Secrets Management

Keep credentials out of code, logs, bundles and history — one supply path, scoped per environment, rotatable on demand — and run the rotate-first response when one has already leaked. Use when adding or moving a key, token, connection string or signing secret, when a scanner or reviewer finds one committed, when a credential appears in logs or a client bundle, or when rotation is due. Not for deciding what a credential may access, and not for vulnerability advisories in dependencies.

nahid-sparktales Updated

File contents

nahid-sparktales/agent-dispatcher/tree/main/skills/security/secrets-management commit 108ea92693

Frequently asked questions

npx skillmds@latest add nahid-sparktales/secrets-management