Secrets Gitleaks
AgentSecOps/SecOpsAgentKit
Hardcoded secret detection and prevention in git repositories and codebases using Gitleaks.
Never commit secrets, manage credentials securely using environment variables, vaults, and Hack23 ISMS key management policy
$ npx skills add Hack23/cia --skill secrets-management -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install Hack23/cia secrets-management --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/secrets-management .claude/skills/secrets-management && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "secrets-management" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/secrets-management into .claude/skills/secrets-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-management", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/Hack23/cia/tree/master/.github/skills/secrets-managementType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add Hack23/cia --skill secrets-management -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install Hack23/cia secrets-management --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.github/skills/secrets-management .agents/skills/secrets-management && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "secrets-management" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/secrets-management into .agents/skills/secrets-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-management", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Hack23/cia --skill secrets-management -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install Hack23/cia secrets-management --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.github/skills/secrets-management .cursor/skills/secrets-management && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "secrets-management" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/secrets-management into .cursor/skills/secrets-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-management", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/Hack23/cia.git --path .github/skills/secrets-management--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add Hack23/cia --skill secrets-management -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install Hack23/cia secrets-management --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.github/skills/secrets-management .gemini/skills/secrets-management && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "secrets-management" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/secrets-management into .gemini/skills/secrets-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-management", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install Hack23/cia secrets-managementInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add Hack23/cia --skill secrets-management -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .github/skills && cp -r skills-src/.github/skills/secrets-management .github/skills/secrets-management && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "secrets-management" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/secrets-management into .github/skills/secrets-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-management", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add Hack23/cia --skill secrets-management -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install Hack23/cia secrets-management --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/Hack23/cia.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.github/skills/secrets-management .opencode/skills/secrets-management && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "secrets-management" agent skill from https://github.com/Hack23/cia/tree/master/.github/skills/secrets-management into .opencode/skills/secrets-management/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-management", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
secrets-managementNever commit secrets, manage credentials securely using environment variables, vaults, and Hack23 ISMS key management policy
Secrets Management is an agent skill from Hack23/cia. Never commit secrets, manage credentials securely using environment variables, vaults, and Hack23 ISMS key management policy
Its SKILL.md is about 5.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in DevOps & Cloud, covering Secrets management and Cryptography. It works with Git. The repository describes itself as: Citizen Intelligence Agency. Open-source intelligence platform analyzing Swedish political activities using AI and data visualization. Tracks politicians, government… The licence is Apache-2.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit bbed538. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
opensslgitkubectlawspsqlbrewapt-getcurlFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
github.comdata.riksdagen.seapi.worldbank.orgAlso links to:
cheatsheetseries.owasp.orgcsrc.nist.govaws.amazon.comvaultproject.iospring.ioFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
DATABASE_PASSWORDRIKSDAGEN_API_KEYJWT_SECRETNEW_DB_PASSWORDNEW_SECRETWORLDBANK_API_KEYGITHUB_TOKENDB_PASSWORDAPI_KEYVAULT_TOKENCONFIG_SERVER_ENCRYPTION_KEYFIELD_ENCRYPTION_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Secrets Management loads about 5.3k tokens when it runs. Until then it costs about 36 tokens; SKILL.md has 517 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
# Never commit .env file with real secrets- .env # Git-ignored file with secrets# Copy to .env and fill in actual values# NEVER commit .env file!.env.env.local.env.productionsudo apt-get install git-secrets # Ubuntu# Check for .env filesecho "❌ ERROR: Attempting to commit .env file!"Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from Hack23/cia at commit bbed538, republished under its Apache-2.0 licence (© Hack23). 517 words, ~5,350 tokens.
.claude/skills/secrets-management/SKILL.md (or your agent's skills folder).This skill ensures secure handling of sensitive credentials, API keys, database passwords, and cryptographic keys throughout the CIA platform's development and deployment lifecycle. It enforces zero-tolerance for hardcoded secrets and mandates proper secrets management practices.
