Agent skill

Ak Dev New Secret Provider

by yaalalabs in yaalalabs/agent-kernel

Step-by-step guide for adding a new built-in secret provider to Agent Kernel's secret-resolution capability (beyond env and awsssm).

Apache-2.0Auto-check passedDevOps & Cloud

Install Ak Dev New Secret Provider

skills CLI
$ npx skills add yaalalabs/agent-kernel --skill ak-dev-new-secret-provider -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yaalalabs/agent-kernel ak-dev-new-secret-provider --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yaalalabs/agent-kernel.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/ak-dev-new-secret-provider .claude/skills/ak-dev-new-secret-provider && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
ak-dev-new-secret-provider
GitHub stars
192
Token cost
~2.6k tokens
SKILL.md length
1,045 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
Apache-2.0

At a glance

Step-by-step guide for adding a new built-in secret provider to Agent Kernel's secret-resolution capability (beyond env and awsssm).

  • Works in 7 steps: Create the Provider File → Register with the Factory → Configuration → …
  • You need a new managed secret store (e.g
  • SKILL.md covers Existing Providers, Do You Need a Built-in?, The Contract and Step-by-Step, plus 1 more section
  • Calls uv and make; needs OPENAI_API_KEY

What it does

Ak Dev New Secret Provider is an agent skill from yaalalabs/agent-kernel. Step-by-step guide for adding a new built-in secret provider to Agent Kernel's secret-resolution capability (beyond env and awsssm). Use this skill when you need a new managed secret store (e.g. AWS Secrets Manager, Azure Key Vault, GCP Secret Manager, HashiCorp Vault) addressable by a short secret.provider.type name. Covers the SecretProvider contract, addressing, factory registration, configuration, optional dependencies, the SecretProviderContract test suite, deployment IAM wiring, and docs.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Test generation and Deployment. It works with Amazon Web Services, Azure Key Vault, Google Cloud and HashiCorp Vault. The repository describes itself as: The Operating System for Scalable Enterprise AI Agents - Run, orchestrate, and deploy Compliant Enterprise AI Agents at scale across frameworks, without lock-in, rewrites or… The licence is Apache-2.0.

When your agent uses it

  • You need a new managed secret store (e.g
  • Tasks that involve Test generation
  • Tasks that involve Deployment

Example prompts

  • “/ak-dev-new-secret-provider”

Requirements

  • Python 3
  • A credential in OPENAI_API_KEY

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Create the Provider File
  2. Register with the Factory
  3. Configuration
  4. Optional Dependency Extra
  5. Tests
  6. Deployment Wiring (Cloud Stores)
  7. Documentation

What it can do on your machine

Read from SKILL.md and the folder at commit 97fa8d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv
    • make

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use uv, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • OPENAI_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Ak Dev New Secret Provider loads about 2.6k tokens when it runs. Until then it costs about 132 tokens; SKILL.md has 1,045 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~132
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from yaalalabs/agent-kernel at commit 97fa8d9, republished under its Apache-2.0 licence (© yaalalabs). 1,045 words, ~2,581 tokens.

Download SKILL.mdSave it as .claude/skills/ak-dev-new-secret-provider/SKILL.md (or your agent's skills folder).
name
ak-dev-new-secret-provider
description
Step-by-step guide for adding a new built-in secret provider to Agent Kernel's secret-resolution capability (beyond env and aws_ssm). Use this skill when you need a new managed secret store (e.g. AWS Secrets Manager, Azure Key Vault, GCP Secret Manager, HashiCorp Vault) addressable by a short `secret.provider.type` name. Covers the SecretProvider contract, addressing, factory registration, configuration, optional dependencies, the SecretProviderContract test suite, deployment IAM wiring, and docs.
license
Apache-2.0
metadata.author
yaalalabs
metadata.category
developer

Adding a New Secret Provider

This guide walks through adding a built-in provider to the secret-resolution capability (ak-py/src/agentkernel/secret/). Use AWSSMSecretProvider (ak-py/src/agentkernel/secret/providers/aws_ssm.py) as the reference implementation, since it is the only built-in that talks to a remote store. The ak-dev-architecture skill's Secret Resolution section covers the manager, cache and resolution order this guide builds on.

