Agent skill

Secrets Management

by Hack23 in Hack23/cia

Never commit secrets, manage credentials securely using environment variables, vaults, and Hack23 ISMS key management policy

Apache-2.0Auto-check: notesDevOps & Cloud

Install Secrets Management

skills CLI
$ npx skills add Hack23/cia --skill secrets-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Hack23/cia secrets-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/secrets-management .claude/skills/secrets-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secrets-management
GitHub stars
239
Token cost
~5.3k tokens
SKILL.md length
517 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
Apache-2.0

At a glance

Never commit secrets, manage credentials securely using environment variables, vaults, and Hack23 ISMS key management policy

  • Works in 5 steps: ✅ Rotate the compromised secret… → ✅ Revoke old secret/key from all systems → ✅ Review access logs for unauthorized… → …
  • Tasks that involve Secrets management
  • SKILL.md covers Purpose, When to Use This Skill, Golden Rules of Secrets… and Secrets Detection and Prevention, plus 7 more sections
  • Calls openssl, git and kubectl; reaches github.com and data.riksdagen.se; needs DATABASE_PASSWORD and RIKSDAGEN_API_KEY

What it does

Secrets Management is an agent skill from Hack23/cia. Never commit secrets, manage credentials securely using environment variables, vaults, and Hack23 ISMS key management policy

Its SKILL.md is about 5.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Secrets management and Cryptography. It works with Git. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Secrets management
  • Tasks that involve Cryptography

Example prompts

  • “/secrets-management”

Requirements

  • Docker
  • A credential in API_KEY
  • A credential in RIKSDAGEN_API_KEY

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. ✅ Rotate the compromised secret immediately
  2. ✅ Revoke old secret/key from all systems
  3. ✅ Review access logs for unauthorized access
  4. ✅ Notify security team and stakeholders
  5. ✅ Document incident in security log

What it can do on your machine

Read from SKILL.md and the folder at commit bbed538. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • openssl
    • git
    • kubectl
    • aws
    • psql
    • brew
    • apt-get
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com
    • data.riksdagen.se
    • api.worldbank.org

    Also links to:

    • cheatsheetseries.owasp.org
    • csrc.nist.gov
    • aws.amazon.com
    • vaultproject.io
    • spring.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DATABASE_PASSWORD
    • RIKSDAGEN_API_KEY
    • JWT_SECRET
    • NEW_DB_PASSWORD
    • NEW_SECRET
    • WORLDBANK_API_KEY
    • GITHUB_TOKEN
    • DB_PASSWORD
    • API_KEY
    • VAULT_TOKEN
    • CONFIG_SERVER_ENCRYPTION_KEY
    • FIELD_ENCRYPTION_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secrets Management loads about 5.3k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 517 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~36
When it runs · the whole SKILL.md, loaded when a task matches
~5.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:154
    # Never commit .env file with real secrets
  • NoteMentions a .env fileSKILL.md:161
    - .env  # Git-ignored file with secrets
  • NoteMentions a .env fileSKILL.md:167
    # Copy to .env and fill in actual values
  • NoteMentions a .env fileSKILL.md:168
    # NEVER commit .env file!
  • NoteMentions a .env fileSKILL.md:183
    .env
  • NoteMentions a .env fileSKILL.md:184
    .env.local
  • NoteMentions a .env fileSKILL.md:185
    .env.production
  • NoteRuns commands with sudoSKILL.md:239
    sudo apt-get install git-secrets  # Ubuntu
  • NoteMentions a .env fileSKILL.md:269
    # Check for .env files
  • NoteMentions a .env fileSKILL.md:271
    echo "❌ ERROR: Attempting to commit .env file!"

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Hack23/cia at commit bbed538, republished under its Apache-2.0 licence (© Hack23). 517 words, ~5,350 tokens.

Download SKILL.mdSave it as .claude/skills/secrets-management/SKILL.md (or your agent's skills folder).
name
secrets-management
description
Never commit secrets, manage credentials securely using environment variables, vaults, and Hack23 ISMS key management policy
license
Apache-2.0

Secrets Management Skill

Purpose

This skill ensures secure handling of sensitive credentials, API keys, database passwords, and cryptographic keys throughout the CIA platform's development and deployment lifecycle. It enforces zero-tolerance for hardcoded secrets and mandates proper secrets management practices.