Apply this skill when:
Do NOT skip for:
ABSOLUTELY FORBIDDEN:
// ❌ NEVER DO THIS - Hardcoded credentials
public class DatabaseConfig {
private static final String DB_URL = "jdbc:postgresql://prod-db.example.com:5432/cia";
private static final String DB_USERNAME = "admin";
private static final String DB_PASSWORD = "SuperSecret123!"; // SECURITY VIOLATION!
}
// ❌ NEVER DO THIS - API keys in code
public class RiksdagenClient {
private static final String API_KEY = "sk_live_abc123def456"; // EXPOSED!
}SECURE ALTERNATIVES:
// ✅ CORRECT - Use environment variables
@Configuration
public class DatabaseConfig {
@Value("${spring.datasource.url}")
private String dbUrl;
@Value("${spring.datasource.username}")
private String dbUsername;
@Value("${spring.datasource.password}")
private String dbPassword;
@Bean
public DataSource dataSource() {
HikariConfig config = new HikariConfig();
config.setJdbcUrl(dbUrl);
config.setUsername(dbUsername);
config.setPassword(dbPassword);
return new HikariDataSource(config);
}
}
// ✅ CORRECT - API keys from configuration
@Service
public class RiksdagenClient {
private final String apiKey;
public RiksdagenClient(@Value("${riksdagen.api.key}") String apiKey) {
this.apiKey = apiKey;
}
}Application Properties Structure:
src/main/resources/
├── application.yml # Defaults, no secrets
├── application-dev.yml # Development config
├── application-test.yml # Test config
└── application-production.yml # Production config (secrets from env vars)application.yml (Safe to commit):
spring:
application:
name: citizen-intelligence-agency
datasource:
# Values from environment variables
url: ${DATABASE_URL:jdbc:postgresql://localhost:5432/cia_dev}
username: ${DATABASE_USERNAME:cia_user}
password: ${DATABASE_PASSWORD} # No default for passwords!
jpa:
hibernate:
ddl-auto: validate
show-sql: false
riksdagen:
api:
base-url: https://data.riksdagen.se/api
key: ${RIKSDAGEN_API_KEY} # Must be provided via environment
worldbank:
api:
base-url: https://api.worldbank.org/v2
key: ${WORLDBANK_API_KEY:} # Optional, empty default
security:
jwt:
secret: ${JWT_SECRET} # Must be cryptographically random
expiration: 86400 # 24 hours in secondsapplication-production.yml (Also safe):
spring:
datasource:
# Production settings, but actual values from env vars
hikari:
maximum-pool-size: 20
minimum-idle: 5
connection-timeout: 30000
logging:
level:
root: WARN
com.hack23.cia: INFO
file:
name: /var/log/cia/application.logDocker Compose (Development):
version: '3.8'
services:
cia-app:
image: hack23/cia:latest
environment:
# Never commit .env file with real secrets
DATABASE_URL: ${DATABASE_URL}
DATABASE_USERNAME: ${DATABASE_USERNAME}
DATABASE_PASSWORD: ${DATABASE_PASSWORD}
RIKSDAGEN_API_KEY: ${RIKSDAGEN_API_KEY}
JWT_SECRET: ${JWT_SECRET}
env_file:
- .env # Git-ignored file with secrets.env.example (Safe to commit as template):
