Agent skill
security/secrets
Secrets Management security skill
Install this agent skill to your Project
npx add-skill https://github.com/majiayu000/claude-skill-registry/tree/main/skills/other/secrets
SKILL.md
Secrets Management
API keys and credentials require careful handling throughout their lifecycle.
ikigai Application
API keys (OpenAI, Anthropic, etc.):
- Store in config file with
0600permissions - Load once at startup, hold in memory
- Never log, never include in error messages
- Never embed in source code or commits
Memory handling:
- Scrub secrets from memory when done:
explicit_bzero(key, len) - Avoid
strdup()for secrets (can't track copies) - Keep secret lifetime short and scoped
Config file security:
// Check permissions before reading
struct stat st;
if (stat(path, &st) == 0 && (st.st_mode & 077) != 0) {
return ERR(ctx, SECURITY, "Config file permissions too open");
}
Never expose:
- In logs or debug output
- In error messages shown to user
- In core dumps (
prctl(PR_SET_DUMPABLE, 0)) - Via environment to child processes
Review red flags: Secrets in printf/logging, strdup on credentials, missing permission checks.
Recommended Agent Skills
Expand your agent's capabilities with these related and highly-rated skills.
agent-ops-spec
Manage specification documents in .agent/specs/. Use when user provides requirements, acceptance criteria, or feature descriptions that need to be tracked and validated against implementation.
agent-ops-state
Maintain .agent state files. Use at session start, after meaningful steps, and before concluding: read/update constitution/memory/focus/issues/baseline consistently.
agent-ops-spec
Manage specification documents in .agent/specs/. Use when user provides requirements, acceptance criteria, or feature descriptions that need to be tracked and validated against implementation.
agent-ops-testing
Test strategy, execution, and coverage analysis. Use when designing tests, running test suites, or analyzing test results beyond baseline checks.
agent-ops-testing
Test strategy, execution, and coverage analysis. Use when designing tests, running test suites, or analyzing test results beyond baseline checks.
agent-ops-state
Maintain .agent state files. Use at session start, after meaningful steps, and before concluding: read/update constitution/memory/focus/issues/baseline consistently.
Didn't find tool you were looking for?