env-secrets-manager
>
它会碰到什么
逐条看命中(30 条严重或高危)
- 严重
references/best-practices-and-troubleshooting.md:7cred-paths- **Committing .env to git** — add `.env` to .gitignore on day 1; use pre-commit hooks as a safety net
- 严重
references/best-practices-and-troubleshooting.md:7cred-paths- **Committing .env to git** — add `.env` to .gitignore on day 1; use pre-commit hooks as a safety net
- 严重
references/best-practices-and-troubleshooting.md:31cred-paths| Startup validation fails with MISSING for a set variable | Variable is set in `.env` but the app reads from a different file (e.g., `.env.local` overrides it
- 严重
references/best-practices-and-troubleshooting.md:31cred-paths| Startup validation fails with MISSING for a set variable | Variable is set in `.env` but the app reads from a different file (e.g., `.env.local` overrides it
- 严重
references/best-practices-and-troubleshooting.md:31cred-paths| Startup validation fails with MISSING for a set variable | Variable is set in `.env` but the app reads from a different file (e.g., `.env.local` overrides it
- 严重
references/best-practices-and-troubleshooting.md:36cred-paths| `.env.example` accidentally contains real credentials | Developer copied `.env` to `.env.example` without stripping values | Run the auto-generation script to
- 严重
references/best-practices-and-troubleshooting.md:36cred-paths| `.env.example` accidentally contains real credentials | Developer copied `.env` to `.env.example` without stripping values | Run the auto-generation script to
- 严重
references/best-practices-and-troubleshooting.md:36cred-paths| `.env.example` accidentally contains real credentials | Developer copied `.env` to `.env.example` without stripping values | Run the auto-generation script to
- 严重
references/best-practices-and-troubleshooting.md:36cred-paths| `.env.example` accidentally contains real credentials | Developer copied `.env` to `.env.example` without stripping values | Run the auto-generation script to
- 严重
references/env-file-structure.md:1cred-paths# .env File Structure & Startup Validation
- 严重
references/env-file-structure.md:5cred-paths## .env File Structure
- 严重
references/env-file-structure.md:49cred-paths```
- 严重
references/env-file-structure.md:53cred-paths.env.test → Test environment. May be committed if no secrets.
- 严重
references/env-file-structure.md:61cred-paths# Environment files
- 严重
references/env-file-structure.md:62cred-paths.env
- 严重
references/env-file-structure.md:63cred-paths.env.local
- 严重
references/env-file-structure.md:64cred-paths.env.*.local
- 严重
references/env-file-structure.md:65cred-paths.env.development
- 严重
references/env-file-structure.md:66cred-paths.env.staging
- 严重
references/env-file-structure.md:76cred-pathscredentials.json
- 严重
references/env-file-structure.md:80cred-paths.aws/credentials
- 严重
references/secret-manager-integration.md:56cred-pathsdoppler secrets download --no-file --format env > .env.local
- 严重
scripts/env_sync_checker.py:4cred-pathsLoads multiple .env files (e.g., .env.development, .env.staging, .env.production)
- 严重
scripts/env_sync_checker.py:4cred-pathsLoads multiple .env files (e.g., .env.development, .env.staging, .env.production)
- 严重
scripts/env_sync_checker.py:4cred-pathsLoads multiple .env files (e.g., .env.development, .env.staging, .env.production)
- 严重
scripts/env_sync_checker.py:4cred-pathsLoads multiple .env files (e.g., .env.development, .env.staging, .env.production)
- 严重
scripts/env_sync_checker.py:12cred-pathspython env_sync_checker.py .env.dev .env.staging .env.prod
- 严重
scripts/env_sync_checker.py:12cred-pathspython env_sync_checker.py .env.dev .env.staging .env.prod
- 严重
scripts/env_sync_checker.py:12cred-pathspython env_sync_checker.py .env.dev .env.staging .env.prod
- 严重
scripts/env_sync_checker.py:13cred-pathspython env_sync_checker.py .env.* --baseline .env.example --json
这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。
技能内容
Env & Secrets Manager
Complete environment variable and secrets management lifecycle: .env file structure across dev/staging/production, .env.example auto-generation that strips sensitive values, required-variable validation at startup, secret leak detection in git history, credential rotation playbooks, environment drift detection, and integration with HashiCorp Vault, AWS SSM, 1Password CLI, and Doppler.
Core Capabilities
- .env lifecycle — structured layout with categorized sections, auto-generated
.env.example(strips secrets), environment-specific files, and fail-fast startup validation. - Secret leak detection — regex scan of git history, working tree, and staged files; pre-commit hooks; patterns for API keys, tokens, passwords, private keys.
- Credential rotation — per-secret playbooks, scope analysis, zero-downtime dual-read rotation, post-rotation verification and monitoring.