Existing Providers

Providertype valueAddressingExtra
Environment (default)envthe key is the variable name, read verbatim— (stdlib)
AWS SSM Parameter Storeaws_ssm/ak/{prefix}/{key.lower()}, GetParameter(WithDecryption=True)agentkernel[aws]
Bring-your-owndotted path, e.g. myapp.secrets.VaultProviderwhatever the subclass implementsthe user's own

Do You Need a Built-in?

A dotted path already lets a user plug in any SecretProvider subclass with no core change: resolve_dotted(..., base=SecretProvider) imports it and calls its create. AWS Secrets Manager ships this way in v1 (see docs/specs/749-secret-resolution/design.md, Non-goals). Add a built-in only when the backend is broadly useful, has a stable SDK, and deserves a short name, tested IAM wiring and docs. Otherwise, document the dotted-path route in docs/docs/advanced/secrets.md (Custom providers) and stop there.

The Contract

SecretProvider (secret/base.py) is small. The rules around it are what matter:

  • get_secret(key) -> Optional[str]: return the stored value, or None when the backend does not hold it. A miss is not an error. Raise SecretError (secret/errors.py) only when the backend failed (credentials, network, throttling, authorization), and never put the value in the message.
  • The provider owns its addressing. key is always an environment-variable-style name (^[A-Z][A-Z0-9_]*$, e.g. OPENAI_API_KEY). Translating it to the backend's name (path, secret id, lowercase) happens here and nowhere else. The manager transforms nothing.
  • Never cache and never fall back. SecretManager owns the environment → cache → provider order and SecretCache owns TTLs. A provider that caches breaks invalidate() and rotation.
  • Tolerate concurrent calls. The manager calls the provider outside any lock, and concurrent cold reads may each call it. Create SDK clients lazily behind a lock (the double-checked client property in aws_ssm.py).
  • Return values verbatim. Don't strip whitespace or parse JSON, because values are flat strings. Treat an empty value as absent (EnvSecretProvider returns os.environ.get(key) or None).
  • create(cls, config: _SecretConfig) receives the whole secret block, not just secret.provider, so the deployment-wide secret.prefix is shared by every backend. Validate settings here and raise AKConfigError (core/util/factory.py) on unusable values, the way AWSSMSecretProvider._normalize_prefix rejects an empty or nested prefix. It fires at the first SecretManager.current(), so misconfiguration fails at startup, not on first read.

Step-by-Step

1. Create the Provider File

ak-py/src/agentkernel/secret/providers/<name>.py, one class named <Backend>SecretProvider, with a logger ak.secret.provider.<name>:

python
class VaultSecretProvider(SecretProvider):
    """HashiCorp Vault KV v2. Addressing: OPENAI_API_KEY → secret/data/ak/{prefix}/openai_api_key."""

    _log = logging.getLogger("ak.secret.provider.vault")

    def __init__(self, prefix: str) -> None:
        """:raises AKConfigError: If prefix is empty."""
        ...
        self._client: Optional[Any] = None
        self._client_lock = Lock()

    @classmethod
    def create(cls, config: _SecretConfig) -> "VaultSecretProvider":
        return cls(prefix=config.prefix)

    def get_secret(self, key: str) -> Optional[str]:
        """:raises SecretError: If Vault failed for any reason other than not-found."""
        ...

Map exactly one backend error to None (the not-found code, like ParameterNotFound in aws_ssm.py). Everything else becomes SecretError(...) from exc, including SDK transport errors.

