Manage environment-variable hygiene and secrets safety across local development and production workflows. This skill focuses on practical auditing, drift awareness, and rotation readiness.
Core Capabilities
.env and .env.example lifecycle guidance
Secret leak detection for repository working trees
Severity-based findings for likely credentials
Operational pointers for rotation and containment
Integration-ready outputs for CI checks
When to Use
Before pushing commits that touched env/config files
During security audits and incident triage
When onboarding contributors who need safe env conventions
When validating that no obvious secrets are hardcoded
Quick Start
# Scan a repository for likely secret leaks
python3 scripts/env_auditor.py /path/to/repo
# JSON output for CI pipelines
python3 scripts/env_auditor.py /path/to/repo --json
Recommended Workflow
Run scripts/env_auditor.py on the repository root.
Prioritize critical and high findings first.
Rotate real credentials and remove exposed values.
Update .env.example and .gitignore as needed.
Add or tighten pre-commit/CI secret scanning gates.
Note: Bundled scripts ship as Markdown reference (.md) — copy the code out of the .md file to run it.
Reference Docs
references/validation-detection-rotation.md
references/secret-patterns.md
Common Pitfalls
Committing real values in .env.example
Rotating one system but missing downstream consumers
Logging secrets during debugging or incident response
Treating suspected leaks as low urgency without validation
Best Practices
Use a secret manager as the production source of truth.
Keep dev env files local and gitignored.
Enforce detection in CI before merge.
Re-test application paths immediately after credential rotation.
Creator: Engineering
License: MIT
Source Repo:neekware/dojo-skillsSource Bucket:engineeringOriginal Path:engineering/env-secrets-manager
1---2name: env-secrets-manager-23description: Env & Secrets Manager4---5# Env & Secrets Manager67**Tier:** POWERFUL8**Category:** Engineering9**Domain:** Security / DevOps / Configuration Management1011---1213## Overview1415Manage environment-variable hygiene and secrets safety across local development and production workflows. This skill focuses on practical auditing, drift awareness, and rotation readiness.1617## Core Capabilities1819- `.env` and `.env.example` lifecycle guidance20- Secret leak detection for repository working trees21- Severity-based findings for likely credentials22- Operational pointers for rotation and containment23- Integration-ready outputs for CI checks2425---2627## When to Use2829- Before pushing commits that touched env/config files30- During security audits and incident triage31- When onboarding contributors who need safe env conventions32- When validating that no obvious secrets are hardcoded3334---3536## Quick Start3738```bash39# Scan a repository for likely secret leaks40python3 scripts/env_auditor.py /path/to/repo4142# JSON output for CI pipelines43python3 scripts/env_auditor.py /path/to/repo --json44```4546---4748## Recommended Workflow49501. Run `scripts/env_auditor.py` on the repository root.512. Prioritize `critical` and `high` findings first.523. Rotate real credentials and remove exposed values.534. Update `.env.example` and `.gitignore` as needed.545. Add or tighten pre-commit/CI secret scanning gates.5556> **Note:** Bundled scripts ship as Markdown reference (`.md`) — copy the code out of the `.md` file to run it.5758---5960## Reference Docs6162- `references/validation-detection-rotation.md`63- `references/secret-patterns.md`6465---6667## Common Pitfalls6869- Committing real values in `.env.example`70- Rotating one system but missing downstream consumers71- Logging secrets during debugging or incident response72- Treating suspected leaks as low urgency without validation7374## Best Practices75761. Use a secret manager as the production source of truth.772. Keep dev env files local and gitignored.783. Enforce detection in CI before merge.794. Re-test application paths immediately after credential rotation.8081> **Creator:** Engineering82> **License:** MIT83> **Source Repo:** `neekware/dojo-skills`84> **Source Bucket:** `engineering`85> **Original Path:** `engineering/env-secrets-manager`
Run npx skillmds@latest add neekware/env-secrets-manager-2 in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Env & Secrets Manager It is listed under Coding & Dev Tools on SkillMD.
This skill has not completed SkillMD's automated safety review yet. Independent scanners report: SkillSpector: PASS, Skill Scanner: PASS. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
neekware (@neekware) published this skill. Their other Agent Skills are listed on their SkillMD profile.