When to Use This Skill

Apply this skill when:

  • ✅ Adding new external API integrations (Riksdagen, World Bank)
  • ✅ Configuring database connections
  • ✅ Implementing authentication mechanisms
  • ✅ Setting up CI/CD pipelines
  • ✅ Deploying to new environments
  • ✅ Rotating credentials after security incidents
  • ✅ Reviewing code that handles configuration

Do NOT skip for:

  • ❌ Development/testing credentials (still use proper secrets management)
  • ❌ "Temporary" hardcoded values (they become permanent)
  • ❌ Internal-only APIs (still require proper secrets management)

Golden Rules of Secrets Management

Rule #1: Never Commit Secrets to Git

ABSOLUTELY FORBIDDEN:

java
// ❌ NEVER DO THIS - Hardcoded credentials
public class DatabaseConfig {
    private static final String DB_URL = "jdbc:postgresql://prod-db.example.com:5432/cia";
    private static final String DB_USERNAME = "admin";
    private static final String DB_PASSWORD = "SuperSecret123!"; // SECURITY VIOLATION!
}

// ❌ NEVER DO THIS - API keys in code
public class RiksdagenClient {
    private static final String API_KEY = "sk_live_abc123def456"; // EXPOSED!
}

SECURE ALTERNATIVES:

java
// ✅ CORRECT - Use environment variables
@Configuration
public class DatabaseConfig {
    @Value("${spring.datasource.url}")
    private String dbUrl;
    
    @Value("${spring.datasource.username}")
    private String dbUsername;
    
    @Value("${spring.datasource.password}")
    private String dbPassword;
    
    @Bean
    public DataSource dataSource() {
        HikariConfig config = new HikariConfig();
        config.setJdbcUrl(dbUrl);
        config.setUsername(dbUsername);
        config.setPassword(dbPassword);
        return new HikariDataSource(config);
    }
}

// ✅ CORRECT - API keys from configuration
@Service
public class RiksdagenClient {
    private final String apiKey;
    
    public RiksdagenClient(@Value("${riksdagen.api.key}") String apiKey) {
        this.apiKey = apiKey;
    }
}
Rule #2: Use Environment-Specific Configuration

Application Properties Structure:

src/main/resources/
├── application.yml              # Defaults, no secrets
├── application-dev.yml          # Development config
├── application-test.yml         # Test config
└── application-production.yml   # Production config (secrets from env vars)

application.yml (Safe to commit):

yaml
spring:
  application:
    name: citizen-intelligence-agency
  
  datasource:
    # Values from environment variables
    url: ${DATABASE_URL:jdbc:postgresql://localhost:5432/cia_dev}
    username: ${DATABASE_USERNAME:cia_user}
    password: ${DATABASE_PASSWORD}  # No default for passwords!
    
  jpa:
    hibernate:
      ddl-auto: validate
    show-sql: false

riksdagen:
  api:
    base-url: https://data.riksdagen.se/api
    key: ${RIKSDAGEN_API_KEY}  # Must be provided via environment

worldbank:
  api:
    base-url: https://api.worldbank.org/v2
    key: ${WORLDBANK_API_KEY:}  # Optional, empty default

security:
  jwt:
    secret: ${JWT_SECRET}  # Must be cryptographically random
    expiration: 86400  # 24 hours in seconds

application-production.yml (Also safe):

yaml
spring:
  datasource:
    # Production settings, but actual values from env vars
    hikari:
      maximum-pool-size: 20
      minimum-idle: 5
      connection-timeout: 30000
      
logging:
  level:
    root: WARN
    com.hack23.cia: INFO
  file:
    name: /var/log/cia/application.log
Rule #3: Environment Variables in Deployment

Docker Compose (Development):

yaml
version: '3.8'
services:
  cia-app:
    image: hack23/cia:latest
    environment:
      # Never commit .env file with real secrets
      DATABASE_URL: ${DATABASE_URL}
      DATABASE_USERNAME: ${DATABASE_USERNAME}
      DATABASE_PASSWORD: ${DATABASE_PASSWORD}
      RIKSDAGEN_API_KEY: ${RIKSDAGEN_API_KEY}
      JWT_SECRET: ${JWT_SECRET}
    env_file:
      - .env  # Git-ignored file with secrets

.env.example (Safe to commit as template):

bash
# CIA Application Secrets
# Copy to .env and fill in actual values
# NEVER commit .env file!

