Agent skill

AWS Secrets Inspector Expert

by GRCEngClub in GRCEngClub/claude-grc-engineering

A skill your agent uses when interpreting AWS Secrets Manager connector output, deciding between inspector and retrieve modes, drafting SCF-mapped controls for rotation / KMS / public-access /…

Custom licenceAuto-check: warningsDevOps & Cloud

Install AWS Secrets Inspector Expert

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add GRCEngClub/claude-grc-engineering --skill aws-secrets-inspector-expert -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install GRCEngClub/claude-grc-engineering aws-secrets-inspector-expert --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/GRCEngClub/claude-grc-engineering.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/connectors/aws-secrets-inspector/skills/aws-secrets-inspector-expert .claude/skills/aws-secrets-inspector-expert && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aws-secrets-inspector-expert
GitHub stars
419
Token cost
~2.5k tokens
SKILL.md length
1,306 words
Files
1
Skills in repo
12
Repo updated
First seen
Licence
Custom licence

At a glance

A skill your agent uses when interpreting AWS Secrets Manager connector output, deciding between inspector and retrieve modes, drafting SCF-mapped controls for rotation / KMS / public-access /…

  • Works in 4 steps: Help operators decide which mode to use… → Interpret the four SCF-mapped checks… → Explain the safety contract for… → …
  • Interpreting AWS Secrets Manager connector output
  • SKILL.md covers Checks this connector runs…, Framework mappings (via SCF…, Mode selection — inspector vs… and Interpreting output, plus 4 more sections
  • Calls aws and jq; reaches grcengclub.github.io

What it does

AWS Secrets Inspector Expert is an agent skill from GRCEngClub/claude-grc-engineering. Use when interpreting AWS Secrets Manager connector output, deciding between inspector and retrieve modes, drafting SCF-mapped controls for rotation / KMS / public-access / inactive-access findings, or troubleshooting an aws-secrets-inspector run.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud. It works with Amazon Web Services. The repository describes itself as: Open-source GRC toolkit from the GRC Engineering Club. Claude Code plugins for evidence collection, SCF crosswalks, multi-framework gap reports, OSCAL workflows.

When your agent uses it

  • Interpreting AWS Secrets Manager connector output
  • Deciding between inspector and retrieve modes
  • Drafting SCF-mapped controls for rotation / KMS / public-access / inactive-access findings
  • Troubleshooting an aws-secrets-inspector run

Example prompts

  • “/aws-secrets-inspector-expert”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Help operators decide which mode to use and when.
  2. Interpret the four SCF-mapped checks against real-world posture.
  3. Explain the safety contract for retrieval — the value never lands in the findings cache, runs.log, or stderr, and --write-to is restricted…
  4. Help diagnose failures (auth, rate-limit, denied, not-configured, not-found).

What it can do on your machine

Read from SKILL.md and the folder at commit 784fd9a. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • grcengclub.github.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

AWS Secrets Inspector Expert loads about 2.5k tokens when it runs. Until then it costs about 69 tokens; SKILL.md has 1,306 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~69
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:106
    the SDK falls through to env vars → `~/.aws/credentials` → IRSA/SSO. Verify with `/aws-secrets-inspector:status` before

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 1,306 words (~2,544 tokens).

“You are the interpretation layer for the AWS Secrets Manager connector. The connector has two modes — inspector (read configuration, emit v1 finding-contract documents) and retrieve (read a single secret value to stdout or a 0600 file). Your job is…”

— opening of SKILL.md by GRCEngClub, Custom licence
name
aws-secrets-inspector-expert

Read the full SKILL.md on GitHub

Files

Just SKILL.md in plugins/connectors/aws-secrets-inspector/skills/aws-secrets-inspector-expert of GRCEngClub/claude-grc-engineering.

Open the folder on GitHubat commit 784fd9a

Compare with similar skills

AWS Secrets Inspector Expert next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

AWS Secrets Inspector Expert compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
AWS Secrets Inspector Expert this skillGRCEngClub/claude-grc-engineering419—~2.5kAutomated safety check: WarnCustom licence
Cloud Cost Optimizationwshobson/agents40k14 repos~1.7kAutomated safety check: PassMIT
Review Docshashicorp/terraform-provider-aws11k—~1.3kAutomated safety check: PassMPL-2.0
AWS Cdk Developmentzxkane/aws-skills3672 repos~2.5kAutomated safety check: PassMIT
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
Terravision Cloud Diagramspatrickchugh/terravision1.6k—~5.6kAutomated safety check: NotesAGPL-3.0-only

Similar skills

  • Cuts cloud spend across AWS, Azure, GCP and OCI with cost tagging, rightsizing, commitment and spot pricing models, and architecture changes.

    40k GitHub starsUsed in 14 repos~1.7k tokens
    DevOps & CloudAuto-check passed
  • Review Docs

    hashicorp/terraform-provider-aws

    Official

    Review a Terraform AWS Provider PR's end-user documentation (website/docs//.markdown): whether docs are needed, description openings, argument/attribute style, section structure, tags wording, code…

    11k GitHub stars~1.3k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • AWS Cdk Development

    zxkane/aws-skills

    AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.

    367 GitHub starsUsed in 2 repos~2.5k tokens
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Terravision Cloud Diagrams

    patrickchugh/terravision

    Draw cloud architecture diagrams for AWS, Azure or GCP with the official provider icon sets, using TerraVision.

