BusinessMCP
Secrets Management logo

Secrets Management

Security

by wshobson

3/3 audits passMIT

Use Secrets Management in BusinessMCP

Free · imported in one click after signup

View on GitHub

Implement secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, or native platform solutions. Use when handling sensitive credentials, rotating secrets, or securing CI/CD environments.

Secrets Management is from Seth Hobson's agents collection (publisher wshobson, MIT licence) and covers keeping credentials out of CI/CD pipelines. It compares HashiCorp Vault, AWS Secrets Manager, Azure Key Vault and Google Secret Manager, then gives working examples: starting and using Vault, pulling Vault secrets into GitHub Actions and GitLab CI, retrieving AWS Secrets Manager values in a workflow with add-mask, referencing secrets from Terraform, GitHub organization, repository and environment secrets, and GitLab protected and masked variables. It also covers best practices, automated and manual secret rotation, the External Secrets Operator for Kubernetes, and secret scanning with a TruffleHog pre-commit hook and in CI.

Use it when you are adding credentials to a pipeline, setting up rotation, or moving hardcoded keys into a secrets manager. It is reference material with example configurations; it does not audit your existing secrets or provision infrastructure for you, and example values such as a dev-mode root token are for local illustration only.

This is a DevOps skill aimed at coding agents such as Claude Code. BusinessMCP can import it as a playbook, but it is not tied to workspace business data.

What you can do with it

  • Pull Vault secrets into a GitHub Actions deploy job
  • Move hardcoded API keys into AWS Secrets Manager
  • Add a TruffleHog pre-commit hook for secret scanning
  • Sync Kubernetes secrets with the External Secrets Operator

Run it on your business data

Imported into BusinessMCP, Secrets Management becomes a playbook your AI business analyst applies to your connected GitHub repositories.

Use Secrets Management in BusinessMCP

Install it in a coding agent

One command adds Secrets Management to your project.

npx skills add https://github.com/wshobson/agents --skill secrets-management

How we vetted it

Source
wshobson/agents at 4236bb9
Licence
MIT
Security audits (skills.sh)
Gen Agent Trust Hub: Pass · Socket: Pass · Snyk: Pass
Bundled scripts
None, instructions only

Checked 2026-09-25 against its skills.sh listing. How we vet skills

Frequently asked questions

Which secret stores does the skill cover?

HashiCorp Vault, AWS Secrets Manager, Azure Key Vault and Google Secret Manager, plus native GitHub and GitLab CI/CD secrets and the External Secrets Operator for Kubernetes.

Does it include secret scanning?

Yes. It shows a TruffleHog pre-commit hook and a CI secret-scanning step.

How do I install Secrets Management?

Run `npx skills add wshobson/agents --skill secrets-management`, or import it from the BusinessMCP dashboard as a playbook.

Run Secrets Management against your whole business

Free plan, no credit card.

Use Secrets Management in BusinessMCP