DATABASE_URL=jdbc:postgresql://localhost:5432/cia
DATABASE_USERNAME=cia_user
DATABASE_PASSWORD=CHANGE_ME

RIKSDAGEN_API_KEY=your_api_key_here
WORLDBANK_API_KEY=your_api_key_here

JWT_SECRET=generate_with_openssl_rand_base64_64

.gitignore (MUST include):

gitignore
# Secrets and credentials
.env
.env.local
.env.production
*.key
*.pem
*.p12
*.jks
secrets/
credentials/
encrypt.properties

# IDE secrets
.idea/dataSources.xml
.vscode/settings.json
Rule #4: Secrets Rotation Strategy

Quarterly Rotation Schedule:

Q1: Rotate database passwords
Q2: Rotate API keys
Q3: Rotate JWT secrets
Q4: Rotate encryption keys

Rotation Process:

bash
# 1. Generate new secret
NEW_DB_PASSWORD=$(openssl rand -base64 32)

# 2. Update application configuration (zero-downtime)
kubectl set env deployment/cia-app DATABASE_PASSWORD=$NEW_DB_PASSWORD

# 3. Update database
psql -h db.example.com -U admin -c "ALTER USER cia_user PASSWORD '$NEW_DB_PASSWORD';"

# 4. Verify application health
kubectl rollout status deployment/cia-app

# 5. Revoke old secret
# (Keep for 24 hours in case of rollback)

# 6. Document rotation in change log
echo "$(date): Rotated database password" >> /var/log/secrets-rotation.log

Secrets Detection and Prevention

Pre-Commit Hooks

Install git-secrets:

bash
# Install git-secrets
brew install git-secrets  # macOS
# or
sudo apt-get install git-secrets  # Ubuntu

# Setup in repository
cd /path/to/cia
git secrets --install
git secrets --register-aws
git secrets --add 'password\s*=\s*["\'][^"\']{8,}["\']'
git secrets --add 'apikey\s*=\s*["\'][^"\']{16,}["\']'
git secrets --add 'secret\s*=\s*["\'][^"\']{16,}["\']'

Custom Pre-Commit Hook (.git/hooks/pre-commit):

bash
#!/bin/bash

echo "Scanning for secrets..."

# Check for common secret patterns
if git diff --cached | grep -iE '(password|secret|api_?key|token)\s*[:=]\s*["\047][^"\047]{8,}["\047]'; then
    echo "❌ ERROR: Potential secret detected in staged files!"
    echo "Please remove hardcoded secrets and use environment variables."
    exit 1
fi

# Check for specific file types that shouldn't be committed
if git diff --cached --name-only | grep -E '\.(key|pem|p12|jks)$'; then
    echo "❌ ERROR: Attempting to commit key/certificate file!"
    exit 1
fi

# Check for .env files
if git diff --cached --name-only | grep -E '^\.env(\.|$)'; then
    echo "❌ ERROR: Attempting to commit .env file!"
    exit 1
fi

echo "✅ No secrets detected"
exit 0
GitHub Actions Secret Scanning

.github/workflows/secret-scan.yml:

yaml
name: Secret Scanning

on:
  push:
    branches: [ main, develop ]
  pull_request:
    branches: [ main ]

jobs:
  gitleaks:
    name: Gitleaks Secret Scan
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0
      
      - name: Run Gitleaks
        uses: gitleaks/gitleaks-action@v2
        env:
          GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
          GITLEAKS_LICENSE: ${{ secrets.GITLEAKS_LICENSE }}
      
      - name: Upload SARIF report
        if: failure()
        uses: github/codeql-action/upload-sarif@v3
        with:
          sarif_file: results.sarif

  trufflehog:
    name: TruffleHog Secret Scan
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0
      
      - name: TruffleHog Scan
        uses: trufflesecurity/trufflehog@main
        with:
          path: ./
          base: ${{ github.event.repository.default_branch }}
          head: HEAD

