CtrlK
BlogDocsLog inGet started
Tessl Logo

secrets-management

Use this skill when handling API keys, passwords, tokens, private keys, or any sensitive credential. Never hardcode secrets in source code — apply this whenever the word "key", "token", "password", or "secret" appears in the task.

72

Quality

88%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Secrets Management

Rules:

  1. Never hardcode secrets in source files, configs committed to git, or logs.
  2. Use environment variables for local development (python-dotenv).
  3. Use a secrets manager (AWS Secrets Manager, HashiCorp Vault, 1Password CLI) in production.
  4. Add .env and *.pem to .gitignore before the first commit.
  5. Rotate secrets immediately if they are exposed (leaked in a commit, log, or error message).

Scanning: Use ggshield, truffleHog, or git-secrets in CI to block secret commits.

Anti-patterns:

  • os.environ.get('KEY', 'hardcoded_default') in production code.
  • Logging full request/response bodies that may contain tokens.
Repository
aiming-lab/MetaClaw
Last updated
First committed

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.