CtrlK
BlogDocsLog inGet started
Tessl Logo

create-secret

Generate Harness Secret definitions and manage secrets via MCP v2 tools. Supports SecretText, SecretFile, SSHKey, and WinRmCredentials types with configurable secret managers (Harness built-in, HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager). Use when asked to create a secret, store credentials, manage API keys, set up SSH keys, configure WinRM credentials, rotate secrets, or reference secrets in pipelines. Trigger phrases: create secret, secret text, secret file, SSH key, API key, password, credentials, secret manager, store secret.

94

1.10x
Quality

93%

Does it follow best practices?

Impact

96%

1.10x

Average score across 3 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

86%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body is highly actionable with executable MCP tool calls and complete YAML, well-structured into a clear workflow with verification, and uses one-level-deep progressive disclosure effectively. Its main weakness is mild redundancy (duplicated YAML and repeated scope guidance) that could be tightened for token efficiency, and feedback loops live in a separate section rather than inline as explicit checkpoints.

Suggestions

Remove the duplicated SecretText YAML: keep the canonical definition in one place and reference it from the other, or drop the Step 3 body block in favor of the 'Secret Types' example.

Consolidate scope guidance so the project/org/account prefix rules appear once; the troubleshooting section can link back rather than restate them.

Promote the validation steps into inline checkpoints (e.g. 'Verify creation with harness_get; if it fails, consult Error Handling before proceeding') to make the feedback loop explicit within the workflow.

DimensionReasoningScore

Conciseness

Efficient and well-organized with tables and code, but the SecretText YAML is duplicated in both 'Secret Types' and 'Step 3', and scope guidance recurs across the scopes table and troubleshooting; minor trimming would tighten it further.

4 / 5

Actionability

Fully executable harness_list/get/create/update/delete/describe calls with real parameter names and complete body structures, plus concrete YAML definitions, naming patterns with regex, and an error-cause-solution table.

5 / 5

Workflow Clarity

Clear 4-step sequence with validation baked in (Step 2 checks for existing secrets, Step 4 verifies creation), and a separate troubleshooting section covers recovery; feedback loops are present but not inlined as explicit validate->fix->retry checkpoints within the steps.

4 / 5

Progressive Disclosure

SKILL.md is an overview that delegates the bulk of secret-type and manager-configuration detail to a single clearly-signaled, one-level-deep reference (references/secret-types.md), which exists and is appropriately scoped.

5 / 5

Total

18

/

20

Passed

Description

100%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

The description is excellent: it states concrete capabilities, enumerates supported types and managers, and provides an explicit 'Use when' clause with natural trigger phrases in third-person voice. It comprehensively answers both what the skill does and when to use it with minimal conflict risk.

DimensionReasoningScore

Specificity

Lists multiple concrete actions ('Generate', 'manage', 'store credentials', 'rotate secrets', 'reference secrets') plus comprehensive coverage of four secret types and five secret managers.

5 / 5

Completeness

Explicitly answers both 'what' (Generate Harness Secret definitions and manage secrets via MCP v2 tools) and 'when' with a 'Use when...' clause plus concrete 'Trigger phrases'.

5 / 5

Trigger Term Quality

Comprehensive natural trigger phrases ('create secret', 'SSH key', 'API key', 'password', 'credentials', 'secret manager', 'store secret') that users would naturally say.

5 / 5

Distinctiveness Conflict Risk

Clear niche scoped to 'Harness Secret definitions' and 'MCP v2 tools' with distinct triggers; minimal overlap risk with unrelated skills.

5 / 5

Total

20

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
harness/harness-ai
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.