Env Secrets Manager
It focuses on auditing, drift awareness, and rotation readiness
Install
npx promptshop add env-secrets-managerDetails
What This Skill Does
The Env & Secrets Manager skill manages environment-variable hygiene and secrets safety across local development and production workflows. It focuses on auditing, drift awareness, and rotation readiness. This skill is useful for security, devops, and development teams.
When to Use
Before pushing commits that touched env/config filesDuring security audits and incident triageWhen onboarding contributors who need safe env conventionsWhen validating that no obvious secrets are hardcodedScanning a repository for likely secret leaksValidating no obvious secrets are hardcoded
Key Features
Provides guidance for .env and .env.example lifecycleDetects secret leaks in repository working treesProvides severity-based findings for likely credentialsOffers operational pointers for rotation and containmentProvides integration-ready outputs for CI checksIdentifies common pitfalls like committing real values in .env.example
## Overview
Manage environment-variable hygiene and secrets safety across local development and production workflows. This skill focuses on practical auditing, drift awareness, and rotation readiness.
Core Capabilities
.env and .env.example lifecycle guidance Secret leak detection for repository working trees Severity-based findings for likely credentials Operational pointers for rotation and containment Integration-ready outputs for CI checks
When to Use
Before pushing commits that touched env/config files During security audits and incident triage When onboarding contributors who need safe env conventions When validating that no obvious secrets are hardcoded
Quick Start
Scan a repository for likely secret leaks
python3 scripts/env_auditor.py /path/to/repo
JSON output for CI pipelines python3 scripts/env_auditor.py /path/to/repo --json
Recommended Workflow
Run scripts/env_auditor.py on the repository root. Prioritize critical and high findings first. Rotate real credentials and remove exposed values. Update .env.example and .gitignore as needed. Add or tighten pre-commit/CI secret scanning gates.
Reference Docs
references/validation-detection-rotation.md references/secret-patterns.md
Common Pitfalls
Committing real values in .env.example Rotating one system but missing downstream consumers Logging secrets during debugging or incident response Treating suspected leaks as low urgency without validation
Best Practices
Use a secret manager as the production truth. Keep dev env files local and gitignored. Enforce detection in CI before merge. Re-test application paths immediately after credential rotation. Env & Secrets Manager
Tier: POWERFUL Category: Engineering Domain: Security / DevOps / Configuration Management
Overview
Manage environment-variable hygiene and secrets safety across local development and production workflows. This skill focuses on practical auditing, drift awareness, and rotation readiness.
Core Capabilities
.env and .env.example lifecycle guidance Secret leak detection for repository working trees Severity-based findings for likely credentials Operational pointers for rotation and containment Integration-ready outputs for CI checks
When to Use
Before pushing commits that touched env/config files During security audits and incident triage When onboarding contributors who need safe env conventions When validating that no obvious secrets are hardcoded
Quick Start
Scan a repository for likely secret leaks
python3 scripts/env_auditor.py /path/to/repo
JSON output for CI pipelines python3 scripts/env_auditor.py /path/to/repo --json
Recommended Workflow
Run scripts/env_auditor.py on the repository root. Prioritize critical and high findings first. Rotate real credentials and remove exposed values. Update .env.example and .gitignore as needed. Add or tighten pre-commit/CI secret scanning gates.
Reference Docs
references/validation-detection-rotation.md references/secret-patterns.md
Common Pitfalls
Committing real values in .env.example Rotating one system but missing downstream consumers Logging secrets during debugging or incident response Treating suspected leaks as low urgency without validation
Best Practices
Use a secret manager as the production truth. Keep dev env files local and gitignored. Enforce detection in CI before merge. Re-test application paths immediately after credential rotation.