PromptShop

Env Secrets Manager

It focuses on auditing, drift awareness, and rotation readiness

Install

npx promptshop add env-secrets-manager

Details

What This Skill Does

The Env & Secrets Manager skill manages environment-variable hygiene and secrets safety across local development and production workflows. It focuses on auditing, drift awareness, and rotation readiness. This skill is useful for security, devops, and development teams.

When to Use

Before pushing commits that touched env/config filesDuring security audits and incident triageWhen onboarding contributors who need safe env conventionsWhen validating that no obvious secrets are hardcodedScanning a repository for likely secret leaksValidating no obvious secrets are hardcoded

Key Features

Provides guidance for .env and .env.example lifecycleDetects secret leaks in repository working treesProvides severity-based findings for likely credentialsOffers operational pointers for rotation and containmentProvides integration-ready outputs for CI checksIdentifies common pitfalls like committing real values in .env.example

## Overview

Manage environment-variable hygiene and secrets safety across local development and production workflows. This skill focuses on practical auditing, drift awareness, and rotation readiness.

Core Capabilities

.env and .env.example lifecycle guidance Secret leak detection for repository working trees Severity-based findings for likely credentials Operational pointers for rotation and containment Integration-ready outputs for CI checks

When to Use

Before pushing commits that touched env/config files During security audits and incident triage When onboarding contributors who need safe env conventions When validating that no obvious secrets are hardcoded

Quick Start

Scan a repository for likely secret leaks

python3 scripts/env_auditor.py /path/to/repo

JSON output for CI pipelines python3 scripts/env_auditor.py /path/to/repo --json

Recommended Workflow

Run scripts/env_auditor.py on the repository root. Prioritize critical and high findings first. Rotate real credentials and remove exposed values. Update .env.example and .gitignore as needed. Add or tighten pre-commit/CI secret scanning gates.

Reference Docs

references/validation-detection-rotation.md references/secret-patterns.md

Common Pitfalls

Committing real values in .env.example Rotating one system but missing downstream consumers Logging secrets during debugging or incident response Treating suspected leaks as low urgency without validation

Best Practices

Use a secret manager as the production truth. Keep dev env files local and gitignored. Enforce detection in CI before merge. Re-test application paths immediately after credential rotation. Env & Secrets Manager

Tier: POWERFUL Category: Engineering Domain: Security / DevOps / Configuration Management

Overview

Manage environment-variable hygiene and secrets safety across local development and production workflows. This skill focuses on practical auditing, drift awareness, and rotation readiness.

Core Capabilities

.env and .env.example lifecycle guidance Secret leak detection for repository working trees Severity-based findings for likely credentials Operational pointers for rotation and containment Integration-ready outputs for CI checks

When to Use

Before pushing commits that touched env/config files During security audits and incident triage When onboarding contributors who need safe env conventions When validating that no obvious secrets are hardcoded

Quick Start

Scan a repository for likely secret leaks

python3 scripts/env_auditor.py /path/to/repo

JSON output for CI pipelines python3 scripts/env_auditor.py /path/to/repo --json

Recommended Workflow

Run scripts/env_auditor.py on the repository root. Prioritize critical and high findings first. Rotate real credentials and remove exposed values. Update .env.example and .gitignore as needed. Add or tighten pre-commit/CI secret scanning gates.

Reference Docs

references/validation-detection-rotation.md references/secret-patterns.md

Common Pitfalls

Committing real values in .env.example Rotating one system but missing downstream consumers Logging secrets during debugging or incident response Treating suspected leaks as low urgency without validation

Best Practices

Use a secret manager as the production truth. Keep dev env files local and gitignored. Enforce detection in CI before merge. Re-test application paths immediately after credential rotation.