    1.6k GitHub stars~5.6k tokensUpdated 4 days ago
    DevOps & CloudAuto-check: notes
  • Thesvg

    glincker/thesvg

    Fetch brand SVG logos and cloud architecture icons (AWS, Azure, GCP) from theSVG.

    2.8k GitHub stars~1.5k tokensUpdated today
    DevOps & CloudAuto-check passed

More from GRCEngClub/claude-grc-engineering

All 12 skills in this repo
  • Trust Center Builder

    GRCEngClub/claude-grc-engineering

    Builds and deploys a serverless trust center that publishes a company's compliance posture, with gated access to audit reports and an admin dashboard.

    419 GitHub stars~2.6k tokensUpdated 7 days ago
    Auto-check passed
  • GRC Report Context Bootstrap

    GRCEngClub/claude-grc-engineering

    Checks that plugins, collected findings and history exist before a GRC /report command runs, and walks the user through setup instead of producing an empty report.

    419 GitHub stars~1.4k tokensUpdated 7 days ago
    Auto-check: notes
  • Draw.io Diagram Generator

    GRCEngClub/claude-grc-engineering

    Generates draw.io diagrams as native .drawio files, including GRC workflows and control maps, with optional PNG, SVG or PDF export that stays editable.

    419 GitHub stars~1.3k tokensUpdated 7 days ago
    Auto-check: notes
  • Academic Research Companion

    GRCEngClub/claude-grc-engineering

    Guide a research project through the full academic lifecycle — from raw idea to concrete research question, literature grounding, methodology, writing, feedback, and publication.

    419 GitHub stars~2.2k tokensUpdated 7 days ago
    Auto-check passed
  • Access Review Triage

    GRCEngClub/claude-grc-engineering

    Helps you triage a quarterly user access review from an Okta, Azure AD, AWS IAM, GitHub, or generic CSV/JSON export.

    419 GitHub stars~2.4k tokensUpdated 7 days ago
    Auto-check: notes
  • Audit Ready PR Reviewer

    GRCEngClub/claude-grc-engineering

    Reviews pull requests for compliance regressions. An agent skill from GRCEngClub/claude-grc-engineering.

    419 GitHub stars~587 tokensUpdated 7 days ago
    Auto-check: notes

Categories

Questions about AWS Secrets Inspector Expert

What does AWS Secrets Inspector Expert do?

A skill your agent uses when interpreting AWS Secrets Manager connector output, deciding between inspector and retrieve modes, drafting SCF-mapped controls for rotation / KMS / public-access /…. AWS Secrets Inspector Expert is an agent skill from GRCEngClub/claude-grc-engineering. Use when interpreting AWS Secrets Manager connector output, deciding between inspector and retrieve modes, drafting SCF-mapped controls for rotation / KMS / public-access / inactive-access findings, or troubleshooting an aws-secrets-inspector run.

When should I use AWS Secrets Inspector Expert?

AWS Secrets Inspector Expert fits situations like: interpreting AWS Secrets Manager connector output; deciding between inspector and retrieve modes; drafting SCF-mapped controls for rotation / KMS / public-access / inactive-access findings; troubleshooting an aws-secrets-inspector run.

How do I install AWS Secrets Inspector Expert in Claude Code?

Run `npx skills add GRCEngClub/claude-grc-engineering --skill aws-secrets-inspector-expert -a claude-code`. Or copy the skill folder (plugins/connectors/aws-secrets-inspector/skills/aws-secrets-inspector-expert in GRCEngClub/claude-grc-engineering) into .claude/skills/aws-secrets-inspector-expert in your project. Claude Code loads it when a task matches its description.

How do I install AWS Secrets Inspector Expert in Codex?

Run `npx skills add GRCEngClub/claude-grc-engineering --skill aws-secrets-inspector-expert -a codex`. Or copy the skill folder (plugins/connectors/aws-secrets-inspector/skills/aws-secrets-inspector-expert in GRCEngClub/claude-grc-engineering) into .agents/skills/aws-secrets-inspector-expert in your project. Codex loads it when a task matches its description.

Can I use AWS Secrets Inspector Expert in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add GRCEngClub/claude-grc-engineering --skill aws-secrets-inspector-expert -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aws-secrets-inspector-expert, .gemini/skills/aws-secrets-inspector-expert, .github/skills/aws-secrets-inspector-expert and .opencode/skills/aws-secrets-inspector-expert in your project.

What does AWS Secrets Inspector Expert need to run?

Going by SKILL.md and its folder, AWS Secrets Inspector Expert needs the command-line tools its instructions call (aws and jq).

Does AWS Secrets Inspector Expert access the network?

SKILL.md names 1 domain. In commands or code: grcengclub.github.io; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is AWS Secrets Inspector Expert safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does AWS Secrets Inspector Expert use?

AWS Secrets Inspector Expert has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does AWS Secrets Inspector Expert use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to AWS Secrets Inspector Expert?

Skills that share tags, products or a category with AWS Secrets Inspector Expert: Cloud Cost Optimization (wshobson/agents, 40k stars), Review Docs (hashicorp/terraform-provider-aws, 11k stars), AWS Cdk Development (zxkane/aws-skills, 367 stars) and Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains AWS Secrets Inspector Expert?

GRCEngClub (a GitHub organization) maintains it in GRCEngClub/claude-grc-engineering, which has 419 GitHub stars. The repository holds 12 skills in this directory. The repository was last updated on October 4, 2026.

Source: GRCEngClub/claude-grc-engineering on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.