Secure Secrets Storage Solutions

Java Integration:

java
@Configuration
public class SecretsManagerConfig {
    
    @Bean
    public SecretsManagerClient secretsManagerClient() {
        return SecretsManagerClient.builder()
            .region(Region.EU_WEST_1)
            .build();
    }
}

@Service
public class SecretsService {
    
    @Autowired
    private SecretsManagerClient secretsManager;
    
    private final Map<String, String> secretsCache = new ConcurrentHashMap<>();
    
    public String getSecret(String secretName) {
        return secretsCache.computeIfAbsent(secretName, this::fetchSecret);
    }
    
    private String fetchSecret(String secretName) {
        GetSecretValueRequest request = GetSecretValueRequest.builder()
            .secretId(secretName)
            .build();
        
        GetSecretValueResponse response = secretsManager.getSecretValue(request);
        return response.secretString();
    }
    
    // Refresh secrets every hour
    @Scheduled(fixedRate = 3600000)
    public void refreshSecrets() {
        secretsCache.clear();
    }
}

@Configuration
public class DatabaseConfigWithSecretsManager {
    
    @Autowired
    private SecretsService secretsService;
    
    @Bean
    public DataSource dataSource() {
        // Fetch database credentials from Secrets Manager
        String dbSecret = secretsService.getSecret("cia/production/database");
        
        // Parse JSON secret
        JSONObject secretJson = new JSONObject(dbSecret);
        String username = secretJson.getString("username");
        String password = secretJson.getString("password");
        String host = secretJson.getString("host");
        
        HikariConfig config = new HikariConfig();
        config.setJdbcUrl("jdbc:postgresql://" + host + ":5432/cia");
        config.setUsername(username);
        config.setPassword(password);
        
        return new HikariDataSource(config);
    }
}

Create Secret in AWS:

bash
# Create database credentials secret
aws secretsmanager create-secret \
    --name cia/production/database \
    --description "CIA Production Database Credentials" \
    --secret-string '{
        "username": "cia_prod_user",
        "password": "GeneratedSecurePassword123!",
        "host": "cia-prod-db.xyz.eu-west-1.rds.amazonaws.com",
        "port": "5432",
        "database": "cia_production"
    }'

# Grant application IAM role access
aws secretsmanager put-resource-policy \
    --secret-id cia/production/database \
    --resource-policy '{
        "Version": "2012-10-17",
        "Statement": [{
            "Effect": "Allow",
            "Principal": {"AWS": "arn:aws:iam::123456789:role/cia-app-role"},
            "Action": "secretsmanager:GetSecretValue",
            "Resource": "*"
        }]
    }'
HashiCorp Vault (Alternative)

Java Integration:

java
@Configuration
public class VaultConfig {
    
    @Bean
    public VaultTemplate vaultTemplate() {
        VaultEndpoint endpoint = VaultEndpoint.create("vault.example.com", 8200);
        
        // Use token authentication (token from environment)
        TokenAuthentication authentication = new TokenAuthentication(
            System.getenv("VAULT_TOKEN")
        );
        
        SslConfiguration ssl = SslConfiguration.forTrustStore(
            KeyStore.getInstance("PKCS12"),
            "changeit".toCharArray()
        );
        
        return new VaultTemplate(endpoint, 
            new ClientHttpRequestFactoryFactory().create(
                new ClientOptions(), ssl),
            authentication);
    }
}

@Service
public class VaultSecretsService {
    
    @Autowired
    private VaultTemplate vaultTemplate;
    
    public String getDatabasePassword() {
        VaultResponse response = vaultTemplate
            .read("secret/data/cia/production/database");
        
        return (String) response.getData().get("password");
    }
    
    public Map<String, String> getRiksdagenApiConfig() {
        VaultResponse response = vaultTemplate
            .read("secret/data/cia/apis/riksdagen");
        
        return response.getData();
    }
}
Spring Cloud Config Server (Encrypted Properties)

Config Server Setup:

yaml
# bootstrap.yml
spring:
  cloud:
    config:
      server:
        git:
          uri: https://github.com/Hack23/cia-config
          search-paths: '{application}'
        encrypt:
          enabled: true
          
encrypt:
  key: ${CONFIG_SERVER_ENCRYPTION_KEY}

Encrypted Properties:

yaml
# cia-production.yml in config repo
spring:
  datasource:
    password: '{cipher}AQICAHhwKp7VkJJJJ...'  # Encrypted with config server key
    
riksdagen:
  api:
    key: '{cipher}AQICAHhwKp7VkJJJJ...'

