Hashicorp Vault
BagelHole/DevOps-Security-Agent-Skills
Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.
Secrets management expertise covering HashiCorp Vault, AWS Secrets Manager, rotation strategies, zero-trust secrets architecture, envelope encryption, secret injection patterns, least-privilege…
$ npx skills add FerroxLabs/wayland --skill secrets-manager -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install FerroxLabs/wayland secrets-manager --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/devops-cloud/secrets-manager .claude/skills/secrets-manager && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "secrets-manager" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/devops-cloud/secrets-manager into .claude/skills/secrets-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-manager", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/devops-cloud/secrets-managerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add FerroxLabs/wayland --skill secrets-manager -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install FerroxLabs/wayland secrets-manager --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .agents/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/devops-cloud/secrets-manager .agents/skills/secrets-manager && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "secrets-manager" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/devops-cloud/secrets-manager into .agents/skills/secrets-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-manager", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add FerroxLabs/wayland --skill secrets-manager -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install FerroxLabs/wayland secrets-manager --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/devops-cloud/secrets-manager .cursor/skills/secrets-manager && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "secrets-manager" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/devops-cloud/secrets-manager into .cursor/skills/secrets-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-manager", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/FerroxLabs/wayland.git --path src/process/resources/skills-library/bodies/skills/devops-cloud/secrets-manager--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add FerroxLabs/wayland --skill secrets-manager -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install FerroxLabs/wayland secrets-manager --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/devops-cloud/secrets-manager .gemini/skills/secrets-manager && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "secrets-manager" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/devops-cloud/secrets-manager into .gemini/skills/secrets-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-manager", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install FerroxLabs/wayland secrets-managerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add FerroxLabs/wayland --skill secrets-manager -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .github/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/devops-cloud/secrets-manager .github/skills/secrets-manager && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "secrets-manager" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/devops-cloud/secrets-manager into .github/skills/secrets-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-manager", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add FerroxLabs/wayland --skill secrets-manager -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install FerroxLabs/wayland secrets-manager --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/FerroxLabs/wayland.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/src/process/resources/skills-library/bodies/skills/devops-cloud/secrets-manager .opencode/skills/secrets-manager && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "secrets-manager" agent skill from https://github.com/FerroxLabs/wayland/tree/main/src/process/resources/skills-library/bodies/skills/devops-cloud/secrets-manager into .opencode/skills/secrets-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-manager", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
secrets-managerSecrets management expertise covering HashiCorp Vault, AWS Secrets Manager, rotation strategies, zero-trust secrets architecture, envelope encryption, secret injection patterns, least-privilege…
Secrets Manager is an agent skill from FerroxLabs/wayland. Secrets management expertise covering HashiCorp Vault, AWS Secrets Manager, rotation strategies, zero-trust secrets architecture, envelope encryption, secret injection patterns, least-privilege access, and secrets lifecycle management. Use when the user asks about secrets manager, secrets manager best practices, or needs guidance on secrets manager implementation. Do NOT use when the user needs a different specialized skill or is asking about an unrelated technology domain.
Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Secrets management. It works with Amazon Web Services and HashiCorp Vault. The repository describes itself as: Wayland - The AI Agent That Perceives. Reasons. Acts. Evolves. The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4c030c7. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
vaultgitleaksawsmysqlFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Secrets Manager loads about 2.9k tokens when it runs. Until then it costs about 124 tokens; SKILL.md has 649 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from FerroxLabs/wayland at commit 4c030c7, republished under its Apache-2.0 licence (© FerroxLabs). 649 words, ~2,863 tokens.
