Agent skill

AWS SDK Java V2 Secrets Manager

by giuseppe-trisciuoglio in giuseppe-trisciuoglio/developer-kit

Provides AWS Secrets Manager patterns for AWS SDK for Java 2.x, including secret retrieval, caching, rotation-aware access, and Spring Boot integration.

MITAuto-check: notesBackend & APIs

Install AWS SDK Java V2 Secrets Manager

skills CLI
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill aws-sdk-java-v2-secrets-manager -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install giuseppe-trisciuoglio/developer-kit aws-sdk-java-v2-secrets-manager --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/developer-kit-java/skills/aws-sdk-java-v2-secrets-manager .claude/skills/aws-sdk-java-v2-secrets-manager && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aws-sdk-java-v2-secrets-manager
GitHub stars
356
Token cost
~1.5k tokens
SKILL.md length
597 words
Files
5 (incl. references, assets)
Skills in repo
115
Repo updated
First seen
Licence
MIT

At a glance

Provides AWS Secrets Manager patterns for AWS SDK for Java 2.x, including secret retrieval, caching, rotation-aware access, and Spring Boot integration.

  • Works in 6 steps: Model the secret before writing access… → Create one reusable client per… → Retrieve and deserialize at the boundary… → …
  • Reading secrets in Java services
  • SKILL.md covers Overview, When to Use, Instructions and Examples, plus 4 more sections
  • Runs Java scripts from its folder; calls java and aws

What it does

AWS SDK Java V2 Secrets Manager is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides AWS Secrets Manager patterns for AWS SDK for Java 2.x, including secret retrieval, caching, rotation-aware access, and Spring Boot integration. Use when storing or reading secrets in Java services, replacing hardcoded credentials, or wiring secret-backed configuration into applications.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files and assets (for example `references/api-reference.md`, `references/caching-guide.md` and `references/spring-boot-integration.md`).

It sits in Backend & APIs, covering Caching and Backend development. It works with Amazon Web Services, Java and Spring Boot. The repository describes itself as: Modular plugin marketplace for Claude Code and agentic CLIs, with validated, spec-driven skills, agents, commands, and workflows for Java, TypeScript, Python, PHP, AWS, and AI. The licence is MIT.

When your agent uses it

  • Reading secrets in Java services
  • Replacing hardcoded credentials
  • Wiring secret-backed configuration into applications

Example prompts

  • “Use the aws-sdk-java-v2-secrets-manager skill to provide AWS Secrets Manager patterns for AWS SDK for Java 2.x, including secret retrieval, caching…”
  • “/aws-sdk-java-v2-secrets-manager”

Requirements

  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash, Glob, Grep

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Model the secret before writing access code
  2. Create one reusable client per application configuration
  3. Retrieve and deserialize at the boundary layer
  4. Add caching only where it solves a real problem
  5. Design for rotation and staged versions
  6. Validate end-to-end behavior

What it can do on your machine

Read from SKILL.md and the folder at commit fe73fb3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash
    • Glob
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Java), which the agent can run.

    Shell commands in SKILL.md call:

    • java
    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use aws, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AWS SDK Java V2 Secrets Manager loads about 1.5k tokens when it runs, and up to ~8.7k if it reads all its reference files. Until then it costs about 82 tokens; SKILL.md has 597 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Edit, Bash, Glob, Grep

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from giuseppe-trisciuoglio/developer-kit at commit fe73fb3, republished under its MIT licence (© giuseppe-trisciuoglio). 597 words, ~1,522 tokens.

Download SKILL.mdSave it as .claude/skills/aws-sdk-java-v2-secrets-manager/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
aws-sdk-java-v2-secrets-manager
description
Provides AWS Secrets Manager patterns for AWS SDK for Java 2.x, including secret retrieval, caching, rotation-aware access, and Spring Boot integration. Use when storing or reading secrets in Java services, replacing hardcoded credentials, or wiring secret-backed configuration into applications.
allowed-tools
Read, Write, Edit, Bash, Glob, Grep

AWS SDK for Java 2.x - AWS Secrets Manager

Overview

Use this skill to manage application secrets with AWS Secrets Manager from Java services.

