Agent skill

Secrets Manager

by itsmostafa in itsmostafa/aws-agent-skills

AWS Secrets Manager for secure secret storage and rotation. An agent skill from itsmostafa/aws-agent-skills.

MITAuto-check passedBackend & APIs

Install Secrets Manager

skills CLI
$ npx skills add itsmostafa/aws-agent-skills --skill secrets-manager -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install itsmostafa/aws-agent-skills secrets-manager --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/itsmostafa/aws-agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/secrets-manager .claude/skills/secrets-manager && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secrets-manager
GitHub stars
1.2k
Token cost
~2.3k tokens
SKILL.md length
338 words
Files
2
Skills in repo
17
Repo updated
First seen
Licence
MIT

At a glance

AWS Secrets Manager for secure secret storage and rotation. An agent skill from itsmostafa/aws-agent-skills.

  • Storing credentials
  • SKILL.md covers Table of Contents, Core Concepts, Common Patterns and CLI Reference, plus 3 more sections
  • Calls aws; needs AWS_SESSION_TOKEN
  • Configuring automatic rotation

What it does

Secrets Manager is an agent skill from itsmostafa/aws-agent-skills. AWS Secrets Manager for secure secret storage and rotation. Use when storing credentials, configuring automatic rotation, managing secret versions, retrieving secrets in applications, or integrating with RDS.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `rotation-strategies.md`).

It sits in Backend & APIs. It works with Amazon Web Services. The repository describes itself as: AWS Skills for Agents. The licence is MIT.

When your agent uses it

  • Storing credentials
  • Configuring automatic rotation
  • Managing secret versions
  • Retrieving secrets in applications

Example prompts

  • “/secrets-manager”

Requirements

  • Python 3
  • A credential in AWS_SESSION_TOKEN

What it can do on your machine

Read from SKILL.md and the folder at commit e786d25. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • aws

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.aws.amazon.com
    • boto3.amazonaws.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AWS_SESSION_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secrets Manager loads about 2.3k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 338 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from itsmostafa/aws-agent-skills at commit e786d25, republished under its MIT licence (© itsmostafa). 338 words, ~2,262 tokens.

Download SKILL.mdSave it as .claude/skills/secrets-manager/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
secrets-manager
description
AWS Secrets Manager for secure secret storage and rotation. Use when storing credentials, configuring automatic rotation, managing secret versions, retrieving secrets in applications, or integrating with RDS.
last_updated
2026-01-07
doc_source
https://docs.aws.amazon.com/secretsmanager/latest/userguide/

AWS Secrets Manager

AWS Secrets Manager helps protect access to applications, services, and IT resources. Store, retrieve, and automatically rotate credentials, API keys, and other secrets.

Table of Contents

Core Concepts

Secrets

Encrypted data stored in Secrets Manager. Can contain:

  • Database credentials
  • API keys
  • OAuth tokens
  • Any key-value pairs (up to 64 KB)
Versions

Each secret can have multiple versions:

  • AWSCURRENT: Current active version
  • AWSPENDING: Version being rotated to
  • AWSPREVIOUS: Previous version
Rotation

Automatic credential rotation using Lambda functions. Built-in support for:

  • Amazon RDS
  • Amazon Redshift
  • Amazon DocumentDB
  • Custom secrets

Common Patterns

Create a Secret

AWS CLI:

bash
# Create secret with JSON
aws secretsmanager create-secret \
  --name prod/myapp/database \
  --description "Production database credentials" \
  --secret-string '{"username":"admin","password":"MySecurePassword123!","host":"mydb.cluster-xyz.us-east-1.rds.amazonaws.com","port":5432,"database":"myapp"}'

