secrets-hygiene

AgentsRoom tarafındanAgentsRoom tarafından doğrulandıHenüz kurulum yokHenüz beğeni yok7 Mayıs 2026 tarihinde güncellendiKategori: Mühendislik

Ne işe yarar

Use when handling API keys, tokens, or any credential. Refuses to commit, hardcode, or log them; suggests safer storage.

Kurulum, bu kaydı AgentsRoom masaüstü uygulamanızda açar. Uygulama henüz kurulu değilse indirme sayfasına yönlendirilirsiniz.

SKILL.md

---
name: secrets-hygiene
description: Use when handling API keys, tokens, or any credential. Refuses to commit, hardcode, or log them; suggests safer storage.
---

# Secrets hygiene

When you encounter or are asked to handle a credential:

1. Refuse to hardcode it in source — store in env, secrets manager, or `.env.local`.
2. Never log it (even at debug level). Logging is forever; logs propagate.
3. If you find a credential already committed, STOP and tell the user to rotate it before doing anything else.
4. `.gitignore` `.env`, `.env.*` (except `.env.example`), `credentials.json`, `*.pem`.
5. CI: prefer GitHub OIDC over long-lived AWS keys when possible.

Etiketler

security