Topic · DevOps & Cloud
Best secrets management skills for Claude Code, Codex and other agents.
- skills
- 318
- official
- 45
Secrets management skills, ranked
Ranked by score. Sort bymost stars,trending,newest,recently updated
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 1 | Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path. | firecrawl/ | 189k | 1 repo | ~1.4k | Automated safety check: Notes | ISC | today |
| 2 | Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist. | eigent-ai/ | 15k | — | ~1.8k | Automated safety check: Notes | Apache-2.0 | today |
| 3 | Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review. | trufflesecurity/ | 28k | — | ~1.3k | Automated safety check: Pass | AGPL-3.0 | today |
| 4 | Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge. | nanocoai/ | 31k | — | ~4.6k | Automated safety check: Notes | MIT | yesterday |
| 5 | 5.Bibi BibiGPT CLI for summarizing videos, audio, and podcasts directly in the terminal. | JimmyLv/ | 6.2k | — | ~885 | Automated safety check: Pass | GPL-3.0 | 5 mo ago |
| 6 | Migrates the compatible subset of settings and global file-based MCP servers from the Warp desktop app into Warp Agent CLI without exposing credentials or state. | warpdotdev/ | 65k | 1 repo | ~2.1k | Automated safety check: Pass | AGPL-3.0 | today |
| 7 | Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables. | latitude-dev/ | 4.7k | 7 repos | ~1.6k | Automated safety check: Pass | MIT | yesterday |
| 8 | Installs or refreshes OneCLI as the gateway provider for NanoClaw, copying the adapter files, registering the provider and running the setup script. | nanocoai/ | 31k | — | ~1.1k | Automated safety check: Notes | MIT | yesterday |
| 9 | Deploys and manages Vercel projects through the CLI using an access token from the environment or a .env file instead of interactive login. | vercel-labs/ | 32k | 7 repos | ~2.6k | Automated safety check: Notes | No licence | 1 mo ago |
| 10 | Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key. | langbot-app/ | 18k | — | ~1.2k | Automated safety check: Notes | Apache-2.0 | today |
| 11 | Conventions for SGLang environment variables — where to define, how to access, how to name, and how to deprecate. | sgl-project/ | 37k | 2 repos | ~2.9k | Automated safety check: Pass | Apache-2.0 | today |
| 12 | Releases a signed, notarized CodexBar build: confirms the changelog, resolves signing credentials from 1Password, runs the release script in tmux, and updates the Sparkle appcast and Homebrew tap. | steipete/ | 22k | — | ~1.5k | Automated safety check: Pass | MIT | today |
| 13 | Inventories and maintains a fleet of Macs from a desired-state file: package updates, repo and Xcode sync, and disk, backup and security health reports. | steipete/ | 7.3k | — | ~4.8k | Automated safety check: Pass | MIT | 2 days ago |
| 14 | 14.Wtf Pre-launch and pre-commit audit for vibe coding projects. An agent skill from noobnooc/agent. | noobnooc/ | 1.4k | — | ~2.1k | Automated safety check: Notes | No licence | 1 mo ago |
| 15 | How to load secrets and environment variables from 1Password programmatically using the official @1password/sdk (JavaScript/TypeScript). | MadAppGang/ | 1k | — | ~1.6k | Automated safety check: Pass | No licence | today |
| 16 | Add a Baserow configuration environment variable for the backend, frontend, or both, and propagate it through settings, Nuxt runtime config, Docker Compose, documentation, consumers, and tests as… | baserow/ | 6.1k | — | ~1.1k | Automated safety check: Pass | Unknown | today |
| 17 | Decides whether a Notion Worker should use a brokered credential, a plaintext environment secret, or OAuth to authenticate against a non-Notion service. | makenotion/ | 441 | 1 repo | ~3.5k | Automated safety check: Notes | MIT | 26 days ago |
