Official agent skill

Creating Secrets Using Best Practices

by aws in aws/agent-toolkit-for-aws

Creates and manages secrets in AWS Secrets Manager following security best practices.

OfficialApache-2.0Auto-check passedSecurity

Install Creating Secrets Using Best Practices

skills CLI
$ npx skills add aws/agent-toolkit-for-aws --skill creating-secrets-using-best-practices -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aws/agent-toolkit-for-aws creating-secrets-using-best-practices --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/specialized-skills/security-and-identity-skills/creating-secrets-using-best-practices .claude/skills/creating-secrets-using-best-practices && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
creating-secrets-using-best-practices
GitHub stars
2.8k
Used in
1 other repo
Token cost
~461 tokens
SKILL.md length
180 words
Files
2 (incl. references)
Skills in repo
138
Repo updated
First seen
Licence
Apache-2.0

At a glance

Creates and manages secrets in AWS Secrets Manager following security best practices.

  • Creating secrets — it sets up dedicated KMS encryption keys
  • SKILL.md covers Overview, Create a secret with best… and Troubleshooting
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Automatic rotation

What it does

Creating Secrets Using Best Practices is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Creates and manages secrets in AWS Secrets Manager following security best practices. Always use this skill when creating secrets — it sets up dedicated KMS encryption keys, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management that are essential for production-grade secret handling.

Its SKILL.md is about 460 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/create-secrets-using-best-practices.md`).

It sits in Security, covering Cloud security. It works with Amazon Web Services. The repository describes itself as: Official, AWS-supported MCP servers, skills, and plugins to help AI agents build on AWS. The licence is Apache-2.0.

When your agent uses it

  • Creating secrets — it sets up dedicated KMS encryption keys
  • Automatic rotation
  • Least-privilege IAM policies
  • CloudTrail auditing

Example prompts

  • “Use the creating-secrets-using-best-practices skill to create and manages secrets in AWS Secrets Manager following security best practices”
  • “/creating-secrets-using-best-practices”

What it can do on your machine

Read from SKILL.md and the folder at commit bd49cc8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Creating Secrets Using Best Practices loads about 461 tokens when it runs, and up to ~2.9k if it reads all its reference files. Until then it costs about 91 tokens; SKILL.md has 180 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~91
When it runs · the whole SKILL.md, loaded when a task matches
~461
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from aws/agent-toolkit-for-aws at commit bd49cc8, republished under its Apache-2.0 licence (© aws). 180 words, ~461 tokens.

Download SKILL.mdSave it as .claude/skills/creating-secrets-using-best-practices/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
creating-secrets-using-best-practices
description
Creates and manages secrets in AWS Secrets Manager following security best practices. Always use this skill when creating secrets — it sets up dedicated KMS encryption keys, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management that are essential for production-grade secret handling.
version
1

Creating Secrets Using Best Practices

Overview

Domain expertise for creating and managing secrets in AWS Secrets Manager with production-grade security controls: KMS encryption, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management.

Create a secret with best practices

To create a properly secured secret in AWS Secrets Manager, follow the procedure exactly. See secret creation procedure.

The procedure supports four secret types: database credentials, API keys, OAuth tokens, and custom secrets. Each type is structured appropriately and encrypted with a dedicated KMS key.

Troubleshooting

KMS key access issues

Verify the IAM principal has kms:CreateKey and kms:PutKeyPolicy permissions, and that the key policy grants kms:GenerateDataKey, kms:Decrypt, and kms:DescribeKey scoped with kms:ViaService to secretsmanager.<region>.amazonaws.com. See the full procedure for details.

Rotation setup failures

Check that the Lambda rotation function exists, has proper permissions, and can reach the target system. Review CloudWatch logs for the rotation function.

Secret access denied

Verify the IAM policy is attached to the correct principal, the KMS key policy allows decryption (and kms:GenerateDataKey for write/rotation), and the principal is using HTTPS. See the full procedure for details.

© aws, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/specialized-skills/security-and-identity-skills/creating-secrets-using-best-practices of aws/agent-toolkit-for-aws.

  • SKILL.md
  • references/create-secrets-using-best-practices.md

Open the folder on GitHubat commit bd49cc8

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in aws/agent-toolkit-for-aws, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Creating Secrets Using Best Practices next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Creating Secrets Using Best Practices compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Creating Secrets Using Best Practices this skillaws/agent-toolkit-for-aws2.8k1 repos~461Automated safety check: PassApache-2.0
Cloud Auditbriiirussell/cybersecurity-skills412—~1.3kAutomated safety check: NotesMIT
Iamitsmostafa/aws-agent-skills1.2k—~1.8kAutomated safety check: PassMIT
AWS Security ArchitectureHack23/cia239—~2.3kAutomated safety check: PassApache-2.0
AWS Iamsickn33/agentic-awesome-skills47k2 repos~3.4kAutomated safety check: PassMIT
Performing AWS Account Enumeration With Scout Suitemukul975/Anthropic-Cybersecurity-Skills34k—~1.9kAutomated safety check: PassApache-2.0

Similar skills

  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    412 GitHub stars~1.3k tokensUpdated 4 mo ago
    SecurityAuto-check: notes
  • Iam

    itsmostafa/aws-agent-skills

    AWS Identity and Access Management for users, roles, policies, and permissions.

