Drawio AWS
sparklabx/drawio-ai-kit
A skill your agent uses when the user asks for an AWS architecture diagram — VPC/networking, event-driven, landing zone, multi-AZ, serverless pipeline, or any diagram built with AWS service icons.
AWS Secrets Manager for secure secret storage and rotation. An agent skill from itsmostafa/aws-agent-skills.
$ npx skills add itsmostafa/aws-agent-skills --skill secrets-manager -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install itsmostafa/aws-agent-skills secrets-manager --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/itsmostafa/aws-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/secrets-manager .claude/skills/secrets-manager && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "secrets-manager" agent skill from https://github.com/itsmostafa/aws-agent-skills/tree/main/skills/secrets-manager into .claude/skills/secrets-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-manager", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/itsmostafa/aws-agent-skills/tree/main/skills/secrets-managerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add itsmostafa/aws-agent-skills --skill secrets-manager -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install itsmostafa/aws-agent-skills secrets-manager --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/itsmostafa/aws-agent-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/secrets-manager .agents/skills/secrets-manager && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "secrets-manager" agent skill from https://github.com/itsmostafa/aws-agent-skills/tree/main/skills/secrets-manager into .agents/skills/secrets-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-manager", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add itsmostafa/aws-agent-skills --skill secrets-manager -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install itsmostafa/aws-agent-skills secrets-manager --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/itsmostafa/aws-agent-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/secrets-manager .cursor/skills/secrets-manager && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "secrets-manager" agent skill from https://github.com/itsmostafa/aws-agent-skills/tree/main/skills/secrets-manager into .cursor/skills/secrets-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-manager", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/itsmostafa/aws-agent-skills.git --path skills/secrets-manager--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add itsmostafa/aws-agent-skills --skill secrets-manager -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install itsmostafa/aws-agent-skills secrets-manager --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/itsmostafa/aws-agent-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/secrets-manager .gemini/skills/secrets-manager && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "secrets-manager" agent skill from https://github.com/itsmostafa/aws-agent-skills/tree/main/skills/secrets-manager into .gemini/skills/secrets-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-manager", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install itsmostafa/aws-agent-skills secrets-managerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add itsmostafa/aws-agent-skills --skill secrets-manager -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/itsmostafa/aws-agent-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/secrets-manager .github/skills/secrets-manager && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "secrets-manager" agent skill from https://github.com/itsmostafa/aws-agent-skills/tree/main/skills/secrets-manager into .github/skills/secrets-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-manager", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add itsmostafa/aws-agent-skills --skill secrets-manager -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install itsmostafa/aws-agent-skills secrets-manager --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/itsmostafa/aws-agent-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/secrets-manager .opencode/skills/secrets-manager && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "secrets-manager" agent skill from https://github.com/itsmostafa/aws-agent-skills/tree/main/skills/secrets-manager into .opencode/skills/secrets-manager/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "secrets-manager", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
secrets-managerAWS Secrets Manager for secure secret storage and rotation. An agent skill from itsmostafa/aws-agent-skills.
Secrets Manager is an agent skill from itsmostafa/aws-agent-skills. AWS Secrets Manager for secure secret storage and rotation. Use when storing credentials, configuring automatic rotation, managing secret versions, retrieving secrets in applications, or integrating with RDS.
Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `rotation-strategies.md`).
It sits in Backend & APIs. It works with Amazon Web Services. The repository describes itself as: AWS Skills for Agents. The licence is MIT.
Read from SKILL.md and the folder at commit e786d25. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
awsFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
docs.aws.amazon.comboto3.amazonaws.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
AWS_SESSION_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Secrets Manager loads about 2.3k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 338 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from itsmostafa/aws-agent-skills at commit e786d25, republished under its MIT licence (© itsmostafa). 338 words, ~2,262 tokens.
.claude/skills/secrets-manager/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.AWS Secrets Manager helps protect access to applications, services, and IT resources. Store, retrieve, and automatically rotate credentials, API keys, and other secrets.
