Guides detection, emergency rotation, and prevention of leaked secrets and credentials across source code, git history, CI pipelines, logs, and infrastructure config. Use when someone says "I think I committed an API key", "a secret leaked", "scan the repo for credentials", "how should we store secrets", or is setting up secrets management for an application, CI/CD, or Kubernetes. Do NOT use for detecting or redacting personal data like names, emails, or SSNs - use pii-scrubber instead; for routine non-secret environment configuration on Vercel, use vercel-env-management.
Click to play with sound.
---
name: Secrets Hygiene
description: Guides detection, emergency rotation, and prevention of leaked secrets and credentials across source code, git history, CI pipelines, logs, and infrastructure config. Use when someone says "I think I committed an API key", "a secret leaked", "scan the repo for credentials", "how should we store secrets", or is setting up secrets management for an application, CI/CD, or Kubernetes. Do NOT use for detecting or redacting personal data like names, emails, or SSNs - use pii-scrubber instead; for routine non-secret environment configuration on Vercel, use vercel-env-management.
---
# Secrets Hygiene
A leaked secret is a live incident until rotated. Treat any suspected exposure as confirmed until proven otherwise - the cost of an unnecessary rotation is always lower than the cost of a breach. The costly mistake this skill prevents is the instinctive wrong move: deleting the commit, force-pushing, and considering it handled while the key stays valid in every fork, clone, and scraper cache.
## Operating procedure
The order is deliberate: rotation comes before investigation because every minute of analysis is a minute the credential works for an attacker.
### Step 1: Gather inputs
- What leaked (or might have): credential type, issuing system (cloud console, API portal, identity provider), and the privilege it carries.
- Where and when: repo and commit, CI log, chat message, Docker image; how long it has been exposed. If unknown, assume the worst plausible window and label it a guess.
- Whether the repo is public, has forks, or has ever been public.
- Who can execute the rotation and whether a rotation runbook exists for this credential.
For prevention-mode engagements (no active leak), skip to Step 4.
### Step 2: Respond to the suspected leak - in order, without delay
1. Rotate the credential immediately through the issuing system. Do not wait to confirm exposure first. Target: rotation started within 1 hour of discovery for any production credential.… load the full skill through Skill Me