2. Register with the Factory

In secret/factory.py, add the short name to _BUILTIN_SECRET_PROVIDERS and add a branch in SecretProviderFactory.get before the dotted-path fallback. Import the module lazily inside require_extra so a missing SDK raises a clear install hint:

python
if key == "vault":
    with require_extra("vault", "secret.provider.type: vault"):
        from .providers.vault import VaultSecretProvider

    return VaultSecretProvider.create(config)

create takes the block explicitly and must never call AKConfig.get() (test_get_never_reads_akconfig guards this).

3. Configuration
  • Reuse first. secret.prefix already expresses the deployment scope. Derive the backend path from it instead of adding a per-provider path field. Region and credentials come from the SDK's own environment defaults (the boto3.client("ssm") precedent), not from new fields.
  • Only if the backend truly needs settings prefix can't express (e.g. a Vault address or mount), add a _Secret<Backend>Config model under _SecretProviderConfig in core/config.py, with Field(description=...) on every field. Update the type field's description to list the new short name.
  • There is no enabled flag: selecting the provider type is the opt-in.
4. Optional Dependency Extra

Add the SDK to an extra in ak-py/pyproject.toml, or reuse one that already carries it (aws carries boto3 for any AWS backend). Match the extra name to the require_extra(...) call.

Show full SKILL.md (437 more words)Show less
5. Tests
  • Contract: in ak-py/tests/test_secret_providers.py, subclass SecretProviderContract (secret/testing.py, which is deliberately not exported from agentkernel.secret). Override the provider fixture and seed(provider, key, value). Seed through a fake SDK client, not the network, the way TestAWSSMProviderContract seeds _FakeSSMClient.parameters. Leave reads_environment = False unless the store is the environment.
  • Provider-specific tests in the same file: the exact name requested for a key, not-found → None, each failure class → SecretError with no value in the message, config validation → AKConfigError, and lazy/single client creation.
  • Factory tests in ak-py/tests/test_secret_factory.py: short name (case-insensitive) builds the provider, a missing extra raises before any settings check, and the provider receives the whole block.
  • If the new provider adds a factory-level rule, extend ak-py/tests/test_secret_manager.py's environment-always-wins assertions to include it.
6. Deployment Wiring (Cloud Stores)

If the backend is a cloud store the Terraform modules can grant, mirror ssm_enabled in ak-deployment/ak-aws/{serverless,containerized} (variables.tf, state.tf, modules/*/main.tf). Use one bool defaulting to false, keep every resource count-gated so the default plan is empty, and attach a read-only grant scoped to the prefix only to the tier that runs the agent (agent runner in queue mode, request handler / REST service otherwise — never the response or WS connection handler). Keep injecting AK_SECRET__PREFIX from the module's own prefix so the path and the grant can't drift. Never create secret values in Terraform.

7. Documentation
  • docs/docs/advanced/secrets.md: a ### <name> subsection under Providers (addressing, IAM, extra, failure behavior) and the new value in the secret.provider.type row.
  • ak-dev-architecture/SKILL.md, Secret Resolution: add the provider to the Providers bullet and the factory mapping.
  • ak-py/README.md: the extra, if new.
  • The bundled ak-cloud-deploy skill (ak-py/src/agentkernel/skills/ak-cloud-deploy/SKILL.md), if you added a deployment flag.
  • Landing page inventories (docs/src/components/*/data.tsx): a tile in the Cloud & infrastructure row of IntegrationsMarquee/data.tsx (role Secrets, href to the secrets docs page, logo or react-icons/si glyph; a vendor already on the marquee for another role, such as AWS Systems Manager, gets the new role appended to its title instead of a second tile), and the store in the Secret Resolution card's tags and description under the Guard tab in FeatureExplorer/data.tsx. Logo sourcing and the build check are in ak-dev-sync-docs-from-branch, Docs-Site Landing and Features Pages.

