CtrlK
BlogDocsLog inGet started
Tessl Logo

secrets-management

Implement secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, or native platform solutions. Use when handling sensitive credentials, rotating secrets, or securing CI/CD environments.

75

1.11x
Quality

68%

Does it follow best practices?

Impact

86%

1.11x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./tests/ext_conformance/artifacts/agents-wshobson/cicd-automation/skills/secrets-management/SKILL.md

The canonical home for this skill is secrets-management in wshobson/agents

SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is rich with executable, copy-paste-ready examples across Vault, AWS Secrets Manager, GitHub, GitLab, and Kubernetes, but it reads as a padded tool catalog: conceptual sections restate known material, no decision workflow guides tool choice, and both promised reference files are missing while their content is inlined. Tightening the overview and actually shipping the referenced files would lift most dimensions.

Suggestions

Create the referenced `references/vault-setup.md` and `references/github-secrets.md` and move the per-tool integration examples (Vault setup, GitHub/GitLab snippets) into them, leaving SKILL.md as a concise overview with a decision guide for choosing between Vault, AWS Secrets Manager, and platform-native secrets.

Replace the rotation Lambda's undefined `generate_strong_password()` and `update_database_password()` calls with concrete implementations, and add explicit validation checkpoints (e.g., verify the new secret works before revoking the old one) to the rotation workflows.

Cut the "Purpose", "When to Use", and tool feature bullet sections, which restate what Claude already knows about Vault/AWS/Azure/GCP, and fix the no-op `export VAULT_TOKEN=$VAULT_TOKEN` line in the GitLab example.

DimensionReasoningScore

Conciseness

Sections like "## Purpose", "## When to Use", and the tool feature bullets ("Centralized secrets management", "Dynamic secrets generation", "Audit logging") restate knowledge Claude already has. The code blocks themselves are dense and useful, so this is 'mostly efficient with some unnecessary explanation' rather than noticeably verbose.

3 / 5

Actionability

Concrete, mostly copy-paste-ready examples throughout: "vault kv put secret/database/config username=admin password=secret", full GitHub Actions and GitLab YAML, AWS CLI commands, Terraform, and External Secrets manifests. Minor gaps keep it from 5: the rotation Lambda calls undefined "generate_strong_password()" and "update_database_password()" functions, and "export VAULT_TOKEN=$VAULT_TOKEN" is a no-op.

4 / 5

Workflow Clarity

The only sequenced workflow is the five-step "Manual Rotation Process", which lists steps but with only an implicit validation checkpoint; the rest of the body is a tool catalog with no decision flow for choosing between Vault, AWS, and platform-native options. Operations on production secrets lack explicit validation/verification checkpoints, capping this at 3.

3 / 5

Progressive Disclosure

References to "references/vault-setup.md" and "references/github-secrets.md" are clearly signaled both inline and in a "Reference Files" section, but neither file exists in the bundle, and roughly 350 lines of per-tool detail that belongs in those files is inlined in SKILL.md instead. This matches 'references present but broken; content that should be separate is inline' rather than the well-split level 4.

3 / 5

Total

13

/

20

Passed

Description

78%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description that clearly answers both what the skill does and when to use it, with explicit trigger phrases and named tools. The main gaps are a thin action list in the what-clause and a few missing natural synonyms like "API keys" or "passwords".

DimensionReasoningScore

Specificity

"Implement secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, or native platform solutions" names the domain and specific tools but offers only one main action verb, matching the 'names domain and 1-2 concrete actions' anchor. It is not 4 because granular actions like storing, retrieving, or rotating secrets are absent from the what-clause.

3 / 5

Completeness

"Use when handling sensitive credentials, rotating secrets, or securing CI/CD environments" is an explicit when-clause with concrete trigger phrases, paired with a clear what-statement naming the tools. It clearly satisfies the top anchor rather than the 'when could be more specific' level 4.

5 / 5

Trigger Term Quality

"secrets", "credentials", "rotating secrets", "CI/CD", "Vault", and "AWS Secrets Manager" give good natural keyword coverage users would actually say. It falls short of 5 because common variations like "API keys", "passwords", or "tokens" are missing.

4 / 5

Distinctiveness Conflict Risk

The CI/CD secrets niche with named tools (Vault, AWS Secrets Manager) is mostly distinct with minor overlap risk against generic cloud-security or credentials skills. It is not 5 because "handling sensitive credentials" is broad enough to overlap with adjacent security skills.

4 / 5

Total

16

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

referenced_paths_exist

Referenced path issues: 4 missing

Warning

Total

15

/

16

Passed

Repository
Dicklesworthstone/pi_agent_rust
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.