Agent skill

Secret Management

by joelhooks in joelhooks/agent-secrets

Portable credential management for AI agents using age encryption, session-scoped leases, auto-rotation, and killswitch.

MITAuto-check passedDevOps & Cloud

Install Secret Management

skills CLI
$ npx skills add joelhooks/agent-secrets --skill secret-management -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install joelhooks/agent-secrets secret-management --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/joelhooks/agent-secrets.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/secret-management .claude/skills/secret-management && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secret-management
GitHub stars
109
Token cost
~3k tokens
SKILL.md length
885 words
Files
1
Skills in repo
1
Repo updated
First seen
Licence
MIT

At a glance

Portable credential management for AI agents using age encryption, session-scoped leases, auto-rotation, and killswitch.

  • Works in 6 steps: Discover Commands and Secret Names → Adding Secrets → Leasing Secrets → …
  • Time-bounded credential access
  • SKILL.md covers When to Use This Skill, Prerequisites, Core Workflows and Agent Integration Patterns, plus 7 more sections
  • Calls make, gh and curl; reaches api.anthropic.com; needs GITHUB_TOKEN and ANTHROPIC_API_KEY

What it does

Secret Management is an agent skill from joelhooks/agent-secrets. Portable credential management for AI agents using age encryption, session-scoped leases, auto-rotation, and killswitch. Use for time-bounded credential access, agent-secrets daemon timeouts, or supervised restart and launchd reload diagnosis.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: {"os":["linux","macos"],"shell":["bash","zsh","sh"]}

It sits in DevOps & Cloud, covering Secrets management. The repository describes itself as: 🛡️ Portable credential management for AI agents — Age encryption, session leases, killswitch. The licence is MIT.

When your agent uses it

  • Time-bounded credential access
  • Agent-secrets daemon timeouts
  • Supervised restart and launchd reload diagnosis

Example prompts

  • “/secret-management”

Requirements

  • A credential in GITHUB_TOKEN
  • A credential in ANTHROPIC_API_KEY
  • Compatibility (from SKILL.md): {"os":["linux","macos"],"shell":["bash","zsh","sh"]}

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Discover Commands and Secret Names
  2. Adding Secrets
  3. Leasing Secrets
  4. Checking Status
  5. Audit Trail
  6. Revocation

What it can do on your machine

Read from SKILL.md and the folder at commit a095aca. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • make
    • gh
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.anthropic.com

    Also links to:

    • age-encryption.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN
    • ANTHROPIC_API_KEY
    • VERCEL_TOKEN
    • OPENAI_KEY
    • OPENAI_API_KEY
    • GH_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    {"os":["linux","macos"],"shell":["bash","zsh","sh"]}

    From compatibility in the SKILL.md frontmatter.

Context cost

Secret Management loads about 3k tokens when it runs. Until then it costs about 65 tokens; SKILL.md has 885 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~65
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from joelhooks/agent-secrets at commit a095aca, republished under its MIT licence (© joelhooks). 885 words, ~2,983 tokens.

Download SKILL.mdSave it as .claude/skills/secret-management/SKILL.md (or your agent's skills folder).
name
secret-management
description
Portable credential management for AI agents using age encryption, session-scoped leases, auto-rotation, and killswitch. Use for time-bounded credential access, agent-secrets daemon timeouts, or supervised restart and launchd reload diagnosis.
compatibility
{"os":["linux","macos"],"shell":["bash","zsh","sh"]}
license
MIT
metadata.version
0.1.0
metadata.requires
age encryption library, unix socket support

Secret Management for AI Agents

This skill enables AI agents to securely manage and access credentials using agent-secrets, a Go CLI that provides:

  • 🔐 Age encryption for secrets at rest
  • ⏱️ Session-scoped leases with automatic expiration
  • 🔄 Auto-rotation hooks for dynamic credentials
  • 🚨 Multi-factor killswitch for emergency revocation
  • 📋 Append-only audit logging