Checklist

  • secret/providers/<name>.py: owns addressing, None on miss, SecretError on failure, no caching, thread-safe lazy client
  • create validates settings and raises AKConfigError at construction
  • Factory branch behind require_extra + name in _BUILTIN_SECRET_PROVIDERS (secret/factory.py)
  • Config: secret.prefix reused; a _Secret<Backend>Config only if unavoidable (core/config.py)
  • Optional dependency extra in ak-py/pyproject.toml
  • SecretProviderContract subclass + provider-specific tests (tests/test_secret_providers.py)
  • Factory tests (tests/test_secret_factory.py)
  • Terraform grant flag, if a cloud store (ak-deployment/)
  • Docs: docs/docs/advanced/secrets.md, architecture skill, ak-py/README.md
  • Landing page inventories: marquee tile or role (IntegrationsMarquee/data.tsx), Secret Resolution card tags (FeatureExplorer/data.tsx)
  • cd ak-py && uv run pytest tests/test_secret_*.py and make lint-check-all clean

© yaalalabs, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/ak-dev-new-secret-provider of yaalalabs/agent-kernel.

Open the folder on GitHubat commit 97fa8d9

Compare with similar skills

Ak Dev New Secret Provider next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Ak Dev New Secret Provider compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Ak Dev New Secret Provider this skillyaalalabs/agent-kernel192—~2.6kAutomated safety check: PassApache-2.0
Secrets Vault Manageralirezarezvani/claude-skills28k1 repos~3.6kAutomated safety check: NotesMIT
Create Secretharness/harness-skills115—~1.7kAutomated safety check: PassApache-2.0
Senior DevOps Toolkitmaslennikov-ig/claude-code-orchestrator-kit2606 repos~1.1kAutomated safety check: NotesCustom licence
Kcli Cluster Deploymentkarmab/kcli653—~1.5kAutomated safety check: PassApache-2.0
Integrating Secrets Managersjeremylongshore/tons-of-skills-marketplace2.8k—~1.2kAutomated safety check: PassMIT

Similar skills

  • Secrets Vault Manager

    alirezarezvani/claude-skills

    A skill your agent uses when the user asks to set up secret management infrastructure, integrate HashiCorp Vault, configure cloud secret stores (AWS Secrets Manager, Azure Key Vault, GCP Secret…

    28k GitHub starsUsed in 1 repo~3.6k tokens
    DevOps & CloudAuto-check: notes
  • Create Secret

    harness/harness-skills

    Generate Harness Secret definitions and manage secrets via MCP v2 tools.

    115 GitHub stars~1.7k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Senior DevOps Toolkit

    maslennikov-ig/claude-code-orchestrator-kit

    Comprehensive DevOps skill for CI/CD, infrastructure automation, containerization, and cloud platforms (AWS, GCP, Azure). Includes pipeline setup…

    260 GitHub starsUsed in 6 repos~1.1k tokens
    DevOps & CloudAuto-check: notes
  • Guides deployment and management of Kubernetes clusters with kcli.

    653 GitHub stars~1.5k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Integrating Secrets Managers

    jeremylongshore/tons-of-skills-marketplace

    Manage this skill enables AI assistant to seamlessly integrate with various secrets managers like hashicorp vault and aws secrets manager.

    2.8k GitHub stars~1.2k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Cloud Infrastructure

    aiskillstore/marketplace

    Cloud infrastructure design and deployment patterns for AWS, Azure, and GCP.

    433 GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed

More from yaalalabs/agent-kernel

All 23 skills in this repo
  • Ak Dev Code Quality

    yaalalabs/agent-kernel

    Code quality standards, formatting, Python style rules (classes over script-style functions, configuration-field rules), commit conventions, and PR workflow for Agent Kernel development.

    192 GitHub stars~2.5k tokensUpdated 2 days ago
    Auto-check passed
  • Ak Dev New Evaluator Provider

    yaalalabs/agent-kernel

    Step-by-step guide for adding a new built-in test evaluator provider to Agent Kernel (beyond DeepEval, Opik and JEV).