| 18 | EdgeOne Makers CLI command reference. An agent skill from TencentEdgeOne/edgeone-makers-tools. | TencentEdgeOne/ | 1.9k | 1 repo | ~739 | Automated safety check: Notes | MIT | 14 days ago |
| 19 | Analyze environment variables in JavaScript/TypeScript projects. | qdhenry/ | 1.3k | — | ~2.8k | Automated safety check: Notes | No licence | 7 mo ago |
| 20 | A skill your agent uses when: authenticating git and GitHub CLI for NEventStore tasks, fixing gh auth errors, setting PAT environment variables, preparing a shell session for git push and gh issue… | NEventStore/ | 1.6k | — | ~828 | Automated safety check: Pass | MIT | 2 mo ago |
| 21 | Synchronize bilingual documentation when StaticPHP v3 user-facing or developer-facing documentation must change. | crazywhalecc/ | 1.9k | — | ~2.2k | Automated safety check: Pass | MIT | today |
| 22 | Configure and bootstrap a Ts.ED v8 server - the @Configuration decorator or configuration() on the Server class, PlatformExpress/PlatformKoa/PlatformFastify.bootstrap, server options (mount… | tsedio/ | 3.1k | — | ~2.1k | Automated safety check: Notes | MIT | 2 days ago |
| 23 | This skill should be used when the user asks to "add tracking", "add a PostHog event", "change telemetry consent", "instrument onboarding", "debug analytics", or changes telemetry.ts… | OpenHands/ | 90k | — | ~305 | Automated safety check: Pass | MIT | today |
| 24 | Writes Vitest tests following project patterns: tests/ directories, vi.mock() for module mocking with vi.hoisted() for test-time factories, global LLM mock from src/test/setup.ts, environment… | caliber-ai-org/ | 1.3k | — | ~3.2k | Automated safety check: Pass | MIT | 13 days ago |
| 25 | Covers Daytona CLI setup, sandbox debugging, keeping a sandbox alive and which credentials the CLI uses, for when Daytona itself is the problem rather than the tests. | different-ai/ | 24k | — | ~917 | Automated safety check: Pass | Unknown | today |
| 26 | A skill your agent uses when a user wants to create, run, or analyze evaluation suites for Microsoft 365 Copilot declarative agents with the public @microsoft/m365-copilot-eval CLI. | microsoft/ | 1k | — | ~2k | Automated safety check: Notes | Unknown | today |
| 27 | 27.QA Release Run jit's pre-release QA — a team of QA-engineer subagents (functionality, integrations, UX, bug-hunting, code review) that exercise a release candidate on this real Mac and hand back a consolidated… | jitpass/ | 162 | — | ~1.1k | Automated safety check: Pass | Unknown | 2 days ago |
| 28 | Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized. | netdata/ | 81k | — | ~1.8k | Automated safety check: Notes | GPL-3.0 | today |
| 29 | A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code. | timothywarner-org/ | 224 | — | ~2.9k | Automated safety check: Pass | MIT | 2 mo ago |
| 30 | Hardcoded secret detection and prevention in git repositories and codebases using Gitleaks. | AgentSecOps/ | 219 | 2 repos | ~4.1k | Automated safety check: Pass | Unknown | 5 mo ago |
| 31 | Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling. | ktnyt/ | 675 | — | ~565 | Automated safety check: Pass | MIT | 7 mo ago |
| 32 | 32.Niubash Run Windows tasks in Niubash, the GNU Bash-compatible Windows-native shell. | unixwin/ | 146 | — | ~2.1k | Automated safety check: Pass | MIT | 2 days ago |
| 33 | Portable credential management for AI agents using age encryption, session-scoped leases, auto-rotation, and killswitch. | joelhooks/ | 109 | — | ~3k | Automated safety check: Pass | MIT | 11 days ago |
| 34 | Vercel CLI expert guidance. An agent skill from vercel/vercel-plugin. | vercel/ | 301 | 1 repo | ~2.5k | Automated safety check: Pass | Unknown | today |
| 35 | 35.Finalize Finalize a merge request: rebase onto main, run bugs, simplify, and specs in parallel, apply, then refactor last. | zifeo/ | 133 | — | ~1k | Automated safety check: Pass | MPL-2.0 | today |