When to Use This Skill

Use agent-secrets when your agent needs to:

  • Access API keys, tokens, or credentials securely
  • Prevent credential exfiltration in case of compromise
  • Maintain an audit trail of secret access
  • Enable time-bounded credential access with automatic expiration
  • Support credential rotation without manual intervention
  • Implement emergency revocation across all active sessions

Prerequisites

The secrets CLI must be installed and in your PATH:

bash
# Install (see repo README for build instructions)
# https://github.com/joelhooks/agent-secrets

# Initialize the encrypted store (run once per machine)
secrets init

# Discover command tree and capabilities
secrets

This creates:

  • ~/.agent-secrets/identity.age — X25519 private key (0600 permissions)
  • ~/.agent-secrets/secrets.age — encrypted secrets store
  • ~/.agent-secrets/config.json — configuration
  • ~/.agent-secrets/agent-secrets.sock — daemon socket

Core Workflows

1. Discover Commands and Secret Names

Use discovery-first commands before requesting a lease:

bash
# Root command returns JSON command tree with usage and next_actions
secrets

# List all stored secret names and lease metadata
secrets list
2. Adding Secrets

Interactive mode (prompts for secret value):

bash
secrets add my_secret

With rotation hook (auto-refresh on expiration):

bash
secrets add github_token --rotate-via "gh auth refresh"
secrets add aws_token --rotate-via "aws sts get-session-token --duration-seconds 3600"

From stdin (pipe secret value):

bash
echo "sk-ant-api03-..." | secrets add anthropic_key
cat service-account.json | secrets add gcp_credentials
3. Leasing Secrets

secrets lease <name> returns ONLY the raw secret value by default, so no extra flags are needed for shell export:

bash
# Primary pattern
export GITHUB_TOKEN=$(secrets lease github_token)

# Custom TTL
export ANTHROPIC_API_KEY=$(secrets lease anthropic_key --ttl 30m)

# With client ID for audit trail
export OPENAI_KEY=$(secrets lease openai_key --ttl 2h --client-id "claude-code-worker")

# Use --json when you need lease metadata and next_actions
secrets lease github_token --json

Example JSON envelope (--json):

json
{
  "ok": true,
  "command": "secrets lease",
  "result": {
    "lease_id": "lease-123",
    "secret_name": "github_token",
    "value": "ghp_xxx",
    "expires_at": "2026-02-19T12:00:00Z",
    "ttl": "1h",
    "client_id": "claude-code-worker"
  },
  "next_actions": [
    {"command": "export GITHUB_TOKEN=$(secrets lease github_token)", "description": "Export to environment"},
    {"command": "secrets revoke lease-123", "description": "Revoke this lease"}
  ]
}

Error responses include a concrete fix field:

json
{
  "ok": false,
  "command": "secrets lease",
  "error": {"message": "failed to acquire lease: ... secret not found", "code": "generic_error"},
  "fix": "Check available secrets: secrets status"
}

Important: Secrets cannot be accessed directly. You must acquire a lease, and leases auto-expire.

4. Checking Status

View daemon and lease status:

bash
secrets status

Output shows:

  • Daemon running state
  • Start time
  • Number of stored secrets
  • Active lease count
5. Audit Trail

View the append-only audit log:

bash
# Last 50 entries (default)
secrets audit

# Last 100 entries
secrets audit --tail 100

Logs include:

  • Secret access events
  • Lease grants and expirations
  • Revocations
  • Rotation events
  • Killswitch activations
6. Revocation

Revoke specific lease:

bash
secrets revoke abc123

KILLSWITCH — Revoke ALL active leases:

bash
secrets revoke --all

Use the killswitch when:

  • Agent is compromised
  • Session needs immediate termination
  • Emergency security event occurs

Agent Integration Patterns

Claude Code / Cline / Aider

In your agent's environment setup script:

bash
# Session initialization
secrets list
export GITHUB_TOKEN=$(secrets lease github_token)
export ANTHROPIC_API_KEY=$(secrets lease anthropic_key)
export OPENAI_API_KEY=$(secrets lease openai_key)