It focuses on the operational flow that matters in production:

  • how to retrieve and deserialize secrets safely
  • when to add local caching
  • how to integrate secret access into Spring Boot without leaking values into logs or configuration files

Keep large API notes and extended setup details in the bundled references.

When to Use

Use this skill when:

  • replacing hardcoded passwords, API keys, or tokens with managed secrets
  • loading database credentials or third-party API credentials at runtime
  • adding caching to reduce Secrets Manager latency and API cost
  • handling secret version stages such as AWSCURRENT and AWSPENDING
  • wiring secret access into Spring Boot beans or configuration services
  • preparing rotation-aware applications or Lambda rotation workflows

Typical trigger phrases include java secrets manager, spring boot secret, aws secret cache, load db credentials from secrets manager, and rotate secret.

Instructions

1. Model the secret before writing access code

Decide:

  • the secret name and path convention
  • whether the value is plain text or structured JSON
  • which application boundary is allowed to read it
  • whether the caller needs the latest value on every request or can tolerate a cache

Prefer JSON secrets for multi-field credentials such as database connection details.

2. Create one reusable client per application configuration

Use a single SecretsManagerClient with explicit region and the default credential provider chain unless the environment requires something more specific.

Keep client creation in configuration code, not in business services.

3. Retrieve and deserialize at the boundary layer

At the integration boundary:

  • fetch with GetSecretValueRequest
  • deserialize JSON into a typed object or validated map
  • convert AWS exceptions into application-level errors
  • never log secretString() or include it in thrown exception messages
4. Add caching only where it solves a real problem

Use caching when:

  • the secret is read frequently
  • latency matters for startup or request handling
  • the cost of repeated lookups is material

Document cache TTL expectations clearly, especially if the secret rotates.

Show full SKILL.md (261 more words)Show less
5. Design for rotation and staged versions

If the secret rotates:

  • read through a thin service layer so cache invalidation and retry behavior stay centralized
  • understand which callers must tolerate AWSPENDING during verification workflows
  • test how the application behaves during stale cache windows or partial rotation failures
6. Validate end-to-end behavior

Before shipping:

  • verify IAM permissions and KMS access
  • test missing secret, wrong region, and decryption failure paths
  • confirm secrets are not surfaced in logs, metrics, or debug endpoints
  • prove database or API clients refresh correctly when credentials rotate

Examples

Example 1: Reusable client and typed secret lookup
java
@Configuration
public class SecretsConfiguration {

    @Bean
    SecretsManagerClient secretsManagerClient() {
        return SecretsManagerClient.builder()
            .region(Region.of("eu-south-2"))
            .credentialsProvider(DefaultCredentialsProvider.create())
            .build();
    }
}

@Service
public class SecretsService {

    private final SecretsManagerClient client;
    private final ObjectMapper objectMapper;

    public SecretsService(SecretsManagerClient client, ObjectMapper objectMapper) {
        this.client = client;
        this.objectMapper = objectMapper;
    }

    public DatabaseSecret loadDatabaseSecret(String secretId) throws JsonProcessingException {
        GetSecretValueResponse response = client.getSecretValue(
            GetSecretValueRequest.builder().secretId(secretId).build()
        );
        return objectMapper.readValue(response.secretString(), DatabaseSecret.class);
    }
}
Example 2: Cache a hot-path secret lookup
java
public class CachedSecretsService {

    private final SecretCache cache;

    public CachedSecretsService(SecretsManagerClient client) {
        this.cache = new SecretCache(client);
    }

    public String apiToken(String secretId) {
        return cache.getSecretString(secretId);
    }
}

Use this pattern only when the application can tolerate the chosen cache refresh behavior.

Best Practices

  • Use hierarchical secret names that match domain and environment boundaries.
  • Prefer typed JSON deserialization over string parsing scattered across the codebase.
  • Keep secret retrieval in infrastructure services rather than controllers or entities.
  • Reuse the SDK client and cache instances.
  • Combine least-privilege IAM with KMS permissions and CloudTrail visibility.
  • Make rotation behavior explicit in code and operational docs.