| 36 | Deploys, configures, and troubleshoots IBM Cloud Code Engine workloads using the ibmcloud ce CLI. | IBM/ | 117 | — | ~3.4k | Automated safety check: Pass | Apache-2.0 | yesterday |
| 37 | Expert Fish shell configuration including config files, functions, abbreviations, prompts, environment variables, and scripting. | wcygan/ | 196 | — | ~2.9k | Automated safety check: Pass | No licence | 3 days ago |
| 38 | 38.Debug Debug container agent issues. An agent skill from sbusso/claudeclaw. | sbusso/ | 194 | 1 repo | ~3.3k | Automated safety check: Notes | MIT | 1 mo ago |
| 39 | Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills. | BagelHole/ | 1.1k | — | ~2k | Automated safety check: Pass | MIT | 4 mo ago |
| 40 | Walks a repository through release readiness before it goes public: secrets audit, licensing, documentation, CI and language-specific packaging. | trailofbits/ | 7.4k | — | ~2.6k | Automated safety check: Pass | CC-BY-SA-4.0 | 5 days ago |
| 41 | Guide users through configuring key MongoDB MCP server options. | mongodb/ | 190 | 1 repo | ~3.3k | Automated safety check: Pass | Apache-2.0 | today |
| 42 | Keep keypaste's desktop screens, CLI output, site, README and brand assets on brand. | notinferred/ | 160 | — | ~865 | Automated safety check: Pass | AGPL-3.0 | today |
| 43 | Dev/test workflow for tracer engineers working on the Datadog .NET tracer — build a local Datadog.AzureFunctions NuGet package, deploy it to a test Azure Function App, trigger it, and analyze… | DataDog/ | 573 | — | ~4.7k | Automated safety check: Pass | Apache-2.0 | today |
| 44 | 44.Codex Guard Pre-submit hygiene check for AI-agent-authored pull requests. | Akimiya-z/ | 138 | — | ~564 | Automated safety check: Pass | MIT | 5 days ago |
| 45 | 45.Swamp Swamp CLI — create and run models, build and validate workflows, query and manage data, store and retrieve vault secrets, develop and publish extensions, initialize repos, run reports, file issues… | swamp-club/ | 642 | — | ~1.9k | Automated safety check: Pass | Unknown | today |
| 46 | Manages Git identity, HTTPS access tokens and SSH keys at the workspace level through three `tai tool` commands, each with a get, set, list, import or delete action. | YaoApp/ | 8.1k | — | ~712 | Automated safety check: Pass | Unknown | 2 days ago |
| 47 | Guide for configuring, deploying, and operating the MonsterMQ broker. | vogler75/ | 142 | — | ~2.2k | Automated safety check: Pass | GPL-3.0 | today |
| 48 | Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks. | vechain/ | 450 | — | ~1.2k | Automated safety check: Pass | MIT | 2 mo ago |
Questions, answered from the data.
What is the best secrets management skill?
Firecrawl Build Onboarding from firecrawl/firecrawl ranks first of the 318 secrets management skills listed here, with the highest score: its repository has 189k GitHub stars, 1 other GitHub owner carry a copy, its SKILL.md loads about 1.4k tokens and it has informational notes only in the automated safety check. Next come Security Auditor and Dep Updates.
Which secrets management skills are official?
45 of the 318 secrets management skills are official, published by the vendor's own GitHub organization: Vercel CLI With Tokens, Notion Worker Third-Party Auth Guide, M365 Agent Evaluator, Vercel CLI, Code Engine Specialist and 40 more.
How are these skills ranked?
By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.
Explore related skills
Category
More topics in DevOps & Cloud
- Deployment1,152
- CI/CD921
- Containers723
- Observability562
- Container orchestration519
- Infrastructure as code351
- Monitoring and alerting333
- Runbooks and postmortems277
- Incident response271
- Cloud networking230
- Backup and disaster recovery170
- Site reliability engineering150
- Cloud architecture114
- MLOps101
- Cloud cost optimization93
- GitOps87
- Linux administration75
- Platform engineering51
- Chaos engineering28