# CIA Application Secrets
# Copy to .env and fill in actual values
# NEVER commit .env file!
DATABASE_URL=jdbc:postgresql://localhost:5432/cia
DATABASE_USERNAME=cia_user
DATABASE_PASSWORD=CHANGE_ME
RIKSDAGEN_API_KEY=your_api_key_here
WORLDBANK_API_KEY=your_api_key_here
JWT_SECRET=generate_with_openssl_rand_base64_64.gitignore (MUST include):
# Secrets and credentials
.env
.env.local
.env.production
*.key
*.pem
*.p12
*.jks
secrets/
credentials/
encrypt.properties
# IDE secrets
.idea/dataSources.xml
.vscode/settings.jsonQuarterly Rotation Schedule:
Q1: Rotate database passwords
Q2: Rotate API keys
Q3: Rotate JWT secrets
Q4: Rotate encryption keysRotation Process:
# 1. Generate new secret
NEW_DB_PASSWORD=$(openssl rand -base64 32)
# 2. Update application configuration (zero-downtime)
kubectl set env deployment/cia-app DATABASE_PASSWORD=$NEW_DB_PASSWORD
# 3. Update database
psql -h db.example.com -U admin -c "ALTER USER cia_user PASSWORD '$NEW_DB_PASSWORD';"
# 4. Verify application health
kubectl rollout status deployment/cia-app
# 5. Revoke old secret
# (Keep for 24 hours in case of rollback)
# 6. Document rotation in change log
echo "$(date): Rotated database password" >> /var/log/secrets-rotation.logInstall git-secrets:
# Install git-secrets
brew install git-secrets # macOS
# or
sudo apt-get install git-secrets # Ubuntu
# Setup in repository
cd /path/to/cia
git secrets --install
git secrets --register-aws
git secrets --add 'password\s*=\s*["\'][^"\']{8,}["\']'
git secrets --add 'apikey\s*=\s*["\'][^"\']{16,}["\']'
git secrets --add 'secret\s*=\s*["\'][^"\']{16,}["\']'Custom Pre-Commit Hook (.git/hooks/pre-commit):
#!/bin/bash
echo "Scanning for secrets..."
# Check for common secret patterns
if git diff --cached | grep -iE '(password|secret|api_?key|token)\s*[:=]\s*["\047][^"\047]{8,}["\047]'; then
echo "❌ ERROR: Potential secret detected in staged files!"
echo "Please remove hardcoded secrets and use environment variables."
exit 1
fi
# Check for specific file types that shouldn't be committed
if git diff --cached --name-only | grep -E '\.(key|pem|p12|jks)$'; then
echo "❌ ERROR: Attempting to commit key/certificate file!"
exit 1
fi
# Check for .env files
if git diff --cached --name-only | grep -E '^\.env(\.|$)'; then
echo "❌ ERROR: Attempting to commit .env file!"
exit 1
fi
echo "✅ No secrets detected"
exit 0.github/workflows/secret-scan.yml:
name: Secret Scanning
on:
push:
branches: [ main, develop ]
pull_request:
branches: [ main ]
jobs:
gitleaks:
name: Gitleaks Secret Scan
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: Run Gitleaks
uses: gitleaks/gitleaks-action@v2
env:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
GITLEAKS_LICENSE: ${{ secrets.GITLEAKS_LICENSE }}
- name: Upload SARIF report
if: failure()
uses: github/codeql-action/upload-sarif@v3
with:
sarif_file: results.sarif
trufflehog:
name: TruffleHog Secret Scan
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
with:
fetch-depth: 0
- name: TruffleHog Scan
uses: trufflesecurity/trufflehog@main
with:
path: ./
base: ${{ github.event.repository.default_branch }}
head: HEADJava Integration:
@Configuration
public class SecretsManagerConfig {
@Bean
public SecretsManagerClient secretsManagerClient() {
return SecretsManagerClient.builder()
.region(Region.EU_WEST_1)
.build();
}
}
@Service
public class SecretsService {
@Autowired
private SecretsManagerClient secretsManager;
private final Map<String, String> secretsCache = new ConcurrentHashMap<>();
public String getSecret(String secretName) {
return secretsCache.computeIfAbsent(secretName, this::fetchSecret);
}
private String fetchSecret(String secretName) {
GetSecretValueRequest request = GetSecretValueRequest.builder()
.secretId(secretName)
.build();
GetSecretValueResponse response = secretsManager.getSecretValue(request);
