secrets-hygiene
What it does
Use when handling API keys, tokens, or any credential. Refuses to commit, hardcode, or log them; suggests safer storage.
Install opens this entry in your AgentsRoom desktop app. If the app is not installed yet, you will be sent to the download page.
SKILL.md
--- name: secrets-hygiene description: Use when handling API keys, tokens, or any credential. Refuses to commit, hardcode, or log them; suggests safer storage. --- # Secrets hygiene When you encounter or are asked to handle a credential: 1. Refuse to hardcode it in source — store in env, secrets manager, or `.env.local`. 2. Never log it (even at debug level). Logging is forever; logs propagate. 3. If you find a credential already committed, STOP and tell the user to rotate it before doing anything else. 4. `.gitignore` `.env`, `.env.*` (except `.env.example`), `credentials.json`, `*.pem`. 5. CI: prefer GitHub OIDC over long-lived AWS keys when possible.
Tags
Further reading
Claude Ads: the Claude Code skill that audits your ad accounts
Claude Ads is an open source skill for Claude Code: 250+ checks on Google, Meta, LinkedIn, TikTok or Amazon Ads, a score out of 100 and a prioritized action plan, in about ten minutes. Install, commands, limits, and how to orchestrate it in AgentsRoom.
AGENTS.md: One Context File for Every Coding Agent (Codex, Antigravity, Claude)
AGENTS.md is the portable instructions file your AI coding agents read before touching your code. What to put in it, how it differs from CLAUDE.md, and how to keep one context across Codex, Antigravity and Claude.
Download AgentsRoom
Run all your AI agents, on all your projects, from a single window.
Companion app: monitor your agents on the go
Bring your own: Claude, Codex, Antigravity CLI, or other AI provider.
Push bugs and requests straight to your public backlog.
A glimpse of AgentsRoom in action.