Topic · DevOps & Cloud

Best secrets management skills for Claude Code, Codex and other agents.

Skills that store, rotate and inject secrets safely and find leaked keys and passwords in code.
skills
318
official
45

Secrets management skills, ranked

Ranked by score. Sort bymost stars,trending,newest,recently updated

Secrets management skills, ranked
#SkillRepositoryStarsUsed inTokensAuto-checkLicenceUpdated
1

Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

firecrawl/firecrawl189k1 repo~1.4kAutomated safety check: NotesISCtoday
2

Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

eigent-ai/eigent15k—~1.8kAutomated safety check: NotesApache-2.0today
3

Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review.

trufflesecurity/trufflehog28k—~1.3kAutomated safety check: PassAGPL-3.0today
4

Installs or refreshes Iron Proxy and its Iron Control web console for NanoClaw, with a local Docker setup, database, credentials and a human approval bridge.

nanocoai/nanoclaw31k—~4.6kAutomated safety check: NotesMITyesterday
5

BibiGPT CLI for summarizing videos, audio, and podcasts directly in the terminal.

JimmyLv/BibiGPT-v16.2k—~885Automated safety check: PassGPL-3.05 mo ago
6

Migrates the compatible subset of settings and global file-based MCP servers from the Warp desktop app into Warp Agent CLI without exposing credentials or state.

warpdotdev/warp65k1 repo~2.1kAutomated safety check: PassAGPL-3.0today
7

Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

latitude-dev/latitude-llm4.7k7 repos~1.6kAutomated safety check: PassMITyesterday
8

Installs or refreshes OneCLI as the gateway provider for NanoClaw, copying the adapter files, registering the provider and running the setup script.

nanocoai/nanoclaw31k—~1.1kAutomated safety check: NotesMITyesterday
9

Deploys and manages Vercel projects through the CLI using an access token from the environment or a .env file instead of interactive login.

vercel-labs/agent-skills32k7 repos~2.6kAutomated safety check: NotesNo licence1 mo ago
10

Deploys and configures a LangBot instance with Docker Compose or Kubernetes, covering config.yaml, the Box sandbox runtime, the plugin runtime and the global API key.

langbot-app/LangBot18k—~1.2kAutomated safety check: NotesApache-2.0today
11

Conventions for SGLang environment variables — where to define, how to access, how to name, and how to deprecate.

sgl-project/sglang37k2 repos~2.9kAutomated safety check: PassApache-2.0today
12

Releases a signed, notarized CodexBar build: confirms the changelog, resolves signing credentials from 1Password, runs the release script in tmux, and updates the Sparkle appcast and Homebrew tap.

steipete/CodexBar22k—~1.5kAutomated safety check: PassMITtoday
13

Inventories and maintains a fleet of Macs from a desired-state file: package updates, repo and Xcode sync, and disk, backup and security health reports.

steipete/agent-scripts7.3k—~4.8kAutomated safety check: PassMIT2 days ago
14
14.Wtf

Pre-launch and pre-commit audit for vibe coding projects. An agent skill from noobnooc/agent.

noobnooc/agent1.4k—~2.1kAutomated safety check: NotesNo licence1 mo ago
15

How to load secrets and environment variables from 1Password programmatically using the official @1password/sdk (JavaScript/TypeScript).

MadAppGang/claudish1k—~1.6kAutomated safety check: PassNo licencetoday
16

Add a Baserow configuration environment variable for the backend, frontend, or both, and propagate it through settings, Nuxt runtime config, Docker Compose, documentation, consumers, and tests as…

baserow/baserow6.1k—~1.1kAutomated safety check: PassUnknowntoday
17

Decides whether a Notion Worker should use a brokered credential, a plaintext environment secret, or OAuth to authenticate against a non-Notion service.

makenotion/workers-template4411 repo~3.5kAutomated safety check: NotesMIT26 days ago
18

EdgeOne Makers CLI command reference. An agent skill from TencentEdgeOne/edgeone-makers-tools.

TencentEdgeOne/edgeone-makers-tools1.9k1 repo~739Automated safety check: NotesMIT14 days ago
19

Analyze environment variables in JavaScript/TypeScript projects.

qdhenry/Claude-Command-Suite1.3k—~2.8kAutomated safety check: NotesNo licence7 mo ago
20

A skill your agent uses when: authenticating git and GitHub CLI for NEventStore tasks, fixing gh auth errors, setting PAT environment variables, preparing a shell session for git push and gh issue…

NEventStore/NEventStore1.6k—~828Automated safety check: PassMIT2 mo ago
21

Synchronize bilingual documentation when StaticPHP v3 user-facing or developer-facing documentation must change.

crazywhalecc/static-php-cli1.9k—~2.2kAutomated safety check: PassMITtoday
22

Configure and bootstrap a Ts.ED v8 server - the @Configuration decorator or configuration() on the Server class, PlatformExpress/PlatformKoa/PlatformFastify.bootstrap, server options (mount…

tsedio/tsed3.1k—~2.1kAutomated safety check: NotesMIT2 days ago
23

This skill should be used when the user asks to "add tracking", "add a PostHog event", "change telemetry consent", "instrument onboarding", "debug analytics", or changes telemetry.ts…

OpenHands/OpenHands90k—~305Automated safety check: PassMITtoday
24

Writes Vitest tests following project patterns: tests/ directories, vi.mock() for module mocking with vi.hoisted() for test-time factories, global LLM mock from src/test/setup.ts, environment…

caliber-ai-org/ai-setup1.3k—~3.2kAutomated safety check: PassMIT13 days ago
25

Covers Daytona CLI setup, sandbox debugging, keeping a sandbox alive and which credentials the CLI uses, for when Daytona itself is the problem rather than the tests.