.claude/skills/secrets-manager/SKILL.md (or your agent's skills folder).You are an expert in secrets management for production systems. Secrets -- API keys, database credentials, encryption keys, certificates, tokens -- are the keys to your kingdom. If secrets management is an afterthought, you are one leaked config-file file or one compromised CI pipeline away from a breach.
| Feature | HashiCorp Vault | AWS Secrets Manager | Azure Key Vault | GCP Secret Manager |
|---|---|---|---|---|
| Self-hosted | Yes | No | No | No |
| Dynamic secrets | Yes | No | No | No |
| Auto-rotation | Via policies | Built-in (Lambda) | Built-in | Via Cloud Functions |
| Cost | Free (OSS) | $0.40/secret/month | $0.03/10K ops | $0.06/10K ops |
| Complexity | High | Low | Low | Low |
Small team, single cloud provider
-> Use your cloud provider's secrets manager
Multi-cloud or hybrid
-> HashiCorp Vault
Need dynamic secrets (short-lived, per-request credentials)
-> HashiCorp Vault
Kubernetes-native
-> External Secrets Operator + any backendVault Architecture:
Auth Methods: AppRole, Kubernetes, AWS IAM, OIDC
Secrets Engines: KV (key-value), Database, PKI, Transit, AWS/Azure/GCP
Policies (ACL): Which auth role can access which secrets path
Audit Log: Every request logged# Enable KV secrets engine
vault secrets enable -path=secret kv-v2
# Store a secret
vault kv put secret/my-app/database \
url="postgresql://user:pass@db:5432/mydb" \
password="YOUR_SECURE_PASSWORD_HERE" # CHANGE THIS
# Create a policy
vault policy write my-app-policy - <<EOF
path "secret/data/my-app/*" {
capabilities = ["read", "list"]
}
path "database/creds/my-app-role" {
capabilities = ["read"]
}
EOF
# Enable AppRole auth
vault auth enable approle
vault write auth/approle/role/my-app \
token_policies="my-app-policy" \
token_ttl=1h \
token_max_ttl=4hvault secrets enable database
vault write database/config/mydb \
plugin_name=postgresql-database-plugin \
connection_url="postgresql://{{username}}:{{password}}@db:5432/mydb" \
allowed_roles="my-app-role" \
username="vault-admin" \
password="YOUR_VAULT_PASSWORD_HERE" # CHANGE THIS
vault write database/roles/my-app-role \
db_name=mydb \
creation_statements="CREATE ROLE \"{{name}}\" WITH LOGIN PASSWORD '{{password}}' \
VALID UNTIL '{{expiration}}'; \
GRANT SELECT, INSERT, UPDATE ON ALL TABLES IN SCHEMA public TO \"{{name}}\";" \
default_ttl="1h" \
max_ttl="24h"
# Application gets unique, short-lived credentials on demand
vault read database/creds/my-app-role
# Returns: { username: "v-approle-my-app-a1b2c3", password: "random", lease: 3600s }Master Key (KEK) -- stored in KMS/Vault, never leaves secure boundary
|
| encrypts/decrypts
v
Data Key (DEK) -- generated per record, encrypted copy stored with data
|
| encrypts/decrypts
v
Your Actual Data -- encrypted at rest
ENCRYPT:
1. KMS generates data key -> returns plaintext DEK + encrypted DEK
2. Encrypt data with plaintext DEK
3. Store: encrypted data + encrypted DEK
4. Discard plaintext DEK
DECRYPT:
1. Send encrypted DEK to KMS for decryption
2. Decrypt data with returned plaintext DEK
3. Discard plaintext DEK| Pattern | How | Pros | Cons |
|---|---|---|---|
| Environment variables | SECRET=value in pod spec | Simple, universal | Visible in process list |
| File mount | Secret written to volume | More secure than env vars | App must read file |
| Sidecar | Vault Agent injects secrets | Dynamic, auto-renewed | More infrastructure |
| SDK | App calls Vault API directly | Most control | Code dependency |
| External Secrets Operator | CRD syncs to k8s Secret | GitOps-friendly | Extra operator |
apiVersion: apps/v1
kind: Deployment
metadata:
name: my-api
spec:
template:
metadata:
annotations:
vault.hashicorp.com/agent-inject: "true"
vault.hashicorp.com/role: "my-app"
vault.hashicorp.com/agent-inject-secret-db.txt: "secret/data/my-app/database"
vault.hashicorp.com/agent-inject-template-db.txt: |
{{- with secret "secret/data/my-app/database" -}}
DATABASE_URL={{ .Data.data.url }}
{{- end }}
spec:
serviceAccountName: my-app
containers:
- name: my-api
image: my-api:latest
# Secret at /vault/secrets/db.txt, auto-renewedStep 1: Generate new credential (B)
Step 2: Update app to accept BOTH old (A) and new (B)
Step 3: Deploy application
Step 4: Update external system to use credential B
Step 5: Remove credential A from config
Step 6: Revoke credential ANo rotation needed. Credentials are generated on demand, short-lived (1h TTL), and auto-expired. New credentials requested before old ones expire.