Constraints and Warnings

  • Do not log secret values, serialized secret objects, or decrypted payload fragments.
  • Cached values may remain stale during or after rotation depending on TTL and refresh behavior.
  • Secret access can fail because of IAM policy, KMS policy, region mismatch, or deleted versions; handle these cases explicitly.
  • Automatic rotation is not available for every secret shape or integration.
  • Large or frequently changing secrets may not be good candidates for aggressive in-memory caching.

References

  • references/api-reference.md
  • references/caching-guide.md
  • references/spring-boot-integration.md
  • aws-sdk-java-v2-core
  • aws-sdk-java-v2-kms
  • spring-boot-dependency-injection

© giuseppe-trisciuoglio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references, assets) in plugins/developer-kit-java/skills/aws-sdk-java-v2-secrets-manager of giuseppe-trisciuoglio/developer-kit.

  • SKILL.md
  • assets/templates/SecretsManagerConfigTemplate.java
  • references/api-reference.md
  • references/caching-guide.md
  • references/spring-boot-integration.md

Open the folder on GitHubat commit fe73fb3

Compare with similar skills

AWS SDK Java V2 Secrets Manager next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AWS SDK Java V2 Secrets Manager compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AWS SDK Java V2 Secrets Manager this skillgiuseppe-trisciuoglio/developer-kit356—~1.5kAutomated safety check: NotesMIT
Springboot Patternsaffaan-m/ECC276k5 repos~2.5kAutomated safety check: PassMIT
302 Frameworks Spring Boot RESTjabrena/plinth447—~1kAutomated safety check: PassApache-2.0
Spring Bootpiomin/claude-ai-spring-boot1.3k—~2kAutomated safety check: PassApache-2.0
Dr Jskilljdubois/dr-jskill342—~4.6kAutomated safety check: NotesApache-2.0
WxJava Integration Guidebinarywang/WxJava33k—~123Automated safety check: PassApache-2.0

Similar skills

  • Spring Boot architecture patterns, REST API design, layered services, data access, caching, async processing, and logging.

    276k GitHub starsUsed in 5 repos~2.5k tokens
    Backend & APIsAuto-check passed
  • A skill your agent uses when you need to design, review, or improve REST APIs with Spring Boot — including HTTP methods, resource URIs, status codes, DTOs, versioning, deprecation and sunset…

    447 GitHub stars~1k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Spring Boot

    piomin/claude-ai-spring-boot

    Spring Boot 3.x development - REST APIs, JPA, Security, Testing, and Cloud-native patterns.

    1.3k GitHub stars~2k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed
  • Dr Jskill

    jdubois/dr-jskill

    Creates Java + Spring Boot projects: Web applications, full-stack apps with Vue.js or Angular or React or vanilla JS, PostgreSQL, REST APIs, and Docker.

    342 GitHub stars~4.6k tokensUpdated 9 days ago
    Backend & APIsAuto-check: notes
  • WxJava Integration Guide

    binarywang/WxJava

    Plans a WxJava setup for Java, Spring Boot or Solon projects that call WeChat services, from module and BOM choice to config and a minimal working call.

    33k GitHub stars~123 tokensUpdated today
    Backend & APIsAuto-check passed
  • Flycms Dev

    sunkaifei/FlyCms

    FlyCms 项目(backend/ Spring Boot 4.1.1 + frontend/ vue-vben-admin v5)的架构地图与开发规范总纲。凡在本仓库做任何开发——写后端接口、新增/修改模块、管理页面、数据库变更、修 bug、重构——都要先加载本 skill 再动手,即使用户只说"改一下""加个功能";前端登录/菜单/权限专项另见…

    656 GitHub stars~827 tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from giuseppe-trisciuoglio/developer-kit

All 115 skills in this repo
  • Nestjs Drizzle Crud Generator

    giuseppe-trisciuoglio/developer-kit

    Generates complete CRUD modules for NestJS applications with Drizzle ORM.

    356 GitHub stars~1.3k tokensUpdated 29 days ago
    Auto-check: notes
  • Spring Boot Actuator

    giuseppe-trisciuoglio/developer-kit

    Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services.

    356 GitHub stars~2.2k tokensUpdated 29 days ago
    Auto-check: notes
  • Spring Boot Crud Patterns

    giuseppe-trisciuoglio/developer-kit

    Provides and generates complete CRUD workflows for Spring Boot 3 services.