- Secret manager integration — HashiCorp Vault (KV v2 + OIDC), AWS SSM Parameter Store (KMS), 1Password CLI (template injection), Doppler (project/config).
- Drift detection — compare variable key sets between staging and production and report missing/extra keys.
When to Use
- Setting up a new project — scaffold .env.example and validation.
- Before every commit — scan for accidentally staged secrets.
- Post-incident — rotate leaked credentials systematically.
- Onboarding developers — provide complete environment setup.
- Auditing — detect environment drift between staging and production.
- Compliance — demonstrate secret management practices.
Clarify First
Before running, confirm these inputs. If any is unknown or vague, ASK — do not assume:
- [ ] Task — scaffold/validate a
.env, scan for leaked secrets, or check env drift (selectsenv_validator.pyvssecret_scanner.pyvsenv_sync_checker.py) - [ ] Target paths — the
.env/.env.examplefiles or directory to scan (the input the tools read) - [ ] Secret manager — Vault, AWS SSM, 1Password, or Doppler (determines the integration and rotation commands generated)
Stop rule: ask only the 2-3 that most change the output. If the user says "just draft it," proceed and list your assumptions at the top of the artifact.
Tools
| Tool | Purpose | Command |
|------|---------|---------|
| env_validator.py | Validate a .env against .env.example: missing/extra vars, empty secrets, leaked credentials | python scripts/env_validator.py .env.example .env --strict --check-secrets |
| secret_scanner.py | Scan a directory/file for hardcoded secrets via pattern matching | python scripts/secret_scanner.py ./src --severity high --json |
| env_sync_checker.py | Compare env configs across dev/staging/prod and report drift | python scripts/env_sync_checker.py .env.* --baseline .env.example |
References
Load the reference that matches the task — keep this file lean and pull detail on demand:
- [references/env-file-structure.md](references/env-file-structure.md) — canonical
.envlayout, the.env.*file hierarchy, required.gitignorepatterns, and the full Python startup-validation script. Read when scaffolding a project or wiring validation. - [references/leak-detection-and-rotation.md](references/leak-detection-and-rotation.md) — the git-history secret scanner, pre-commit hook, the 4-step credential rotation playbook (scope, generate, dual-write, verify), and the environment-drift detection script. Read when scanning for leaks or rotating credentials.
- [references/secret-manager-integration.md](references/secret-manager-integration.md) — concrete Vault, AWS SSM, and Doppler commands for storing, reading, and rotating secrets. Read when integrating a secret manager.
- [references/best-practices-and-troubleshooting.md](references/best-practices-and-troubleshooting.md) — common pitfalls, the 8 best practices, the troubleshooting table, and the success-criteria bar. Read when reviewing a setup or debugging.
Scope & Limitations
This skill covers:
.envfile scaffolding, hierarchy, and validation for any language/framework- Secret leak detection in git history, staged files, and working tree
- Credential rotation playbooks with zero-downtime dual-read strategy
- Integration patterns for HashiCorp Vault, AWS SSM, 1Password CLI, and Doppler
This skill does NOT cover:
- Runtime secret injection in Kubernetes (see
engineering/ci-cd-pipeline-builderfor deployment pipeline secrets) - Infrastructure-as-code for provisioning Vault clusters or SSM policies (see
engineering/ci-cd-pipeline-builder) - Application-level encryption at rest or in transit (see
engineering/api-design-reviewerfor API security patterns) - Identity and access management (IAM) role design or SSO/OIDC provider configuration (see
ra-qm-team/compliance skills for access control frameworks)
Integration Points
| Skill | Integration | Data Flow |
|-------|-------------|-----------|
| engineering/ci-cd-pipeline-builder | Inject secrets from Vault/SSM/Doppler into CI/CD pipeline stages | Rotation playbook outputs feed pipeline secret-update steps |
| engineering/dependency-auditor | Flag dependencies that bundle or require hardcoded credentials | Dependency audit findings trigger secret leak scans on affected repos |
| engineering/skill-security-auditor | Validate that no skill packages ship embedded secrets or credentials | Security audit references this skill's regex patterns for detection |
| engineering/codebase-onboarding | Include .env.example setup and secret-manager access in onboarding checklists | Onboarding workflow consumes the .env hierarchy and validation script |
| engineering/observability-designer | Monitor authentication failures post-rotation; alert on anomalous secret access | Post-rotation verification metrics flow into observability dashboards |
| ra-qm-team/soc2-compliance-auditor | Demonstrate secret management controls for SOC 2 CC6.1 and CC6.6 criteria | Rotation audit logs and access policies serve as SOC 2 evidence artifacts |
想直接用这个技能?
本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。