return response.secretString();
}
// Refresh secrets every hour
@Scheduled(fixedRate = 3600000)
public void refreshSecrets() {
secretsCache.clear();
}
}
@Configuration
public class DatabaseConfigWithSecretsManager {
@Autowired
private SecretsService secretsService;
@Bean
public DataSource dataSource() {
// Fetch database credentials from Secrets Manager
String dbSecret = secretsService.getSecret("cia/production/database");
// Parse JSON secret
JSONObject secretJson = new JSONObject(dbSecret);
String username = secretJson.getString("username");
String password = secretJson.getString("password");
String host = secretJson.getString("host");
HikariConfig config = new HikariConfig();
config.setJdbcUrl("jdbc:postgresql://" + host + ":5432/cia");
config.setUsername(username);
config.setPassword(password);
return new HikariDataSource(config);
}
}Create Secret in AWS:
# Create database credentials secret
aws secretsmanager create-secret \
--name cia/production/database \
--description "CIA Production Database Credentials" \
--secret-string '{
"username": "cia_prod_user",
"password": "GeneratedSecurePassword123!",
"host": "cia-prod-db.xyz.eu-west-1.rds.amazonaws.com",
"port": "5432",
"database": "cia_production"
}'
# Grant application IAM role access
aws secretsmanager put-resource-policy \
--secret-id cia/production/database \
--resource-policy '{
"Version": "2012-10-17",
"Statement": [{
"Effect": "Allow",
"Principal": {"AWS": "arn:aws:iam::123456789:role/cia-app-role"},
"Action": "secretsmanager:GetSecretValue",
"Resource": "*"
}]
}'Java Integration:
@Configuration
public class VaultConfig {
@Bean
public VaultTemplate vaultTemplate() {
VaultEndpoint endpoint = VaultEndpoint.create("vault.example.com", 8200);
// Use token authentication (token from environment)
TokenAuthentication authentication = new TokenAuthentication(
System.getenv("VAULT_TOKEN")
);
SslConfiguration ssl = SslConfiguration.forTrustStore(
KeyStore.getInstance("PKCS12"),
"changeit".toCharArray()
);
return new VaultTemplate(endpoint,
new ClientHttpRequestFactoryFactory().create(
new ClientOptions(), ssl),
authentication);
}
}
@Service
public class VaultSecretsService {
@Autowired
private VaultTemplate vaultTemplate;
public String getDatabasePassword() {
VaultResponse response = vaultTemplate
.read("secret/data/cia/production/database");
return (String) response.getData().get("password");
}
public Map<String, String> getRiksdagenApiConfig() {
VaultResponse response = vaultTemplate
.read("secret/data/cia/apis/riksdagen");
return response.getData();
}
}Config Server Setup:
# bootstrap.yml
spring:
cloud:
config:
server:
git:
uri: https://github.com/Hack23/cia-config
search-paths: '{application}'
encrypt:
enabled: true
encrypt:
key: ${CONFIG_SERVER_ENCRYPTION_KEY}Encrypted Properties:
# cia-production.yml in config repo
spring:
datasource:
password: '{cipher}AQICAHhwKp7VkJJJJ...' # Encrypted with config server key
riksdagen:
api:
key: '{cipher}AQICAHhwKp7VkJJJJ...'Encrypt secrets:
# Encrypt a secret
curl -X POST http://config-server:8888/encrypt \
-H "Content-Type: text/plain" \
--data-binary "MySecretPassword123"
# Output: AQICAHhwKp7VkJJJJ...Key Generation:
# Generate RS256 key pair for JWT signing
openssl genrsa -out jwt_private.pem 4096
openssl rsa -in jwt_private.pem -pubout -out jwt_public.pem
# Store private key in secrets manager
aws secretsmanager create-secret \
--name cia/jwt/private-key \
--secret-binary fileb://jwt_private.pem
# Public key can be stored in application resources
cp jwt_public.pem src/main/resources/jwt-public.pem
# Securely delete local copies
shred -u jwt_private.pemJWT Configuration:
@Configuration
public class JwtConfig {
@Autowired
private SecretsService secretsService;
@Bean
public PrivateKey jwtPrivateKey() throws Exception {