Encrypt secrets:

bash
# Encrypt a secret
curl -X POST http://config-server:8888/encrypt \
    -H "Content-Type: text/plain" \
    --data-binary "MySecretPassword123"

# Output: AQICAHhwKp7VkJJJJ...

Cryptographic Key Management

JWT Signing Keys

Key Generation:

bash
# Generate RS256 key pair for JWT signing
openssl genrsa -out jwt_private.pem 4096
openssl rsa -in jwt_private.pem -pubout -out jwt_public.pem

# Store private key in secrets manager
aws secretsmanager create-secret \
    --name cia/jwt/private-key \
    --secret-binary fileb://jwt_private.pem

# Public key can be stored in application resources
cp jwt_public.pem src/main/resources/jwt-public.pem

# Securely delete local copies
shred -u jwt_private.pem

JWT Configuration:

java
@Configuration
public class JwtConfig {
    
    @Autowired
    private SecretsService secretsService;
    
    @Bean
    public PrivateKey jwtPrivateKey() throws Exception {
        String privateKeyPEM = secretsService.getSecret("cia/jwt/private-key");
        
        privateKeyPEM = privateKeyPEM
            .replace("-----BEGIN PRIVATE KEY-----", "")
            .replace("-----END PRIVATE KEY-----", "")
            .replaceAll("\\s", "");
        
        byte[] encoded = Base64.getDecoder().decode(privateKeyPEM);
        
        PKCS8EncodedKeySpec keySpec = new PKCS8EncodedKeySpec(encoded);
        KeyFactory keyFactory = KeyFactory.getInstance("RSA");
        
        return keyFactory.generatePrivate(keySpec);
    }
    
    @Bean
    public PublicKey jwtPublicKey() throws Exception {
        // Public key from classpath (safe to commit)
        Resource resource = new ClassPathResource("jwt-public.pem");
        String publicKeyPEM = IOUtils.toString(resource.getInputStream(), StandardCharsets.UTF_8);
        
        publicKeyPEM = publicKeyPEM
            .replace("-----BEGIN PUBLIC KEY-----", "")
            .replace("-----END PUBLIC KEY-----", "")
            .replaceAll("\\s", "");
        
        byte[] encoded = Base64.getDecoder().decode(publicKeyPEM);
        
        X509EncodedKeySpec keySpec = new X509EncodedKeySpec(encoded);
        KeyFactory keyFactory = KeyFactory.getInstance("RSA");
        
        return keyFactory.generatePublic(keySpec);
    }
}
Database Encryption Keys

PostgreSQL TDE (Transparent Data Encryption):

bash
# Generate encryption key
openssl rand -base64 32 > /secure/location/database-encryption-key

# Configure PostgreSQL
echo "ssl = on" >> postgresql.conf
echo "ssl_cert_file = '/etc/ssl/certs/server.crt'" >> postgresql.conf
echo "ssl_key_file = '/secure/location/server.key'" >> postgresql.conf

# Encrypt specific columns with pgcrypto
psql -d cia -c "CREATE EXTENSION IF NOT EXISTS pgcrypto;"

Application-Level Encryption:

java
@Configuration
public class EncryptionConfig {
    
    @Bean
    public BytesEncryptor fieldEncryptor() {
        String encryptionKey = System.getenv("FIELD_ENCRYPTION_KEY");
        String salt = System.getenv("FIELD_ENCRYPTION_SALT");
        
        return Encryptors.standard(encryptionKey, salt);
    }
}

@Entity
public class Politician {
    
    @Id
    private String id;
    
    private String firstName;
    
    private String lastName;
    
    // Encrypted field
    @Column(name = "personal_id_encrypted")
    private byte[] personalIdEncrypted;
    
    @Autowired
    @Transient
    private BytesEncryptor encryptor;
    