# Create secret with binary data
aws secretsmanager create-secret \
  --name prod/myapp/certificate \
  --secret-binary fileb://certificate.pem

boto3:

python
import boto3
import json

secrets = boto3.client('secretsmanager')

response = secrets.create_secret(
    Name='prod/myapp/database',
    Description='Production database credentials',
    SecretString=json.dumps({
        'username': 'admin',
        'password': 'MySecurePassword123!',
        'host': 'mydb.cluster-xyz.us-east-1.rds.amazonaws.com',
        'port': 5432,
        'database': 'myapp'
    }),
    Tags=[
        {'Key': 'Environment', 'Value': 'production'},
        {'Key': 'Application', 'Value': 'myapp'}
    ]
)
Retrieve a Secret
python
import boto3
import json

secrets = boto3.client('secretsmanager')

def get_secret(secret_name):
    response = secrets.get_secret_value(SecretId=secret_name)

    if 'SecretString' in response:
        return json.loads(response['SecretString'])
    else:
        import base64
        return base64.b64decode(response['SecretBinary'])

# Usage
credentials = get_secret('prod/myapp/database')
db_password = credentials['password']
Caching Secrets
python
from aws_secretsmanager_caching import SecretCache, SecretCacheConfig

# Configure cache
cache_config = SecretCacheConfig(
    max_cache_size=100,
    secret_refresh_interval=3600,
    secret_version_stage_refresh_interval=3600
)

cache = SecretCache(config=cache_config)

def get_cached_secret(secret_name):
    secret = cache.get_secret_string(secret_name)
    return json.loads(secret)
Update a Secret
bash
# Update secret value
aws secretsmanager update-secret \
  --secret-id prod/myapp/database \
  --secret-string '{"username":"admin","password":"NewPassword456!"}'

# Put new version with staging labels
aws secretsmanager put-secret-value \
  --secret-id prod/myapp/database \
  --secret-string '{"username":"admin","password":"NewPassword456!"}' \
  --version-stages AWSCURRENT
Enable Rotation for RDS
bash
aws secretsmanager rotate-secret \
  --secret-id prod/myapp/database \
  --rotation-lambda-arn arn:aws:lambda:us-east-1:123456789012:function:SecretsManagerRDSPostgreSQLRotation \
  --rotation-rules AutomaticallyAfterDays=30
Create Secret with Rotation
bash
# Use CloudFormation for RDS secret with rotation
aws cloudformation deploy \
  --template-file rds-secret.yaml \
  --stack-name rds-secret
yaml
# rds-secret.yaml
AWSTemplateFormatVersion: '2010-09-09'
Resources:
  DBSecret:
    Type: AWS::SecretsManager::Secret
    Properties:
      Name: prod/myapp/database
      GenerateSecretString:
        SecretStringTemplate: '{"username": "admin"}'
        GenerateStringKey: password
        PasswordLength: 32
        ExcludeCharacters: '"@/\'

  DBSecretRotation:
    Type: AWS::SecretsManager::RotationSchedule
    Properties:
      SecretId: !Ref DBSecret
      RotationLambdaARN: !GetAtt RotationLambda.Arn
      RotationRules:
        AutomaticallyAfterDays: 30
Use in Lambda with Extension
python
import json
import urllib.request

def handler(event, context):
    # Use AWS Parameters and Secrets Lambda Extension
    secrets_port = 2773
    secret_name = 'prod/myapp/database'

    url = f'http://localhost:{secrets_port}/secretsmanager/get?secretId={secret_name}'
    headers = {'X-Aws-Parameters-Secrets-Token': os.environ['AWS_SESSION_TOKEN']}

    request = urllib.request.Request(url, headers=headers)
    response = urllib.request.urlopen(request)
    secret = json.loads(response.read())['SecretString']

    credentials = json.loads(secret)
    return credentials

CLI Reference

Secret Management
CommandDescription
aws secretsmanager create-secretCreate secret
aws secretsmanager describe-secretGet secret metadata
aws secretsmanager get-secret-valueRetrieve secret value
aws secretsmanager update-secretUpdate secret
aws secretsmanager delete-secretDelete secret
aws secretsmanager restore-secretRestore deleted secret
aws secretsmanager list-secretsList secrets
Versions
CommandDescription
aws secretsmanager put-secret-valueAdd new version
aws secretsmanager list-secret-version-idsList versions
aws secretsmanager update-secret-version-stageMove staging labels
Rotation
CommandDescription
aws secretsmanager rotate-secretConfigure/trigger rotation
aws secretsmanager cancel-rotate-secretCancel rotation