String privateKeyPEM = secretsService.getSecret("cia/jwt/private-key");
privateKeyPEM = privateKeyPEM
.replace("-----BEGIN PRIVATE KEY-----", "")
.replace("-----END PRIVATE KEY-----", "")
.replaceAll("\\s", "");
byte[] encoded = Base64.getDecoder().decode(privateKeyPEM);
PKCS8EncodedKeySpec keySpec = new PKCS8EncodedKeySpec(encoded);
KeyFactory keyFactory = KeyFactory.getInstance("RSA");
return keyFactory.generatePrivate(keySpec);
}
@Bean
public PublicKey jwtPublicKey() throws Exception {
// Public key from classpath (safe to commit)
Resource resource = new ClassPathResource("jwt-public.pem");
String publicKeyPEM = IOUtils.toString(resource.getInputStream(), StandardCharsets.UTF_8);
publicKeyPEM = publicKeyPEM
.replace("-----BEGIN PUBLIC KEY-----", "")
.replace("-----END PUBLIC KEY-----", "")
.replaceAll("\\s", "");
byte[] encoded = Base64.getDecoder().decode(publicKeyPEM);
X509EncodedKeySpec keySpec = new X509EncodedKeySpec(encoded);
KeyFactory keyFactory = KeyFactory.getInstance("RSA");
return keyFactory.generatePublic(keySpec);
}
}PostgreSQL TDE (Transparent Data Encryption):
# Generate encryption key
openssl rand -base64 32 > /secure/location/database-encryption-key
# Configure PostgreSQL
echo "ssl = on" >> postgresql.conf
echo "ssl_cert_file = '/etc/ssl/certs/server.crt'" >> postgresql.conf
echo "ssl_key_file = '/secure/location/server.key'" >> postgresql.conf
# Encrypt specific columns with pgcrypto
psql -d cia -c "CREATE EXTENSION IF NOT EXISTS pgcrypto;"Application-Level Encryption:
@Configuration
public class EncryptionConfig {
@Bean
public BytesEncryptor fieldEncryptor() {
String encryptionKey = System.getenv("FIELD_ENCRYPTION_KEY");
String salt = System.getenv("FIELD_ENCRYPTION_SALT");
return Encryptors.standard(encryptionKey, salt);
}
}
@Entity
public class Politician {
@Id
private String id;
private String firstName;
private String lastName;
// Encrypted field
@Column(name = "personal_id_encrypted")
private byte[] personalIdEncrypted;
@Autowired
@Transient
private BytesEncryptor encryptor;
@Transient
public String getPersonalId() {
if (personalIdEncrypted == null) return null;
return new String(encryptor.decrypt(personalIdEncrypted));
}
public void setPersonalId(String personalId) {
if (personalId == null) {
this.personalIdEncrypted = null;
} else {
this.personalIdEncrypted = encryptor.encrypt(personalId.getBytes());
}
}
}Immediate Actions (Within 1 Hour):
Investigation (Within 24 Hours):
Remediation (Within 1 Week):
Incident Response Script:
#!/bin/bash
# secrets-incident-response.sh
SECRET_TYPE=$1 # e.g., "database-password", "api-key"
INCIDENT_ID=$(date +%Y%m%d-%H%M%S)
echo "=== Secrets Incident Response ==="
echo "Incident ID: $INCIDENT_ID"
echo "Secret Type: $SECRET_TYPE"
echo "Started: $(date)"
# 1. Generate new secret
echo "Generating new secret..."
NEW_SECRET=$(openssl rand -base64 32)
# 2. Update Secrets Manager
echo "Updating Secrets Manager..."
aws secretsmanager update-secret \
--secret-id "cia/production/$SECRET_TYPE" \
--secret-string "$NEW_SECRET"
# 3. Rotate in application
echo "Rotating in application..."
kubectl set env deployment/cia-app "${SECRET_TYPE^^}"="$NEW_SECRET"
# 4. Verify health
echo "Verifying application health..."
kubectl wait --for=condition=available --timeout=300s deployment/cia-app
# 5. Log incident
echo "Logging incident..."
echo "[$INCIDENT_ID] Rotated $SECRET_TYPE due to compromise" >> /var/log/security-incidents.log
# 6. Notify team
echo "Notifying security team..."
# (Send notification via email/Slack/PagerDuty)
echo "=== Incident Response Complete ==="
echo "Completed: $(date)"Secrets & Key Management Framework:
All Hack23 ISMS Policies: https://github.com/Hack23/ISMS-PUBLIC
© Hack23, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .github/skills/secrets-management of Hack23/cia.
