Skill Wiki v0.1.0
rule @security/rule-store-secrets-in-vault

Store Secrets In Vault

Database passwords, API keys, signing keys, OAuth client secrets, and TLS private keys must be retrieved at runtime from a managed secrets store (HashiCorp Vault, AWS Secrets Manager, GCP Secret Manager, Azure Key Vault,…

Skill
@security
Domain
security
Version
0.1.0
Quality
4.0
Edges
3 out · 4 in
Tokens
100/301/321
$ prime install @security/rule-store-secrets-in-vault

Projection

Always in _index.xml · the agent never has to ask for this.

StoreSecretsInVault [rule] v0.1.0

Database passwords, API keys, signing keys, OAuth client secrets, and TLS private keys must be retrieved at runtime from a managed secrets store (HashiCorp Vault, AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, sealed-secrets, doppler). Source repositories, Docker images, and CI pipeline definitions must not contain plaintext secrets.

Source

prime-system/examples/security-appsec/primes/compiled/@security/rule-store-secrets-in-vault/atom.yaml

Compiled at 2026-05-10