Encrypted data stored in Secrets Manager. Can contain:
Each secret can have multiple versions:
Automatic credential rotation using Lambda functions. Built-in support for:
AWS CLI:
# Create secret with JSON
aws secretsmanager create-secret \
--name prod/myapp/database \
--description "Production database credentials" \
--secret-string '{"username":"admin","password":"MySecurePassword123!","host":"mydb.cluster-xyz.us-east-1.rds.amazonaws.com","port":5432,"database":"myapp"}'
# Create secret with binary data
aws secretsmanager create-secret \
--name prod/myapp/certificate \
--secret-binary fileb://certificate.pemboto3:
import boto3
import json
secrets = boto3.client('secretsmanager')
response = secrets.create_secret(
Name='prod/myapp/database',
Description='Production database credentials',
SecretString=json.dumps({
'username': 'admin',
'password': 'MySecurePassword123!',
'host': 'mydb.cluster-xyz.us-east-1.rds.amazonaws.com',
'port': 5432,
'database': 'myapp'
}),
Tags=[
{'Key': 'Environment', 'Value': 'production'},
{'Key': 'Application', 'Value': 'myapp'}
]
)import boto3
import json
secrets = boto3.client('secretsmanager')
def get_secret(secret_name):
response = secrets.get_secret_value(SecretId=secret_name)
if 'SecretString' in response:
return json.loads(response['SecretString'])
else:
import base64
return base64.b64decode(response['SecretBinary'])
# Usage
credentials = get_secret('prod/myapp/database')
db_password = credentials['password']from aws_secretsmanager_caching import SecretCache, SecretCacheConfig
# Configure cache
cache_config = SecretCacheConfig(
max_cache_size=100,
secret_refresh_interval=3600,
secret_version_stage_refresh_interval=3600
)
cache = SecretCache(config=cache_config)
def get_cached_secret(secret_name):
secret = cache.get_secret_string(secret_name)
return json.loads(secret)# Update secret value
aws secretsmanager update-secret \
--secret-id prod/myapp/database \
--secret-string '{"username":"admin","password":"NewPassword456!"}'
# Put new version with staging labels
aws secretsmanager put-secret-value \
--secret-id prod/myapp/database \
--secret-string '{"username":"admin","password":"NewPassword456!"}' \
--version-stages AWSCURRENTaws secretsmanager rotate-secret \
--secret-id prod/myapp/database \
--rotation-lambda-arn arn:aws:lambda:us-east-1:123456789012:function:SecretsManagerRDSPostgreSQLRotation \
--rotation-rules AutomaticallyAfterDays=30# Use CloudFormation for RDS secret with rotation
aws cloudformation deploy \
--template-file rds-secret.yaml \
--stack-name rds-secret# rds-secret.yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
DBSecret:
Type: AWS::SecretsManager::Secret
Properties:
Name: prod/myapp/database
GenerateSecretString:
SecretStringTemplate: '{"username": "admin"}'
GenerateStringKey: password
PasswordLength: 32
ExcludeCharacters: '"@/\'
DBSecretRotation:
Type: AWS::SecretsManager::RotationSchedule
Properties:
SecretId: !Ref DBSecret
RotationLambdaARN: !GetAtt RotationLambda.Arn
RotationRules:
AutomaticallyAfterDays: 30import json
import urllib.request
def handler(event, context):
# Use AWS Parameters and Secrets Lambda Extension
secrets_port = 2773
secret_name = 'prod/myapp/database'
url = f'http://localhost:{secrets_port}/secretsmanager/get?secretId={secret_name}'
headers = {'X-Aws-Parameters-Secrets-Token': os.environ['AWS_SESSION_TOKEN']}
request = urllib.request.Request(url, headers=headers)
response = urllib.request.urlopen(request)
secret = json.loads(response.read())['SecretString']
credentials = json.loads(secret)
return credentials| Command | Description |
|---|---|
aws secretsmanager create-secret | Create secret |
aws secretsmanager describe-secret | Get secret metadata |
aws secretsmanager get-secret-value | Retrieve secret value |
aws secretsmanager update-secret | Update secret |
aws secretsmanager delete-secret | Delete secret |
aws secretsmanager restore-secret | Restore deleted secret |
aws secretsmanager list-secrets | List secrets |
| Command | Description |
|---|---|
aws secretsmanager put-secret-value | Add new version |
aws secretsmanager list-secret-version-ids | List versions |
aws secretsmanager update-secret-version-stage | Move staging labels |
| Command | Description |
|---|---|
aws secretsmanager rotate-secret | Configure/trigger rotation |
aws secretsmanager cancel-rotate-secret | Cancel rotation |
environment/application/secret-type{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": [
"secretsmanager:GetSecretValue",
"secretsmanager:DescribeSecret"
],
"Resource": "arn:aws:secretsmanager:us-east-1:123456789012:secret:prod/*",
"Condition": {
"StringEquals": {
"secretsmanager:ResourceTag/Environment": "production"
}
}
}
]
}Causes:
secretsmanager:GetSecretValueDebug:
# Check secret resource policy
aws secretsmanager get-resource-policy --secret-id my-secret
# Check IAM permissions
aws iam simulate-principal-policy \
--policy-source-arn arn:aws:iam::123456789012:role/my-role \
--action-names secretsmanager:GetSecretValue \
--resource-arns arn:aws:secretsmanager:us-east-1:123456789012:secret:my-secretDebug:
# Check rotation status
aws secretsmanager describe-secret --secret-id my-secret
# Check Lambda logs
aws logs filter-log-events \
--log-group-name /aws/lambda/SecretsManagerRotation \
--filter-pattern "ERROR"Common causes:
# List secrets to find correct name
aws secretsmanager list-secrets \
--filters Key=name,Values=myapp
# Check if deleted (within recovery window)
aws secretsmanager list-secrets \
--include-planned-deletion© itsmostafa, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in skills/secrets-manager of itsmostafa/aws-agent-skills.
