Implement secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, or native platform solutions. Use when handling sensitive credentials, rotating secrets, or securing CI/CD environments.
Overall
score
82%
Does it follow best practices?
If you maintain this skill, you can automatically optimize it using the tessl CLI to improve its score:
npx tessl skill review --optimize ./path/to/skillEvaluation — 86%
↑ 1.12xAgent success when using this skill
Validation for skill structure
GitHub Actions Vault integration
Vault action version
0%
100%
kv-v2 path format
100%
100%
Secret masking
100%
100%
GitHub environment scoping
100%
100%
No hardcoded secrets
100%
100%
VAULT_TOKEN reference
100%
100%
Database credentials retrieved
100%
100%
Payment API key retrieved
100%
100%
Secrets requirements documented
100%
100%
Main branch trigger
100%
100%
Without context: $0.2065 · 43s · 11 turns · 60 in / 2,352 out tokens
With context: $0.3301 · 1m 14s · 15 turns · 14 in / 3,357 out tokens
Secret scanning setup
TruffleHog in pre-commit
0%
0%
Docker invocation pattern
0%
0%
Commit blocking on failure
0%
0%
GitLab secret-scan job
100%
100%
TruffleHog in CI
0%
100%
allow_failure: false
100%
100%
Security stage placement
100%
100%
Hook executable
0%
0%
Installation documented
78%
100%
False positive guidance
100%
100%
Without context: $0.4784 · 1m 47s · 24 turns · 73 in / 5,675 out tokens
With context: $0.5524 · 1m 51s · 26 turns · 263 in / 6,081 out tokens
Kubernetes External Secrets Operator
ESO apiVersion
100%
100%
SecretStore kind
100%
100%
ExternalSecret kind
100%
100%
refreshInterval set
100%
100%
creationPolicy Owner
100%
100%
Correct secret target
100%
100%
Both fields mapped
100%
100%
AWS credentials action version
100%
100%
No hardcoded AWS credentials
70%
100%
Production namespace
100%
100%
Architecture documented
100%
100%
Ownership model explained
100%
100%
Without context: $0.2141 · 1m 20s · 13 turns · 9 in / 3,597 out tokens
With context: $0.5712 · 1m 57s · 25 turns · 131 in / 6,733 out tokens
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.