    192 GitHub stars~3.4k tokensUpdated 2 days ago
    Auto-check passed
  • Ak Dev New Guardrail Provider

    yaalalabs/agent-kernel

    Step-by-step guide for adding a new guardrail provider to Agent Kernel.

    192 GitHub stars~3.5k tokensUpdated 2 days ago
    Auto-check passed
  • Step-by-step guide for adding a new knowledge base backend to Agent Kernel.

    192 GitHub stars~5.1k tokensUpdated 2 days ago
    Auto-check passed
  • Ak Dev New Messaging Integration

    yaalalabs/agent-kernel

    Step-by-step guide for adding a new messaging platform integration to Agent Kernel.

    192 GitHub stars~4.6k tokensUpdated 2 days ago
    Auto-check passed
  • Ak Dev New Multimodal Storage

    yaalalabs/agent-kernel

    Step-by-step guide for adding a new multimodal attachment storage backend to Agent Kernel.

    192 GitHub stars~4.3k tokensUpdated 2 days ago
    Auto-check passed

Categories

Questions about Ak Dev New Secret Provider

What does Ak Dev New Secret Provider do?

Step-by-step guide for adding a new built-in secret provider to Agent Kernel's secret-resolution capability (beyond env and awsssm). Ak Dev New Secret Provider is an agent skill from yaalalabs/agent-kernel. Step-by-step guide for adding a new built-in secret provider to Agent Kernel's secret-resolution capability (beyond env and awsssm).

When should I use Ak Dev New Secret Provider?

Ak Dev New Secret Provider fits situations like: you need a new managed secret store (e.g; tasks that involve Test generation; tasks that involve Deployment.

How do I install Ak Dev New Secret Provider in Claude Code?

Run `npx skills add yaalalabs/agent-kernel --skill ak-dev-new-secret-provider -a claude-code`. Or copy the skill folder (.agents/skills/ak-dev-new-secret-provider in yaalalabs/agent-kernel) into .claude/skills/ak-dev-new-secret-provider in your project. Claude Code loads it when a task matches its description.

How do I install Ak Dev New Secret Provider in Codex?

Run `npx skills add yaalalabs/agent-kernel --skill ak-dev-new-secret-provider -a codex`. Or copy the skill folder (.agents/skills/ak-dev-new-secret-provider in yaalalabs/agent-kernel) into .agents/skills/ak-dev-new-secret-provider in your project. Codex loads it when a task matches its description.

Can I use Ak Dev New Secret Provider in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yaalalabs/agent-kernel --skill ak-dev-new-secret-provider -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/ak-dev-new-secret-provider, .gemini/skills/ak-dev-new-secret-provider, .github/skills/ak-dev-new-secret-provider and .opencode/skills/ak-dev-new-secret-provider in your project.

What does Ak Dev New Secret Provider need to run?

Going by SKILL.md and its folder, Ak Dev New Secret Provider needs the command-line tools its instructions call (uv and make) and credentials named OPENAI_API_KEY. Our summary lists: Python 3; A credential in OPENAI_API_KEY.

Does Ak Dev New Secret Provider access the network?

SKILL.md contains no URLs. Its commands use uv, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Ak Dev New Secret Provider safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Ak Dev New Secret Provider use?

Ak Dev New Secret Provider is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Ak Dev New Secret Provider use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Ak Dev New Secret Provider?

Skills that share tags, products or a category with Ak Dev New Secret Provider: Secrets Vault Manager (alirezarezvani/claude-skills, 28k stars), Create Secret (harness/harness-skills, 115 stars), Senior DevOps Toolkit (maslennikov-ig/claude-code-orchestrator-kit, 260 stars) and Kcli Cluster Deployment (karmab/kcli, 653 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Ak Dev New Secret Provider?

yaalalabs (a GitHub organization) maintains it in yaalalabs/agent-kernel, which has 192 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 9, 2026.

Source: yaalalabs/agent-kernel on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.