# Now agent has time-bounded access
gh api /user
curl -H "Authorization: Bearer $ANTHROPIC_API_KEY" https://api.anthropic.com/...
Swarm Worker Pattern

For multi-agent swarm tasks, each worker should:

  1. Lease required credentials on startup with unique client ID
  2. Use --ttl matching expected task duration
  3. Let leases auto-expire on completion (no manual cleanup needed)

Example:

bash
# Worker initialization
WORKER_ID="worker-${EPIC_ID}-${TASK_ID}"
export GH_TOKEN=$(secrets lease github_token --ttl 2h --client-id "$WORKER_ID")
export VERCEL_TOKEN=$(secrets lease vercel_token --ttl 2h --client-id "$WORKER_ID")

# Work proceeds with secured credentials
# Leases auto-expire after 2 hours

Security Considerations

Encryption
  • All secrets encrypted at rest using age with X25519
  • Identity file permissions are 0600 (read/write owner only)
  • No plaintext secrets on disk
Lease Management
  • Mandatory TTL on all leases (max 24h by default)
  • Expired leases automatically pruned by background process
  • Leases cannot be extended—must acquire new lease
Audit
  • Every operation logged with timestamp, client ID, and event type
  • Append-only format (JSONL) prevents tampering
  • Use audit log for security reviews and incident response
Killswitch
  • revoke --all immediately invalidates all active leases
  • Optional: rotate all secrets with configured hooks
  • Optional: wipe entire store
  • Optional: heartbeat monitor (auto-killswitch if remote endpoint fails)
Rotation Hooks

Auto-rotation commands run on lease expiration or manual trigger:

bash
# GitHub token refresh
secrets add github_token --rotate-via "gh auth refresh"

# AWS session token
secrets add aws_token --rotate-via "aws sts get-session-token --duration-seconds 3600"

# Custom script
secrets add api_key --rotate-via "/path/to/refresh-token.sh"

Configuration

Edit ~/.agent-secrets/config.json to customize:

json
{
  "directory": "/home/user/.agent-secrets",
  "socket_path": "/home/user/.agent-secrets/agent-secrets.sock",
  "default_lease_ttl": "1h",
  "max_lease_ttl": "24h",
  "rotation_timeout": "30s",
  "heartbeat": {
    "enabled": false,
    "url": "https://your-endpoint.com/heartbeat",
    "interval": "1m",
    "timeout": "10s",
    "fail_action": {
      "revoke_all": true,
      "rotate_all": false,
      "wipe_store": false
    }
  }
}
Heartbeat Monitor (Optional)

Enable remote killswitch via heartbeat failure:

  • Set heartbeat.enabled: true
  • Configure endpoint URL
  • Set fail actions (revoke_all, rotate_all, wipe_store)

If heartbeat endpoint becomes unreachable for timeout duration, configured fail actions execute automatically.

Show full SKILL.md (402 more words)Show less

Common CLI Commands Reference

CommandDescriptionExample
secretsShow command tree for discoverysecrets
initInitialize encrypted storesecrets init
listList stored secret namessecrets list
add <name>Add secret (interactive or stdin)secrets add github_token
add <name> --rotate-via <cmd>Add secret with rotation hooksecrets add token --rotate-via "gh auth refresh"
lease <name>Get raw secret value (default 1h lease)secrets lease github_token
lease <name> --jsonGet lease envelope + next actionssecrets lease github_token --json
lease <name> --ttl <duration>Get lease with custom TTLsecrets lease api_key --ttl 30m
lease <name> --client-id <id>Get lease with audit identifiersecrets lease token --client-id "worker-123"
statusShow daemon and lease statussecrets status
auditView audit log (last 50 entries)secrets audit
audit --tail <n>View last N audit entriessecrets audit --tail 100
revoke <lease-id>Revoke specific leasesecrets revoke abc123
revoke --allKILLSWITCH: Revoke all leasessecrets revoke --all

Troubleshooting

Daemon missing, slow, or wedged?