Configure a Lambda function with four steps: createSecret (generate new), setSecret (update the target system), testSecret (verify it works), finishSecret (promote to current).
LAYER 1: Network - Secrets manager on private network only, mTLS
LAYER 2: AuthN - Platform identity (K8s SA, IAM role), no static creds
LAYER 3: AuthZ - Per-service policies, no wildcard access
LAYER 4: Encryption - Secrets encrypted at rest (KMS-backed)
LAYER 5: Audit - Every read/write logged, unusual access alerting
LAYER 6: Rotation - All secrets have max lifetime, automated rotation| Anti-Pattern | Risk | Fix |
|---|---|---|
| Shared secrets across services | One compromise exposes all | Unique secrets per service |
| Long-lived API keys | Extended blast radius | Short TTLs, auto-rotation |
| Secrets in CI/CD variables | CI compromise = all secrets | OIDC federation, no static secrets in CI |
config-file files in development | Accidentally committed | .config.example + secrets manager |
| Secrets in Docker images | Image pull = secret access | Inject at runtime only |
| Hardcoded in source code | Git history forever | Pre-commit hooks to detect |
# .pre-commit-config.yaml
repos:
- repo: [reference URL]
rev: v8.18.0
hooks:
- id: gitleaks# Scan existing repo history
gitleaks detect --source . --verbose
# CI integration: scan only new commits
gitleaks protect --staged --verboseAWS Access Key: AKIA[0-9A-Z]{16}
GitHub Token: gh[ps]_[a-zA-Z0-9]{36}
Private Key: -----BEGIN (RSA )?PRIVATE KEY-----
Connection string: (postgres|mysql|mongodb)://[^:]+:[^@]+@IMMEDIATE (0-15 min):
1. Rotate the compromised secret
2. Revoke all sessions/tokens issued with old secret
3. Check: is the secret used elsewhere? Rotate those too
4. Enable enhanced audit logging
INVESTIGATION (15 min - 4 hours):
5. How was the secret exposed?
6. Check audit logs for unauthorized access
7. Assess blast radius
8. If customer data at risk: involve legal/compliance
REMEDIATION (4-48 hours):
9. Fix root cause
10. If in Git: use git-filter-repo to remove
11. Scan all repos for similar exposures
12. Update pre-commit hooks
13. Post-mortem within 48 hoursUse this skill when:
Do NOT use this skill when:
# Secrets Manager Analysis
## Context Assessment
[Situation summary and constraints]
## Recommended Approach
[Primary recommendation with rationale]
## Implementation Steps
1. [Step with specific details]
2. [Step with specific details]
3. [Step with specific details]
## Trade-offs and Considerations
- [Key trade-off 1]
- [Key trade-off 2]
## Next Steps
- [Immediate action item]
- [Follow-up action item]Input: "Help me implement secrets manager for a medium-scale production application"
Output: A structured analysis covering current state assessment, recommended secrets manager approach with specific patterns, implementation roadmap with milestones, and risk mitigation strategies tailored to the application scale and constraints.
© FerroxLabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in src/process/resources/skills-library/bodies/skills/devops-cloud/secrets-manager of FerroxLabs/wayland.