Best Practices

Secret Organization
  • Use hierarchical names: environment/application/secret-type
  • Tag secrets for organization and cost allocation
  • Separate by environment (dev, staging, prod)
Security
  • Use resource policies to control access
  • Enable encryption with customer-managed KMS keys
  • Rotate secrets regularly (30-90 days)
  • Audit access with CloudTrail
  • Use VPC endpoints for private access
Access Control
json
{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": [
        "secretsmanager:GetSecretValue",
        "secretsmanager:DescribeSecret"
      ],
      "Resource": "arn:aws:secretsmanager:us-east-1:123456789012:secret:prod/*",
      "Condition": {
        "StringEquals": {
          "secretsmanager:ResourceTag/Environment": "production"
        }
      }
    }
  ]
}
Application Integration
  • Cache secrets to reduce API calls
  • Handle rotation gracefully (retry with new credentials)
  • Use Lambda extension for faster access
  • Never log secrets

Troubleshooting

AccessDeniedException

Causes:

  • IAM policy missing secretsmanager:GetSecretValue
  • Resource policy denying access
  • KMS key policy missing permissions

Debug:

bash
# Check secret resource policy
aws secretsmanager get-resource-policy --secret-id my-secret

# Check IAM permissions
aws iam simulate-principal-policy \
  --policy-source-arn arn:aws:iam::123456789012:role/my-role \
  --action-names secretsmanager:GetSecretValue \
  --resource-arns arn:aws:secretsmanager:us-east-1:123456789012:secret:my-secret
Rotation Failed

Debug:

bash
# Check rotation status
aws secretsmanager describe-secret --secret-id my-secret

# Check Lambda logs
aws logs filter-log-events \
  --log-group-name /aws/lambda/SecretsManagerRotation \
  --filter-pattern "ERROR"

Common causes:

  • Lambda timeout (increase to 30+ seconds)
  • Network connectivity (VPC configuration)
  • Database connection issues
  • Wrong secret format
Secret Not Found
bash
# List secrets to find correct name
aws secretsmanager list-secrets \
  --filters Key=name,Values=myapp

# Check if deleted (within recovery window)
aws secretsmanager list-secrets \
  --include-planned-deletion

References

© itsmostafa, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/secrets-manager of itsmostafa/aws-agent-skills.

  • SKILL.md
  • rotation-strategies.md

Open the folder on GitHubat commit e786d25

Compare with similar skills

Secrets Manager next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secrets Manager compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secrets Manager this skillitsmostafa/aws-agent-skills1.2k—~2.3kAutomated safety check: PassMIT
Drawio AWSsparklabx/drawio-ai-kit6521 repos~1.6kAutomated safety check: PassMIT
AWS Solution Architectalirezarezvani/claude-skills28k1 repos~2.5kAutomated safety check: PassMIT
Cell Architecturegetsentry/sentry46k—~4.6kAutomated safety check: PassCustom licence
Model Deploymentawslabs/agent-plugins9151 repos~1.5kAutomated safety check: PassApache-2.0
Atmos Authcloudposse/atmos1.4k—~4.2kAutomated safety check: PassApache-2.0

Similar skills

  • Drawio AWS

    sparklabx/drawio-ai-kit

    A skill your agent uses when the user asks for an AWS architecture diagram — VPC/networking, event-driven, landing zone, multi-AZ, serverless pipeline, or any diagram built with AWS service icons.

    652 GitHub starsUsed in 1 repo~1.6k tokens
    Backend & APIsAuto-check passed
  • AWS Solution Architect

    alirezarezvani/claude-skills

    Design AWS architectures for startups using serverless patterns and IaC templates.

    28k GitHub starsUsed in 1 repo~2.5k tokens
    Backend & APIsAuto-check passed
  • Cell Architecture

    getsentry/sentry

    Official

    Reference and active migration guide for Sentry's cell architecture.

    46k GitHub stars~4.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • Model Deployment

    awslabs/agent-plugins

    Official

    Generates code that deploys fine-tuned models from SageMaker Serverless Model Customization to SageMaker endpoints or Bedrock.