Open the folder on GitHubat commit e786d25
Secrets Manager next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Secrets Manager this skillitsmostafa/aws-agent-skills | 1.2k | — | ~2.3k | Automated safety check: Pass | MIT | |
| Drawio AWSsparklabx/drawio-ai-kit | 652 | 1 repos | ~1.6k | Automated safety check: Pass | MIT | |
| AWS Solution Architectalirezarezvani/claude-skills | 28k | 1 repos | ~2.5k | Automated safety check: Pass | MIT | |
| Cell Architecturegetsentry/sentry | 46k | — | ~4.6k | Automated safety check: Pass | Custom licence | |
| Model Deploymentawslabs/agent-plugins | 915 | 1 repos | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Atmos Authcloudposse/atmos | 1.4k | — | ~4.2k | Automated safety check: Pass | Apache-2.0 |
sparklabx/drawio-ai-kit
A skill your agent uses when the user asks for an AWS architecture diagram — VPC/networking, event-driven, landing zone, multi-AZ, serverless pipeline, or any diagram built with AWS service icons.
alirezarezvani/claude-skills
Design AWS architectures for startups using serverless patterns and IaC templates.
getsentry/sentry
Reference and active migration guide for Sentry's cell architecture.
awslabs/agent-plugins
Generates code that deploys fine-tuned models from SageMaker Serverless Model Customization to SageMaker endpoints or Bedrock.
cloudposse/atmos
Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access
alirezarezvani/claude-code-skill-factory
Expert AWS solution architecture for startups focusing on serverless, scalable, and cost-effective cloud infrastructure with modern DevOps practices and infrastructure-as-code
itsmostafa/aws-agent-skills
AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills.
itsmostafa/aws-agent-skills
AWS Bedrock foundation models for generative AI. An agent skill from itsmostafa/aws-agent-skills.
itsmostafa/aws-agent-skills
AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.
itsmostafa/aws-agent-skills
AWS ECS container orchestration for running Docker containers.
itsmostafa/aws-agent-skills
AWS CloudFormation infrastructure as code for stack management.
itsmostafa/aws-agent-skills
AWS CloudWatch monitoring for logs, metrics, alarms, and dashboards.
Works with
Categories
AWS Secrets Manager for secure secret storage and rotation. An agent skill from itsmostafa/aws-agent-skills. Secrets Manager is an agent skill from itsmostafa/aws-agent-skills. AWS Secrets Manager for secure secret storage and rotation.
Secrets Manager fits situations like: storing credentials; configuring automatic rotation; managing secret versions; retrieving secrets in applications.
Run `npx skills add itsmostafa/aws-agent-skills --skill secrets-manager -a claude-code`. Or copy the skill folder (skills/secrets-manager in itsmostafa/aws-agent-skills) into .claude/skills/secrets-manager in your project. Claude Code loads it when a task matches its description.
Run `npx skills add itsmostafa/aws-agent-skills --skill secrets-manager -a codex`. Or copy the skill folder (skills/secrets-manager in itsmostafa/aws-agent-skills) into .agents/skills/secrets-manager in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add itsmostafa/aws-agent-skills --skill secrets-manager -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secrets-manager, .gemini/skills/secrets-manager, .github/skills/secrets-manager and .opencode/skills/secrets-manager in your project.
Going by SKILL.md and its folder, Secrets Manager needs the command-line tools its instructions call (aws) and credentials named AWS_SESSION_TOKEN. Our summary lists: Python 3; A credential in AWS_SESSION_TOKEN.
SKILL.md names 2 domains. As links in the text: docs.aws.amazon.com and boto3.amazonaws.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Secrets Manager is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.3k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Secrets Manager: Drawio AWS (sparklabx/drawio-ai-kit, 652 stars), AWS Solution Architect (alirezarezvani/claude-skills, 28k stars), Cell Architecture (getsentry/sentry, 46k stars) and Model Deployment (awslabs/agent-plugins, 915 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
itsmostafa (a GitHub user) maintains it in itsmostafa/aws-agent-skills, which has 1,161 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 5, 2026.
Source: itsmostafa/aws-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.