Read Daemon operations. Start with a timed RPC:

bash
secrets --no-update-check --timeout 2 status

A running PID and connectable socket do not prove responsiveness. Capture timing and supervisor state before recovery. Use secrets daemon restart for a responsive supervised daemon; otherwise use the host's approved supervisor recovery path. Never start a second daemon against a supervised store.

On macOS, credential requests serving interactive clients need ProcessType=Interactive, not Background. Check the loaded job, not just the plist on disk. A configuration reload must wait for confirmed service removal after bootout before bootstrap; a fixed sleep or kickstart is not a reload. Preserve ownership and permissions.

Verify status latency and an authorized short-lived lease after recovery. Discard the credential value. Check lease-command success before exporting output; never treat an error envelope as a credential.

Permission denied on identity file?

bash
chmod 600 ~/.agent-secrets/identity.age

Forgot which secrets are stored?

bash
secrets list

Need to rotate everything immediately?

bash
secrets revoke --all
# Then add secrets again with fresh values

Best Practices for AI Agents

  1. Use descriptive client IDs: Include agent name, task ID, or session ID for audit trail
  2. Match TTL to task duration: Don't request 24h lease for 5min task
  3. Let leases expire naturally: No manual cleanup needed
  4. Enable rotation hooks: For dynamic credentials (GitHub, AWS, etc.)
  5. Monitor audit log: Review for unexpected access patterns
  6. Test killswitch: Verify revoke --all works in your environment
  7. Use unique leases per worker: In swarm mode, each worker gets own lease with unique client ID

Example: Full Agent Session

bash
#!/bin/bash
# Agent session initialization with agent-secrets

set -euo pipefail

# Navigate to agent-secrets CLI
SECRETS_CLI="/home/joel/Code/joelhooks/agent-secrets/secrets"

# Lease credentials for 2-hour work session
echo "🔐 Acquiring credentials..."
export GITHUB_TOKEN=$($SECRETS_CLI lease github_token)
export ANTHROPIC_API_KEY=$($SECRETS_CLI lease anthropic_key)
export VERCEL_TOKEN=$($SECRETS_CLI lease vercel_token)

# Verify credentials loaded
echo "✅ Credentials acquired (expire in 2h)"

# Check status
$SECRETS_CLI status

# Agent work proceeds here...
# gh pr create ...
# vercel deploy ...
# etc.

# No cleanup needed - leases auto-expire
echo "🎯 Session complete (leases will auto-expire)"

Repository Location

CLI source: /home/joel/Code/joelhooks/agent-secrets

Build the CLI:

bash
cd /home/joel/Code/joelhooks/agent-secrets
make build
# Binary: secrets

Install system-wide:

bash
cd /home/joel/Code/joelhooks/agent-secrets
make install
# Binary installed to $GOPATH/bin/secrets

© joelhooks, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/secret-management of joelhooks/agent-secrets.

Open the folder on GitHubat commit a095aca

Compare with similar skills

Secret Management next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secret Management compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secret Management this skilljoelhooks/agent-secrets109—~3kAutomated safety check: PassMIT
Iron Proxy Gateway for NanoClawnanocoai/nanoclaw31k—~4.6kAutomated safety check: NotesMIT
LangBot Deployment Guidelangbot-app/LangBot18k—~1.2kAutomated safety check: NotesApache-2.0
Env Var Conventionssgl-project/sglang37k2 repos~2.9kAutomated safety check: PassApache-2.0
Mac Fleet Maintenancesteipete/agent-scripts7.3k—~4.8kAutomated safety check: PassMIT
Add Config Env Varbaserow/baserow6.1k—~1.1kAutomated safety check: PassCustom licence

Similar skills

  • Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

    31k GitHub stars~4.6k tokensUpdated 3 days ago
    DevOps & CloudAuto-check: notes
  • LangBot Deployment Guide

    langbot-app/LangBot

    Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

    18k GitHub stars~1.2k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Env Var Conventions

    sgl-project/sglang

    Conventions for SGLang environment variables — where to define, how to access, how to name, and how to deprecate.