Open the folder on GitHubat commit bbed538
Secrets Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Secrets Management this skillHack23/cia | 239 | — | ~5.3k | Automated safety check: Notes | Apache-2.0 | |
| Secrets GitleaksAgentSecOps/SecOpsAgentKit | 220 | 2 repos | ~4.1k | Automated safety check: Pass | Custom licence | |
| Hashicorp VaultBagelHole/DevOps-Security-Agent-Skills | 1.1k | — | ~2k | Automated safety check: Pass | MIT | |
| Network Proxydidi/mpx | 3.9k | — | ~464 | Automated safety check: Pass | Apache-2.0 | |
| Private Secret Scanningjamditis/claude-skills-journalism | 416 | — | ~1.8k | Automated safety check: Pass | MIT | |
| KubeSphere DevOps Credentialskubesphere/kubesphere | 17k | — | ~4.2k | Automated safety check: Pass | Custom licence |
AgentSecOps/SecOpsAgentKit
Hardcoded secret detection and prevention in git repositories and codebases using Gitleaks.
BagelHole/DevOps-Security-Agent-Skills
Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.
didi/mpx
Helps when network-related commands (like curl, git, npm, pip, brew) are failing, timing out, or running slowly due to network issues.
jamditis/claude-skills-journalism
Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports.
kubesphere/kubesphere
Covers creating and managing KubeSphere DevOps credentials as typed Kubernetes Secrets that sync to Jenkins, including the API endpoints and a common pitfall.
kortix-ai/suna
How this repo manages API secrets and the four local-run environments (local/dev/staging/prod).
Hack23/cia
WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms
Hack23/cia
Advanced chart types, D3.js/Vaadin Charts patterns, political data visualization, time series analysis
Hack23/cia
AI governance, EU AI Act compliance, OWASP LLM security, responsible AI practices for GitHub Copilot agents
Hack23/cia
External API integration patterns, retry logic, circuit breakers, caching, rate limiting for government data APIs
Hack23/cia
AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform
Hack23/cia
AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment
Works with
Categories
Never commit secrets, manage credentials securely using environment variables, vaults, and Hack23 ISMS key management policy. Secrets Management is an agent skill from Hack23/cia.
Secrets Management fits situations like: tasks that involve Secrets management; tasks that involve Cryptography.
Run `npx skills add Hack23/cia --skill secrets-management -a claude-code`. Or copy the skill folder (.github/skills/secrets-management in Hack23/cia) into .claude/skills/secrets-management in your project. Claude Code loads it when a task matches its description.
Run `npx skills add Hack23/cia --skill secrets-management -a codex`. Or copy the skill folder (.github/skills/secrets-management in Hack23/cia) into .agents/skills/secrets-management in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Hack23/cia --skill secrets-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secrets-management, .gemini/skills/secrets-management, .github/skills/secrets-management and .opencode/skills/secrets-management in your project.
Going by SKILL.md and its folder, Secrets Management needs the command-line tools its instructions call (openssl, git, kubectl, aws, psql and brew) and credentials named DATABASE_PASSWORD, RIKSDAGEN_API_KEY, JWT_SECRET and NEW_DB_PASSWORD. Our summary lists: Docker; A credential in API_KEY; A credential in RIKSDAGEN_API_KEY.
SKILL.md names 8 domains. In commands or code: github.com, data.riksdagen.se and api.worldbank.org; the agent is likely to contact these when it follows the instructions. As links in the text: cheatsheetseries.owasp.org, csrc.nist.gov, aws.amazon.com, vaultproject.io and spring.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file; runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Secrets Management is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 5.3k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Secrets Management: Secrets Gitleaks (AgentSecOps/SecOpsAgentKit, 220 stars), Hashicorp Vault (BagelHole/DevOps-Security-Agent-Skills, 1.1k stars), Network Proxy (didi/mpx, 3.9k stars) and Private Secret Scanning (jamditis/claude-skills-journalism, 416 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
Hack23 (a GitHub organization) maintains it in Hack23/cia, which has 239 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on October 7, 2026.
Source: Hack23/cia on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.