    915 GitHub starsUsed in 1 repo~1.5k tokens
    Backend & APIsAuto-check passed
  • Atmos Auth

    cloudposse/atmos

    Authentication and identity management: providers (SSO/SAML/OIDC/GCP/Atmos Pro), identities, keyring, identity chaining, login/exec/shell/console, and github/sts for private GitHub access

    1.4k GitHub stars~4.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • AWS Solution Architect

    alirezarezvani/claude-code-skill-factory

    Expert AWS solution architecture for startups focusing on serverless, scalable, and cost-effective cloud infrastructure with modern DevOps practices and infrastructure-as-code

    880 GitHub starsUsed in 1 repo~3.7k tokens
    Backend & APIsAuto-check passed

More from itsmostafa/aws-agent-skills

All 17 skills in this repo
  • API Gateway

    itsmostafa/aws-agent-skills

    AWS API Gateway for REST and HTTP API management. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed
  • Bedrock

    itsmostafa/aws-agent-skills

    AWS Bedrock foundation models for generative AI. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Ecs

    itsmostafa/aws-agent-skills

    AWS ECS container orchestration for running Docker containers.

    1.2k GitHub starsUsed in 1 repo~4.7k tokens
    Auto-check passed
  • Cloudformation

    itsmostafa/aws-agent-skills

    AWS CloudFormation infrastructure as code for stack management.

    1.2k GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Cloudwatch

    itsmostafa/aws-agent-skills

    AWS CloudWatch monitoring for logs, metrics, alarms, and dashboards.

    1.2k GitHub stars~3.5k tokensUpdated 2 days ago
    Auto-check passed

Questions about Secrets Manager

What does Secrets Manager do?

AWS Secrets Manager for secure secret storage and rotation. An agent skill from itsmostafa/aws-agent-skills. Secrets Manager is an agent skill from itsmostafa/aws-agent-skills. AWS Secrets Manager for secure secret storage and rotation.

When should I use Secrets Manager?

Secrets Manager fits situations like: storing credentials; configuring automatic rotation; managing secret versions; retrieving secrets in applications.

How do I install Secrets Manager in Claude Code?

Run `npx skills add itsmostafa/aws-agent-skills --skill secrets-manager -a claude-code`. Or copy the skill folder (skills/secrets-manager in itsmostafa/aws-agent-skills) into .claude/skills/secrets-manager in your project. Claude Code loads it when a task matches its description.

How do I install Secrets Manager in Codex?

Run `npx skills add itsmostafa/aws-agent-skills --skill secrets-manager -a codex`. Or copy the skill folder (skills/secrets-manager in itsmostafa/aws-agent-skills) into .agents/skills/secrets-manager in your project. Codex loads it when a task matches its description.

Can I use Secrets Manager in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add itsmostafa/aws-agent-skills --skill secrets-manager -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secrets-manager, .gemini/skills/secrets-manager, .github/skills/secrets-manager and .opencode/skills/secrets-manager in your project.

What does Secrets Manager need to run?

Going by SKILL.md and its folder, Secrets Manager needs the command-line tools its instructions call (aws) and credentials named AWS_SESSION_TOKEN. Our summary lists: Python 3; A credential in AWS_SESSION_TOKEN.

Does Secrets Manager access the network?

SKILL.md names 2 domains. As links in the text: docs.aws.amazon.com and boto3.amazonaws.com. This is read from the text; nothing was executed.

Is Secrets Manager safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Secrets Manager use?

Secrets Manager is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Secrets Manager use?

About 2.3k tokens (SKILL.md is roughly 9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Secrets Manager?

Skills that share tags, products or a category with Secrets Manager: Drawio AWS (sparklabx/drawio-ai-kit, 652 stars), AWS Solution Architect (alirezarezvani/claude-skills, 28k stars), Cell Architecture (getsentry/sentry, 46k stars) and Model Deployment (awslabs/agent-plugins, 915 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secrets Manager?

itsmostafa (a GitHub user) maintains it in itsmostafa/aws-agent-skills, which has 1,161 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on October 5, 2026.

Source: itsmostafa/aws-agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.