    37k GitHub starsUsed in 2 repos~2.9k tokens
    DevOps & CloudAuto-check passed
  • Mac Fleet Maintenance

    steipete/agent-scripts

    Inventories and maintains a fleet of Macs from a desired-state file: package updates, repo and Xcode sync, and disk, backup and security health reports.

    7.3k GitHub stars~4.8k tokensUpdated 5 days ago
    DevOps & CloudAuto-check passed
  • Add Config Env Var

    baserow/baserow

    Add a Baserow configuration environment variable for the backend, frontend, or both, and propagate it through settings, Nuxt runtime config, Docker Compose, documentation, consumers, and tests as…

    6.1k GitHub stars~1.1k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Edgeone Makers CLI

    TencentEdgeOne/edgeone-makers-tools

    EdgeOne Makers CLI command reference. An agent skill from TencentEdgeOne/edgeone-makers-tools.

    1.9k GitHub starsUsed in 1 repo~739 tokens
    DevOps & CloudAuto-check: notes

Categories

Questions about Secret Management

What does Secret Management do?

Portable credential management for AI agents using age encryption, session-scoped leases, auto-rotation, and killswitch. Secret Management is an agent skill from joelhooks/agent-secrets. Portable credential management for AI agents using age encryption, session-scoped leases, auto-rotation, and killswitch.

When should I use Secret Management?

Secret Management fits situations like: time-bounded credential access; agent-secrets daemon timeouts; supervised restart and launchd reload diagnosis.

How do I install Secret Management in Claude Code?

Run `npx skills add joelhooks/agent-secrets --skill secret-management -a claude-code`. Or copy the skill folder (skills/secret-management in joelhooks/agent-secrets) into .claude/skills/secret-management in your project. Claude Code loads it when a task matches its description.

How do I install Secret Management in Codex?

Run `npx skills add joelhooks/agent-secrets --skill secret-management -a codex`. Or copy the skill folder (skills/secret-management in joelhooks/agent-secrets) into .agents/skills/secret-management in your project. Codex loads it when a task matches its description.

Can I use Secret Management in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add joelhooks/agent-secrets --skill secret-management -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secret-management, .gemini/skills/secret-management, .github/skills/secret-management and .opencode/skills/secret-management in your project.

What does Secret Management need to run?

Going by SKILL.md and its folder, Secret Management needs the command-line tools its instructions call (make, gh and curl) and credentials named GITHUB_TOKEN, ANTHROPIC_API_KEY, VERCEL_TOKEN and OPENAI_KEY. Our summary lists: A credential in GITHUB_TOKEN; A credential in ANTHROPIC_API_KEY. Compatibility (from SKILL.md): {"os":["linux","macos"],"shell":["bash","zsh","sh"]}.

Does Secret Management access the network?

SKILL.md names 2 domains. In commands or code: api.anthropic.com; the agent is likely to contact it when it follows the instructions. As links in the text: age-encryption.org. This is read from the text; nothing was executed.

Is Secret Management safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Secret Management use?

Secret Management is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Secret Management use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Secret Management?

Skills that share tags, products or a category with Secret Management: Iron Proxy Gateway for NanoClaw (nanocoai/nanoclaw, 31k stars), LangBot Deployment Guide (langbot-app/LangBot, 18k stars), Env Var Conventions (sgl-project/sglang, 37k stars) and Mac Fleet Maintenance (steipete/agent-scripts, 7.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secret Management?

joelhooks (a GitHub user) maintains it in joelhooks/agent-secrets, which has 109 GitHub stars. The repository was last updated on September 25, 2026.

Source: joelhooks/agent-secrets on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.