⚡AgentSkills
🔐 Cybersecurity · Application Security

Enforce secrets hygiene end to end

Generation, storage, rotation, and leak response for credentials humans inevitably touch.

foundation~25 minSecurity EngineersAppSecDevSecOps

Steps

  1. 1Generate long random secrets via managers; ban hand-invented passwords
  2. 2Inject at runtime from vault/KMS; forbid .env commits with real values
  3. 3Pre-commit hooks scanning for high-entropy strings and known key formats
  4. 4Rotate on schedule AND immediately after any suspected exposure
  5. 5Scope every key least-privilege; prefer short-lived credentials
  6. 6Practice the leak playbook: revoke → rotate → audit access → postmortem

Common Pitfalls

  • ▲Rotated old keys never actually revoked
  • ▲Service accounts sharing one god-mode credential

Commands

Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill application-security-secrets-hygiene
Install globally
$ npx skills add aniruddhaadak80/skills --skill application-security-secrets-hygiene -g

Tags

#secrets#keys#rotation#cybersecurity#application-security

Related skills

STRIDE-lite walkthrough producing mitigations wired into tickets before code exists.

🔐 Cybersecurity·~40m

Focused pass over authz, injection, secrets, and deserialization on risky diffs.

🔐 Cybersecurity·~35m