    @Transient
    public String getPersonalId() {
        if (personalIdEncrypted == null) return null;
        return new String(encryptor.decrypt(personalIdEncrypted));
    }
    
    public void setPersonalId(String personalId) {
        if (personalId == null) {
            this.personalIdEncrypted = null;
        } else {
            this.personalIdEncrypted = encryptor.encrypt(personalId.getBytes());
        }
    }
}

Secrets Incident Response

If Secret Compromised:

Immediate Actions (Within 1 Hour):

  1. ✅ Rotate the compromised secret immediately
  2. ✅ Revoke old secret/key from all systems
  3. ✅ Review access logs for unauthorized access
  4. ✅ Notify security team and stakeholders
  5. ✅ Document incident in security log

Investigation (Within 24 Hours):

  1. ✅ Determine how secret was exposed
  2. ✅ Identify all systems that used the secret
  3. ✅ Check for signs of unauthorized access
  4. ✅ Review code repository history
  5. ✅ Update detection mechanisms

Remediation (Within 1 Week):

  1. ✅ Implement additional controls to prevent recurrence
  2. ✅ Update security documentation
  3. ✅ Conduct team training on secrets management
  4. ✅ Add monitoring/alerting for similar incidents
  5. ✅ Complete incident report

Incident Response Script:

bash
#!/bin/bash
# secrets-incident-response.sh

SECRET_TYPE=$1  # e.g., "database-password", "api-key"
INCIDENT_ID=$(date +%Y%m%d-%H%M%S)

echo "=== Secrets Incident Response ==="
echo "Incident ID: $INCIDENT_ID"
echo "Secret Type: $SECRET_TYPE"
echo "Started: $(date)"

# 1. Generate new secret
echo "Generating new secret..."
NEW_SECRET=$(openssl rand -base64 32)

# 2. Update Secrets Manager
echo "Updating Secrets Manager..."
aws secretsmanager update-secret \
    --secret-id "cia/production/$SECRET_TYPE" \
    --secret-string "$NEW_SECRET"

# 3. Rotate in application
echo "Rotating in application..."
kubectl set env deployment/cia-app "${SECRET_TYPE^^}"="$NEW_SECRET"

# 4. Verify health
echo "Verifying application health..."
kubectl wait --for=condition=available --timeout=300s deployment/cia-app

# 5. Log incident
echo "Logging incident..."
echo "[$INCIDENT_ID] Rotated $SECRET_TYPE due to compromise" >> /var/log/security-incidents.log

# 6. Notify team
echo "Notifying security team..."
# (Send notification via email/Slack/PagerDuty)

echo "=== Incident Response Complete ==="
echo "Completed: $(date)"
Show full SKILL.md (171 more words)Show less

ISMS Compliance Mapping

ISO 27001:2022 Controls
  • A.8.4 - Access to Source Code: Secrets not in source code
  • A.8.11 - Data Masking: Secrets masked in logs
  • A.8.24 - Use of Cryptography: Keys managed securely
  • A.5.17 - Authentication Information: Credentials protected
NIST Cybersecurity Framework
  • PR.AC-1: Credentials managed and protected
  • PR.DS-5: Protections against data leaks
  • PR.MA-2: Remote maintenance authenticated
CIS Controls v8
  • Control 3.3: Protect recovery data
  • Control 3.11: Encrypt sensitive data at rest
  • Control 4.7: Manage credentials

Hack23 ISMS Policy References

Secrets & Key Management Framework:

All Hack23 ISMS Policies: https://github.com/Hack23/ISMS-PUBLIC

CIA Platform Architecture References

References

Standards & Guidelines
Tools & Services

© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/secrets-management of Hack23/cia.

Open the folder on GitHubat commit bbed538

Compare with similar skills

Secrets Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secrets Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secrets Management this skillHack23/cia239—~5.3kAutomated safety check: NotesApache-2.0
Secrets GitleaksAgentSecOps/SecOpsAgentKit2202 repos~4.1kAutomated safety check: PassCustom licence
Hashicorp VaultBagelHole/DevOps-Security-Agent-Skills1.1k—~2kAutomated safety check: PassMIT
Network Proxydidi/mpx3.9k—~464Automated safety check: PassApache-2.0
Private Secret Scanningjamditis/claude-skills-journalism416—~1.8kAutomated safety check: PassMIT
KubeSphere DevOps Credentialskubesphere/kubesphere17k—~4.2kAutomated safety check: PassCustom licence

Similar skills

  • Secrets Gitleaks

    AgentSecOps/SecOpsAgentKit

    Hardcoded secret detection and prevention in git repositories and codebases using Gitleaks.

