
Secrets Management
Securityby wshobson
3/3 audits passMIT
Implement secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, or native platform solutions. Use when handling sensitive credentials, rotating secrets, or securing CI/CD environments.
Secrets Management is from Seth Hobson's agents collection (publisher wshobson, MIT licence) and covers keeping credentials out of CI/CD pipelines. It compares HashiCorp Vault, AWS Secrets Manager, Azure Key Vault and Google Secret Manager, then gives working examples: starting and using Vault, pulling Vault secrets into GitHub Actions and GitLab CI, retrieving AWS Secrets Manager values in a workflow with add-mask, referencing secrets from Terraform, GitHub organization, repository and environment secrets, and GitLab protected and masked variables. It also covers best practices, automated and manual secret rotation, the External Secrets Operator for Kubernetes, and secret scanning with a TruffleHog pre-commit hook and in CI.
Use it when you are adding credentials to a pipeline, setting up rotation, or moving hardcoded keys into a secrets manager. It is reference material with example configurations; it does not audit your existing secrets or provision infrastructure for you, and example values such as a dev-mode root token are for local illustration only.
This is a DevOps skill aimed at coding agents such as Claude Code. BusinessMCP can import it as a playbook, but it is not tied to workspace business data.
What you can do with it
- Pull Vault secrets into a GitHub Actions deploy job
- Move hardcoded API keys into AWS Secrets Manager
- Add a TruffleHog pre-commit hook for secret scanning
- Sync Kubernetes secrets with the External Secrets Operator
Run it on your business data
Imported into BusinessMCP, Secrets Management becomes a playbook your AI business analyst applies to your connected GitHub repositories.
Use Secrets Management in BusinessMCPInstall it in a coding agent
One command adds Secrets Management to your project.
npx skills add https://github.com/wshobson/agents --skill secrets-managementHow we vetted it
- Source
- wshobson/agents at 4236bb9
- Licence
- MIT
- Security audits (skills.sh)
- Gen Agent Trust Hub: Pass · Socket: Pass · Snyk: Pass
- Bundled scripts
- None, instructions only
Checked 2026-09-25 against its skills.sh listing. How we vet skills
Related skills
All skillsSecurity and Hardening
Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe…
Terraform Skill
Use when writing, reviewing, or debugging Terraform/OpenTofu modules, tests, CI, scans, or state ops - diagnoses failure mode (identity churn, secrets, blast radius, CI drift, state corruption) with version-aware guards.
AWS CDK Development
AWS Cloud Development Kit (CDK) expert for building cloud infrastructure with TypeScript/Python.
Frequently asked questions
Which secret stores does the skill cover?
HashiCorp Vault, AWS Secrets Manager, Azure Key Vault and Google Secret Manager, plus native GitHub and GitLab CI/CD secrets and the External Secrets Operator for Kubernetes.
Does it include secret scanning?
Yes. It shows a TruffleHog pre-commit hook and a CI secret-scanning step.
How do I install Secrets Management?
Run `npx skills add wshobson/agents --skill secrets-management`, or import it from the BusinessMCP dashboard as a playbook.
Run Secrets Management against your whole business
Free plan, no credit card.
Use Secrets Management in BusinessMCP