secrets-management (CI/CD)
Secure secrets handling for CI/CD using Vault, AWS Secrets Manager, and native platform stores.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for secrets-management (CI/CD), derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
An Agent Skill that guides the agent to store, rotate, and inject credentials in CI/CD pipelines without hardcoding. It supplies patterns for HashiCorp Vault, AWS Secrets Manager, least-privilege access, and automatic rotation. The skill body injects config templates the agent applies to pipeline files.
Key features and capabilities
- Vault and AWS Secrets Manager integration patterns
- Automatic secret rotation guidance
- Least-privilege access enforcement
Use cases
- Securing CI/CD credentials
- Rotating API keys and DB passwords