Key Rotation Manager - Auto-activating skill for Security Advanced. Triggers on: key rotation manager, key rotation manager Part of the Security Advanced skill category.
35
3%
Does it follow best practices?
Impact
92%
0.97xAverage score across 3 eval scenarios
Passed
No known issues
Optimize this skill with Tessl
npx tessl skill review --optimize ./planned-skills/generated/04-security-advanced/key-rotation-manager/SKILL.mdProduction-ready key rotation script
Error handling present
100%
50%
No hardcoded secrets
100%
100%
Audit log written
100%
100%
Audit log has timestamps
100%
100%
Old key preserved before replacement
100%
100%
Verification step present
100%
100%
Step-by-step structure
100%
100%
README present
100%
100%
Secrets file not printed to stdout
100%
100%
Handles missing or malformed input
88%
44%
Rotation applies to all keys
100%
100%
Compliance-aligned key rotation policy
SOC2 referenced
100%
100%
Second standard referenced
100%
100%
Rotation frequencies specified
100%
100%
Emergency rotation procedure
100%
100%
Roles and responsibilities defined
100%
100%
Checklist uses Meet/Partial/Gap format
100%
100%
Policy covers multiple key types
100%
100%
Least privilege mentioned
0%
100%
Exceptions process included
100%
100%
Audit trail requirement stated
100%
100%
Step-by-step rotation procedure
100%
50%
Policy scope is explicit
100%
100%
Threat modeling for key rotation
threat_model.md created
100%
100%
threat_model_summary.json created
100%
100%
JSON schema followed
100%
100%
At least 5 threats identified
100%
100%
Impact levels used
100%
100%
Covers credential interception
100%
100%
Covers vault/store compromise
100%
100%
Covers rotation failure scenario
100%
100%
Mitigations are actionable
100%
100%
Step-by-step rotation pipeline described
100%
100%
Priority summary included
100%
100%
Standard framework referenced
0%
0%
Least privilege addressed
100%
100%
87f14eb
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.