Open the folder on GitHubat commit 4c030c7
Secrets Manager next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Secrets Manager this skillFerroxLabs/wayland | 608 | — | ~2.9k | Automated safety check: Pass | Apache-2.0 | |
| Hashicorp VaultBagelHole/DevOps-Security-Agent-Skills | 1.1k | — | ~2k | Automated safety check: Pass | MIT | |
| Secrets Managementdavila7/claude-code-templates | 32k | 11 repos | ~2k | Automated safety check: Pass | MIT | |
| Secrets Vault Manageralirezarezvani/claude-skills | 28k | 1 repos | ~3.6k | Automated safety check: Notes | MIT | |
| Managing Secretsancoleman/ai-design-components | 526 | — | ~2.9k | Automated safety check: Pass | MIT | |
| Secrets Auditbriiirussell/cybersecurity-skills | 412 | — | ~2.6k | Automated safety check: Notes | MIT |
BagelHole/DevOps-Security-Agent-Skills
Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.
davila7/claude-code-templates
Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools.
alirezarezvani/claude-skills
A skill your agent uses when the user asks to set up secret management infrastructure, integrate HashiCorp Vault, configure cloud secret stores (AWS Secrets Manager, Azure Key Vault, GCP Secret…
ancoleman/ai-design-components
Managing secrets (API keys, database credentials, certificates) with Vault, cloud providers, and Kubernetes.
briiirussell/cybersecurity-skills
Find leaked secrets in source code, Git history, build artifacts, and infrastructure — and audit the secrets-management posture preventing future leaks.
TheSoftwareHouse/copilot-collections
Secrets management patterns for cloud and Kubernetes environments.
FerroxLabs/wayland
Install, start, connect, and troubleshoot visualization companion projects for Aion/OpenClaw, with Star-Office-UI as the default recommendation.
FerroxLabs/wayland
OpenClaw usage expert: Helps you install, deploy, configure, and use OpenClaw personal AI assistant.
FerroxLabs/wayland
Set up TVControl end to end: install the connector, start TradingView Desktop with its control port open, load a watchlist export, add the indicators they use, and leave a working chart.
FerroxLabs/wayland
End-to-end guide for designing, running, and analyzing A/B tests including experiment design, statistical significance, sample size calculation, common pitfalls, and advanced testing patterns.
FerroxLabs/wayland
Complete academic writing guide covering thesis and dissertation structure, journal article format using IMRaD, literature review methodology, citation management, the peer review process, and…
FerroxLabs/wayland
Web accessibility expertise covering WCAG 2.2 conformance, audit methodology, ARIA patterns, keyboard navigation, screen reader testing, focus management, form accessibility, and automated vs manual…
Works with
Categories
Secrets management expertise covering HashiCorp Vault, AWS Secrets Manager, rotation strategies, zero-trust secrets architecture, envelope encryption, secret injection patterns, least-privilege…. Secrets Manager is an agent skill from FerroxLabs/wayland. Secrets management expertise covering HashiCorp Vault, AWS Secrets Manager, rotation strategies, zero-trust secrets architecture, envelope encryption, secret injection patterns, least-privilege access, and secrets lifecycle management.
Secrets Manager fits situations like: the user asks about secrets manager; secrets manager best practices; needs guidance on secrets manager implementation; the user needs a different specialized skill.
Run `npx skills add FerroxLabs/wayland --skill secrets-manager -a claude-code`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/devops-cloud/secrets-manager in FerroxLabs/wayland) into .claude/skills/secrets-manager in your project. Claude Code loads it when a task matches its description.
Run `npx skills add FerroxLabs/wayland --skill secrets-manager -a codex`. Or copy the skill folder (src/process/resources/skills-library/bodies/skills/devops-cloud/secrets-manager in FerroxLabs/wayland) into .agents/skills/secrets-manager in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add FerroxLabs/wayland --skill secrets-manager -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secrets-manager, .gemini/skills/secrets-manager, .github/skills/secrets-manager and .opencode/skills/secrets-manager in your project.
Going by SKILL.md and its folder, Secrets Manager needs the command-line tools its instructions call (vault, gitleaks, aws and mysql). Our summary lists: Docker.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Secrets Manager is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.9k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Secrets Manager: Hashicorp Vault (BagelHole/DevOps-Security-Agent-Skills, 1.1k stars), Secrets Management (davila7/claude-code-templates, 32k stars), Secrets Vault Manager (alirezarezvani/claude-skills, 28k stars) and Managing Secrets (ancoleman/ai-design-components, 526 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
FerroxLabs (a GitHub user) maintains it in FerroxLabs/wayland, which has 608 GitHub stars. The repository holds 1,194 skills in this directory. The repository was last updated on October 6, 2026.
Source: FerroxLabs/wayland on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.