    356 GitHub stars~2.5k tokensUpdated 29 days ago
    Auto-check: notes
  • Spring Boot Security JWT

    giuseppe-trisciuoglio/developer-kit

    Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…

    356 GitHub stars~3.9k tokensUpdated 29 days ago
    Auto-check: notes
  • AWS CLI Beast

    giuseppe-trisciuoglio/developer-kit

    Provides advanced AWS CLI patterns for managing EC2, Lambda, S3, DynamoDB, RDS, VPC, IAM, and CloudWatch.

    356 GitHub stars~1.7k tokensUpdated 29 days ago
    Auto-check: notes
  • PR Review Comments

    giuseppe-trisciuoglio/developer-kit

    Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line.

    356 GitHub stars~1k tokensUpdated 29 days ago
    Auto-check: notes

Categories

Questions about AWS SDK Java V2 Secrets Manager

What does AWS SDK Java V2 Secrets Manager do?

Provides AWS Secrets Manager patterns for AWS SDK for Java 2.x, including secret retrieval, caching, rotation-aware access, and Spring Boot integration. AWS SDK Java V2 Secrets Manager is an agent skill from giuseppe-trisciuoglio/developer-kit.x, including secret retrieval, caching, rotation-aware access, and Spring Boot integration.

When should I use AWS SDK Java V2 Secrets Manager?

AWS SDK Java V2 Secrets Manager fits situations like: reading secrets in Java services; replacing hardcoded credentials; wiring secret-backed configuration into applications.

How do I install AWS SDK Java V2 Secrets Manager in Claude Code?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill aws-sdk-java-v2-secrets-manager -a claude-code`. Or copy the skill folder (plugins/developer-kit-java/skills/aws-sdk-java-v2-secrets-manager in giuseppe-trisciuoglio/developer-kit) into .claude/skills/aws-sdk-java-v2-secrets-manager in your project. Claude Code loads it when a task matches its description.

How do I install AWS SDK Java V2 Secrets Manager in Codex?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill aws-sdk-java-v2-secrets-manager -a codex`. Or copy the skill folder (plugins/developer-kit-java/skills/aws-sdk-java-v2-secrets-manager in giuseppe-trisciuoglio/developer-kit) into .agents/skills/aws-sdk-java-v2-secrets-manager in your project. Codex loads it when a task matches its description.

Can I use AWS SDK Java V2 Secrets Manager in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add giuseppe-trisciuoglio/developer-kit --skill aws-sdk-java-v2-secrets-manager -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-sdk-java-v2-secrets-manager, .gemini/skills/aws-sdk-java-v2-secrets-manager, .github/skills/aws-sdk-java-v2-secrets-manager and .opencode/skills/aws-sdk-java-v2-secrets-manager in your project.

What does AWS SDK Java V2 Secrets Manager need to run?

Going by SKILL.md and its folder, AWS SDK Java V2 Secrets Manager needs Java for the scripts in its folder and the command-line tools its instructions call (java and aws). Its frontmatter pre-approves these tools: Read, Write, Edit, Bash, Glob, Grep.

Does AWS SDK Java V2 Secrets Manager access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is AWS SDK Java V2 Secrets Manager safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does AWS SDK Java V2 Secrets Manager use?

AWS SDK Java V2 Secrets Manager is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does AWS SDK Java V2 Secrets Manager use?

About 1.5k tokens (SKILL.md is roughly 6.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.2k tokens, read only when the agent opens those files.

What are the alternatives to AWS SDK Java V2 Secrets Manager?

Skills that share tags, products or a category with AWS SDK Java V2 Secrets Manager: Springboot Patterns (affaan-m/ECC, 276k stars), 302 Frameworks Spring Boot REST (jabrena/plinth, 447 stars), Spring Boot (piomin/claude-ai-spring-boot, 1.3k stars) and Dr Jskill (jdubois/dr-jskill, 342 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AWS SDK Java V2 Secrets Manager?

giuseppe-trisciuoglio (a GitHub user) maintains it in giuseppe-trisciuoglio/developer-kit, which has 356 GitHub stars. The repository holds 115 skills in this directory. The repository was last updated on September 10, 2026.

Source: giuseppe-trisciuoglio/developer-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.