Keep credentials out of source, logs and client bundles.
Scanned 9/3/2026
Install to Claude Code
npx -y skills add Andersseen/agentyx --skill secrets-handling --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Secrets Handling?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/andersseen-secrets-handling)More formats (shields.io, HTML) on the badges page.
---
name: secrets-handling
description: Keep credentials out of source, logs and client bundles.
---
# Secrets handling
A secret in version control is compromised the moment it is pushed, and rewriting history does not
undo it.
## Keep secrets out of the repository
Load credentials from environment variables or a secret manager. Commit a documented example file
with placeholder values, never the real ones.
## Rotate on exposure
Treat any secret that reached a repository, log, ticket or chat message as leaked. Rotate it before
removing it — deletion without rotation leaves the credential valid.
## Never log or serialize them
Redact credentials, tokens and keys in logs, error messages and crash reports. Review debug output
and third-party error reporters, which capture more surrounding context than expected.
## Understand the client boundary
Anything shipped to a browser or mobile app is public, regardless of build-time substitution. Only
publishable identifiers belong in client code; every real secret stays server side.
## Scan continuously
Run secret scanning in pre-commit hooks and in CI. Detection after the fact is far cheaper than an
incident, and cheaper still before the push.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.
Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation
SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.
Python backend development expertise for FastAPI, security patterns, database operations, Upstash integrations, and code quality. Use when: (1) Building REST APIs with FastAPI, (2) Implementing JWT/OAuth2 authentication, (3) Setting up SQLAlchemy/async databases, (4) Integrating Redis/Upstash caching, (5) Refactoring AI-generated Python code (deslopification), (6) Designing API patterns, or (7) Optimizing backend performance.
PTES-aligned adversarial security audit for backend, frontend, and mobile applications. Produces a CVSS-scored Hacker Report with verified PoCs and phased remediation.