GitHub stars~877 tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes

More from FerroxLabs/wayland

All 1,194 skills in this repo
  • Star Office Helper

    FerroxLabs/wayland

    Install, start, connect, and troubleshoot visualization companion projects for Aion/OpenClaw, with Star-Office-UI as the default recommendation.

    608 GitHub stars~2.2k tokensUpdated yesterday
    Auto-check: notes
  • Openclaw Setup

    FerroxLabs/wayland

    OpenClaw usage expert: Helps you install, deploy, configure, and use OpenClaw personal AI assistant.

    608 GitHub stars~1.9k tokensUpdated yesterday
    Auto-check passed
  • Tvcontrol Setup

    FerroxLabs/wayland

    Set up TVControl end to end: install the connector, start TradingView Desktop with its control port open, load a watchlist export, add the indicators they use, and leave a working chart.

    608 GitHub stars~5.7k tokensUpdated yesterday
    Auto-check passed
  • Ab Testing Specialist

    FerroxLabs/wayland

    End-to-end guide for designing, running, and analyzing A/B tests including experiment design, statistical significance, sample size calculation, common pitfalls, and advanced testing patterns.

    608 GitHub stars~3.7k tokensUpdated yesterday
    Auto-check passed
  • Academic Writer

    FerroxLabs/wayland

    Complete academic writing guide covering thesis and dissertation structure, journal article format using IMRaD, literature review methodology, citation management, the peer review process, and…

    608 GitHub stars~4.5k tokensUpdated yesterday
    Auto-check passed
  • Accessibility Auditor

    FerroxLabs/wayland

    Web accessibility expertise covering WCAG 2.2 conformance, audit methodology, ARIA patterns, keyboard navigation, screen reader testing, focus management, form accessibility, and automated vs manual…

    608 GitHub stars~4.1k tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Secrets Manager

What does Secrets Manager do?

Secrets management expertise covering HashiCorp Vault, AWS Secrets Manager, rotation strategies, zero-trust secrets architecture, envelope encryption, secret injection patterns, least-privilege…. Secrets Manager is an agent skill from FerroxLabs/wayland. Secrets management expertise covering HashiCorp Vault, AWS Secrets Manager, rotation strategies, zero-trust secrets architecture, envelope encryption, secret injection patterns, least-privilege access, and secrets lifecycle management.

When should I use Secrets Manager?

Secrets Manager fits situations like: the user asks about secrets manager; secrets manager best practices; needs guidance on secrets manager implementation; the user needs a different specialized skill.

How do I install Secrets Manager in Claude Code?

Run `npx skills add FerroxLabs/wayland --skill secrets-manager -a claude-code`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/devops-cloud/secrets-manager in FerroxLabs/wayland) into .claude/skills/secrets-manager in your project. Claude Code loads it when a task matches its description.

How do I install Secrets Manager in Codex?

Run `npx skills add FerroxLabs/wayland --skill secrets-manager -a codex`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/devops-cloud/secrets-manager in FerroxLabs/wayland) into .agents/skills/secrets-manager in your project. Codex loads it when a task matches its description.

Can I use Secrets Manager in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add FerroxLabs/wayland --skill secrets-manager -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secrets-manager, .gemini/skills/secrets-manager, .github/skills/secrets-manager and .opencode/skills/secrets-manager in your project.

What does Secrets Manager need to run?

Going by SKILL.md and its folder, Secrets Manager needs the command-line tools its instructions call (vault, gitleaks, aws and mysql). Our summary lists: Docker.

Does Secrets Manager access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Secrets Manager safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Secrets Manager use?

Secrets Manager is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Secrets Manager use?

About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Secrets Manager?

Skills that share tags, products or a category with Secrets Manager: Hashicorp Vault (BagelHole/DevOps-Security-Agent-Skills, 1.1k stars), Secrets Management (davila7/claude-code-templates, 32k stars), Secrets Vault Manager (alirezarezvani/claude-skills, 28k stars) and Managing Secrets (ancoleman/ai-design-components, 526 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secrets Manager?

FerroxLabs (a GitHub user) maintains it in FerroxLabs/wayland, which has 608 GitHub stars. The repository holds 1,194 skills in this directory. The repository was last updated on October 6, 2026.

Source: FerroxLabs/wayland on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.