    220 GitHub starsUsed in 2 repos~4.1k tokens
    DevOps & CloudAuto-check passed
  • Hashicorp Vault

    BagelHole/DevOps-Security-Agent-Skills

    Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.1k GitHub stars~2k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed
  • Helps when network-related commands (like curl, git, npm, pip, brew) are failing, timing out, or running slowly due to network issues.

    3.9k GitHub stars~464 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Private Secret Scanning

    jamditis/claude-skills-journalism

    Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports.

    416 GitHub stars~1.8k tokensUpdated 3 days ago
    DevOps & CloudAuto-check passed
  • KubeSphere DevOps Credentials

    kubesphere/kubesphere

    Covers creating and managing KubeSphere DevOps credentials as typed Kubernetes Secrets that sync to Jenkins, including the API endpoints and a common pitfall.

    17k GitHub stars~4.2k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Dotenvx Secrets

    kortix-ai/suna

    How this repo manages API secrets and the four local-run environments (local/dev/staging/prod).

    20k GitHub stars~4.2k tokensUpdated today
    DevOps & CloudAuto-check: notes

More from Hack23/cia

All 78 skills in this repo
  • WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms

    239 GitHub stars~2.7k tokensUpdated today
    Auto-check passed
  • Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis

    239 GitHub stars~1.5k tokensUpdated today
    Auto-check passed
  • AI Governance

    Hack23/cia

    AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents

    239 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • API Integration

    Hack23/cia

    External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform

    239 GitHub stars~1.9k tokensUpdated today
    Auto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Secrets Management

What does Secrets Management do?

Never commit secrets, manage credentials securely using environment variables, vaults, and Hack23 ISMS key management policy. Secrets Management is an agent skill from Hack23/cia.

When should I use Secrets Management?

Secrets Management fits situations like: tasks that involve Secrets management; tasks that involve Cryptography.

How do I install Secrets Management in Claude Code?

Run `npx skills add Hack23/cia --skill secrets-management -a claude-code`. Or copy the skill folder (.github/skills/secrets-management in Hack23/cia) into .claude/skills/secrets-management in your project. Claude Code loads it when a task matches its description.

How do I install Secrets Management in Codex?

Run `npx skills add Hack23/cia --skill secrets-management -a codex`. Or copy the skill folder (.github/skills/secrets-management in Hack23/cia) into .agents/skills/secrets-management in your project. Codex loads it when a task matches its description.

Can I use Secrets Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill secrets-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secrets-management, .gemini/skills/secrets-management, .github/skills/secrets-management and .opencode/skills/secrets-management in your project.

What does Secrets Management need to run?

Going by SKILL.md and its folder, Secrets Management needs the command-line tools its instructions call (openssl, git, kubectl, aws, psql and brew) and credentials named DATABASE_PASSWORD, RIKSDAGEN_API_KEY, JWT_SECRET and NEW_DB_PASSWORD. Our summary lists: Docker; A credential in API_KEY; A credential in RIKSDAGEN_API_KEY.

Does Secrets Management access the network?

SKILL.md names 8 domains. In commands or code: github.com, data.riksdagen.se and api.worldbank.org; the agent is likely to contact these when it follows the instructions. As links in the text: cheatsheetseries.owasp.org, csrc.nist.gov, aws.amazon.com, vaultproject.io and spring.io. This is read from the text; nothing was executed.

Is Secrets Management safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Secrets Management use?

Secrets Management is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Secrets Management use?

About 5.3k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Secrets Management?

Skills that share tags, products or a category with Secrets Management: Secrets Gitleaks (AgentSecOps/SecOpsAgentKit, 220 stars), Hashicorp Vault (BagelHole/DevOps-Security-Agent-Skills, 1.1k stars), Network Proxy (didi/mpx, 3.9k stars) and Private Secret Scanning (jamditis/claude-skills-journalism, 416 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secrets Management?

Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 7, 2026.

Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.