    1.2k GitHub stars~1.8k tokensUpdated yesterday
    SecurityAuto-check passed
  • AWS security best practices, VPC security, IAM, KMS, CloudTrail, GuardDuty for CIA platform deployment

    239 GitHub stars~2.3k tokensUpdated today
    SecurityAuto-check passed
  • AWS Iam

    sickn33/agentic-awesome-skills

    Manage IAM users, roles, and policies. An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~3.4k tokens
    SecurityAuto-check passed
  • Performing AWS Account Enumeration With Scout Suite

    mukul975/Anthropic-Cybersecurity-Skills

    Run the agentless, open-source ScoutSuite tool (via pip install and the scout CLI) against an AWS account to enumerate resources across services, identify misconfigurations, and generate an…

    34k GitHub stars~1.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Auditing Cloud With Cis Benchmarks

    mukul975/Anthropic-Cybersecurity-Skills

    Audit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools like Prowler and ScoutSuite, interpreting failed controls, and tracking…

    34k GitHub stars~3k tokensUpdated 1 mo ago
    SecurityAuto-check passed

More from aws/agent-toolkit-for-aws

All 138 skills in this repo
  • Agent Advisor

    aws/agent-toolkit-for-aws

    Official

    Entry point for AI-agent work on AWS: pick a runtime, plan a migration for existing workloads, and build an executable POC — one phased flow.

    2.8k GitHub stars~4.9k tokensUpdated today
    Auto-check passed
  • Agents Build

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses to extend an existing agent project with memory, app integration, VPC, multi-agent, migration, model, browser, code interpreter, payments, or resource removal.

    2.8k GitHub stars~2.3k tokensUpdated today
    Auto-check: notes
  • Launch With AWS

    aws/agent-toolkit-for-aws

    Official

    Migrates vibe-coded web applications to AWS. An agent skill from aws/agent-toolkit-for-aws.

    2.8k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Official

    Deploy an event-driven workflow that routes S3 uploads to either Lambda or Fargate via Step Functions based on file size.

    2.8k GitHub stars~4k tokensUpdated today
    Auto-check passed
  • AWS Marketplace Metering

    aws/agent-toolkit-for-aws

    Official

    Deploys, queries, and debugs AWS Marketplace usage-based (PAYG) metering — the pipeline (ResolveCustomer, BatchMeterUsage, EventBridge via SAM) and querying/debugging metering records, statuses…

    2.8k GitHub stars~18k tokensUpdated today
    Auto-check passed
  • Agents Pay

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses when THIS agent needs to pay for x402-protected content at runtime: hitting a paywall mid-task, settling it via AgentCore Payments, and applying operator-defined spend limits.

    2.8k GitHub stars~6.5k tokensUpdated today
    Auto-check: notes

Categories

Questions about Creating Secrets Using Best Practices

What does Creating Secrets Using Best Practices do?

Creates and manages secrets in AWS Secrets Manager following security best practices. Creating Secrets Using Best Practices is an agent skill from aws/agent-toolkit-for-aws, published by the product's own GitHub organization. Creates and manages secrets in AWS Secrets Manager following security best practices.

When should I use Creating Secrets Using Best Practices?

Creating Secrets Using Best Practices fits situations like: creating secrets — it sets up dedicated KMS encryption keys; automatic rotation; least-privilege IAM policies; cloudTrail auditing.

How do I install Creating Secrets Using Best Practices in Claude Code?

Run `npx skills add aws/agent-toolkit-for-aws --skill creating-secrets-using-best-practices -a claude-code`. Or copy the skill folder (skills/specialized-skills/security-and-identity-skills/creating-secrets-using-best-practices in aws/agent-toolkit-for-aws) into .claude/skills/creating-secrets-using-best-practices in your project. Claude Code loads it when a task matches its description.

How do I install Creating Secrets Using Best Practices in Codex?

Run `npx skills add aws/agent-toolkit-for-aws --skill creating-secrets-using-best-practices -a codex`. Or copy the skill folder (skills/specialized-skills/security-and-identity-skills/creating-secrets-using-best-practices in aws/agent-toolkit-for-aws) into .agents/skills/creating-secrets-using-best-practices in your project. Codex loads it when a task matches its description.

Can I use Creating Secrets Using Best Practices in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aws/agent-toolkit-for-aws --skill creating-secrets-using-best-practices -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/creating-secrets-using-best-practices, .gemini/skills/creating-secrets-using-best-practices, .github/skills/creating-secrets-using-best-practices and .opencode/skills/creating-secrets-using-best-practices in your project.

What does Creating Secrets Using Best Practices need to run?

SKILL.md names no scripts, command-line tools or credentials: Creating Secrets Using Best Practices is instructions for the agent only.

Does Creating Secrets Using Best Practices access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Creating Secrets Using Best Practices safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Creating Secrets Using Best Practices use?

Creating Secrets Using Best Practices is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Creating Secrets Using Best Practices use?

About 461 tokens (SKILL.md is roughly 1.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.5k tokens, read only when the agent opens those files.

What are the alternatives to Creating Secrets Using Best Practices?

Skills that share tags, products or a category with Creating Secrets Using Best Practices: Cloud Audit (briiirussell/cybersecurity-skills, 412 stars), Iam (itsmostafa/aws-agent-skills, 1.2k stars), AWS Security Architecture (Hack23/cia, 239 stars) and AWS Iam (sickn33/agentic-awesome-skills, 47k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Creating Secrets Using Best Practices?

aws (a GitHub organization, an official publisher) maintains it in aws/agent-toolkit-for-aws, which has 2,816 GitHub stars. The repository holds 138 skills in this directory. The repository was last updated on October 7, 2026.

Source: aws/agent-toolkit-for-aws on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.