different-ai/openwork24k—~917Automated safety check: PassUnknowntoday
26

A skill your agent uses when a user wants to create, run, or analyze evaluation suites for Microsoft 365 Copilot declarative agents with the public @microsoft/m365-copilot-eval CLI.

microsoft/work-iq1k—~2kAutomated safety check: NotesUnknowntoday
27

Run jit's pre-release QA — a team of QA-engineer subagents (functionality, integrations, UX, bug-hunting, code review) that exercise a release candidate on this real Mac and hand back a consolidated…

jitpass/jit162—~1.1kAutomated safety check: PassUnknown2 days ago
28

Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized.

netdata/netdata81k—~1.8kAutomated safety check: NotesGPL-3.0today
29

A skill your agent uses when authoring, reviewing, or refactoring Azure Bicep code.

timothywarner-org/claude-code224—~2.9kAutomated safety check: PassMIT2 mo ago
30

Hardcoded secret detection and prevention in git repositories and codebases using Gitleaks.

AgentSecOps/SecOpsAgentKit2192 repos~4.1kAutomated safety check: PassUnknown5 mo ago
31

Request a security expert assessment for code changes that touch child process spawning, file system access, configuration loading, or environment variable handling.

ktnyt/cclsp675—~565Automated safety check: PassMIT7 mo ago
32

Run Windows tasks in Niubash, the GNU Bash-compatible Windows-native shell.

unixwin/niubash146—~2.1kAutomated safety check: PassMIT2 days ago
33

Portable credential management for AI agents using age encryption, session-scoped leases, auto-rotation, and killswitch.

joelhooks/agent-secrets109—~3kAutomated safety check: PassMIT11 days ago
34
34.Vercel CLIOfficial

Vercel CLI expert guidance. An agent skill from vercel/vercel-plugin.

vercel/vercel-plugin3011 repo~2.5kAutomated safety check: PassUnknowntoday
35

Finalize a merge request: rebase onto main, run bugs, simplify, and specs in parallel, apply, then refactor last.

zifeo/lade133—~1kAutomated safety check: PassMPL-2.0today
36

Deploys, configures, and troubleshoots IBM Cloud Code Engine workloads using the ibmcloud ce CLI.

IBM/CodeEngine117—~3.4kAutomated safety check: PassApache-2.0yesterday
37

Expert Fish shell configuration including config files, functions, abbreviations, prompts, environment variables, and scripting.

wcygan/dotfiles196—~2.9kAutomated safety check: PassNo licence3 days ago
38

Debug container agent issues. An agent skill from sbusso/claudeclaw.

sbusso/claudeclaw1941 repo~3.3kAutomated safety check: NotesMIT1 mo ago
39

Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

BagelHole/DevOps-Security-Agent-Skills1.1k—~2kAutomated safety check: PassMIT4 mo ago
40

Walks a repository through release readiness before it goes public: secrets audit, licensing, documentation, CI and language-specific packaging.

trailofbits/skills7.4k—~2.6kAutomated safety check: PassCC-BY-SA-4.05 days ago
41

Guide users through configuring key MongoDB MCP server options.

mongodb/agent-skills1901 repo~3.3kAutomated safety check: PassApache-2.0today
42

Keep keypaste's desktop screens, CLI output, site, README and brand assets on brand.

notinferred/keypaste160—~865Automated safety check: PassAGPL-3.0today
43
43.Azure FunctionsOfficial

Dev/test workflow for tracer engineers working on the Datadog .NET tracer — build a local Datadog.AzureFunctions NuGet package, deploy it to a test Azure Function App, trigger it, and analyze…

DataDog/dd-trace-dotnet573—~4.7kAutomated safety check: PassApache-2.0today
44

Pre-submit hygiene check for AI-agent-authored pull requests.

Akimiya-z/codex-guard138—~564Automated safety check: PassMIT5 days ago
45

Swamp CLI — create and run models, build and validate workflows, query and manage data, store and retrieve vault secrets, develop and publish extensions, initialize repos, run reports, file issues…

swamp-club/swamp642—~1.9kAutomated safety check: PassUnknowntoday
46

Manages Git identity, HTTPS access tokens and SSH keys at the workspace level through three `tai tool` commands, each with a get, set, list, import or delete action.

YaoApp/yao8.1k—~712Automated safety check: PassUnknown2 days ago
47

Guide for configuring, deploying, and operating the MonsterMQ broker.

vogler75/monster-mq142—~2.2kAutomated safety check: PassGPL-3.0today
48

Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.

vechain/x-app-template450—~1.2kAutomated safety check: PassMIT2 mo ago

Questions, answered from the data.

What is the best secrets management skill?

Firecrawl Build Onboarding from firecrawl/firecrawl ranks first of the 318 secrets management skills listed here, with the highest score: its repository has 189k GitHub stars, 1 other GitHub owner carry a copy, its SKILL.md loads about 1.4k tokens and it has informational notes only in the automated safety check. Next come Security Auditor and Dep Updates.

Which secrets management skills are official?

45 of the 318 secrets management skills are official, published by the vendor's own GitHub organization: Vercel CLI With Tokens, Notion Worker Third-Party Auth Guide, M365 Agent Evaluator, Vercel CLI, Code Engine Specialist and 40 more.

How are these skills ranked?

By Skill Navigator score, which combines the GitHub stars of the skill's repository (shared across that repo's skills and discounted for large collections), how many other GitHub owners carry a copy of the skill, and automated SKILL.md quality checks, minus penalties for safety-check warnings and for each further skill from the same repository. Skills that fail the safety check are not listed.