🔐 Cybersecurity · Application Security
Enforce secrets hygiene end to end
Generation, storage, rotation, and leak response for credentials humans inevitably touch.
foundation~25 minSecurity EngineersAppSecDevSecOps
Steps
- 1Generate long random secrets via managers; ban hand-invented passwords
- 2Inject at runtime from vault/KMS; forbid .env commits with real values
- 3Pre-commit hooks scanning for high-entropy strings and known key formats
- 4Rotate on schedule AND immediately after any suspected exposure
- 5Scope every key least-privilege; prefer short-lived credentials
- 6Practice the leak playbook: revoke → rotate → audit access → postmortem
Common Pitfalls
- ▲Rotated old keys never actually revoked
- ▲Service accounts sharing one god-mode credential
Commands
Install with skills CLI
$ npx skills add aniruddhaadak80/skills --skill application-security-secrets-hygieneInstall globally
$ npx skills add aniruddhaadak80/skills --skill application-security-secrets-hygiene -gTags
#secrets#keys#rotation#cybersecurity#application-security