Token导航 LogoToken导航TokenDH.com
开发敏感数据github未标认证来源可访问许可证需确认审计通过

integrating-secrets-managers集成秘密管理器

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

558

周安装

23

GitHub Stars

2,088

下载量

182
CodexClaudeCursorGemini CLI

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

unknown

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:integrating-secrets-managers(集成秘密管理器)
来源仓库:https://github.com/jeremylongshore/claude-code-plugins-plus-skills
仓库路径:skills/integrating-secrets-managers
安装命令:
npx skills add https://github.com/jeremylongshore/claude-code-plugins-plus-skills --skill integrating-secrets-managers
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 npx skills 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

skills.shnpx skills
npx skills add https://github.com/jeremylongshore/claude-code-plugins-plus-skills --skill integrating-secrets-managers

简介

辅助安全审计、权限检查和凭据风险分析。

  • 适合梳理敏感配置、检查依赖风险或生成复核清单。
  • 不能将工具输出直接作为最终结论。适用宿主包括 Codex、Claude、Cursor、Gemini CLI,接入前应确认版本、权限和运行环境要求。
  • 涉及密钥或生产系统时应确认最小权限和操作边界。
  • integrating-secrets-managers 属于开发类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

Integrating Secrets Managers

Overview

Integrate secrets management platforms (HashiCorp Vault, AWS Secrets Manager, GCP Secret Manager, Azure Key Vault) into applications and infrastructure. Generate authentication configurations, access policies, secret rotation schedules, and application code patterns for secure credential retrieval at runtime.

Prerequisites

  • Secrets manager instance running and accessible (Vault server, AWS Secrets Manager enabled)
  • Cloud provider CLI authenticated or Vault CLI installed (vault, aws, gcloud, az)
  • IAM/policy permissions to create secrets and access policies
  • Understanding of which application components need which secrets
  • Network connectivity between application workloads and the secrets manager endpoint

Instructions

  1. Inventory all secrets currently in use: database credentials, API keys, TLS certificates, OAuth tokens
  2. Select the secrets manager based on infrastructure: Vault for multi-cloud, AWS Secrets Manager for AWS-native, GCP Secret Manager for GCP
  3. Create the secrets store structure: organize by application, environment, and secret type (e.g., apps/myapp/prod/database)
  4. Generate access policies with least-privilege: each application identity gets read access only to its own secrets
  5. Configure authentication method: Kubernetes service account (Vault K8s auth), IAM role (AWS), Workload Identity (GCP)
  6. Implement secret retrieval in the application: SDK call at startup, sidecar injection (Vault Agent), or CSI driver mount
  7. Set up automatic secret rotation: define rotation lambda/function, rotation interval, and notification on rotation events
  8. Remove hardcoded secrets from code and configuration files; replace with secret references
  9. Add monitoring: alert on secret access failures, rotation failures, and unauthorized access attempts

Output

  • Vault policies (HCL) or IAM policies (JSON) for secret access
  • Authentication configuration (Vault K8s auth, AWS IAM role, GCP Workload Identity)
  • Application code snippets for secret retrieval (SDK-based or environment variable injection)
  • Secret rotation configuration (AWS rotation Lambda, Vault dynamic secrets)
  • Kubernetes External Secrets Operator or CSI SecretProviderClass manifests

Error Handling

ErrorCauseSolution
permission denied on secret readPolicy does not grant access to the requested pathUpdate Vault policy or IAM policy to include the specific secret ARN/path
Vault token expiredAuthentication token TTL exceededConfigure token renewal or use short-lived tokens with auto-renewal via Vault Agent
Secret not foundSecret path/name incorrect or secret deletedVerify the secret exists with vault kv get or aws secretsmanager describe-secret
Rotation failedRotation function lacks permissions or target service unreachableCheck rotation function logs; verify it has permissions to update credentials on the target service
Connection refused to VaultVault server down or network policy blocking accessVerify Vault is running and healthy; check network policies/firewalls between application and Vault

Examples

  • "Integrate HashiCorp Vault with a Kubernetes deployment using the Vault Agent sidecar injector to inject database credentials as environment variables."
  • "Set up AWS Secrets Manager with automatic rotation every 30 days for an RDS PostgreSQL password, with a Lambda rotation function."
  • "Replace all hardcoded API keys in the application with GCP Secret Manager references using Workload Identity for authentication."

Resources

适合场景

01

用户想查找某类 Agent Skill 时

02

需要根据任务场景推荐可安装能力包时

03

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

Codex

38.88%
按下载量换算71

Claude

26.59%
按下载量换算48

Cursor

17.5%
按下载量换算32

Gemini CLI

9.45%
按下载量换算17

安全审计

Gen Agent Trust Hub

通过

Socket

通过

Snyk

通过

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills