About
This skill creates a tracked task to immediately revoke and rotate any exposed secret, such as keys or tokens found in chats, logs, or commits. It centralizes the response into a single action with escalation, preventing the issue from being merely noted and forgotten. Use it when a live credential is discovered where it shouldn't be, triggering a mandatory rotation workflow.
Quick Install
Claude Code
Recommendednpx skills add avelikiy/great_cto -a claude-code/plugin add https://github.com/avelikiy/great_ctogit clone https://github.com/avelikiy/great_cto.git ~/.claude/skills/secrets-rotationCopy and paste this command in Claude Code to install this skill
Documentation
secrets-rotation — an exposed secret is spent
Deleting the message, rewriting git history or redacting the log does not un-expose a secret: the transcript, the remote, the backup and the provider's own logs already hold it. The only fix is to make the exposed value worthless — revoke it and issue a new one.
What went wrong on real projects is not ignorance of that. It is that the rotation was remembered instead of tracked: "rotate the exchange API keys" was carried forward through seven session logs; "keys that passed through chat" appeared in seven summaries of another project; a monitoring token pasted in plain text was never rotated. Each session wrote the reminder again and nobody owned it.
The moment you see one
-
Never repeat the value. Not in your answer, not in a task title, not in a log, not in a commit message. Name its kind and where it is: "OpenRouter API key, in the operator's message of 22.09, 14:10".
scripts/lib/secret-patterns.mjsnames the kind. -
Say it plainly, first line: this key is compromised; revoking it is the only fix.
-
Open one task, not a note — in Beads if the project has it:
bd create "Rotate <kind> exposed in <where> on <date>" -t bug -p 0 \ -d "Exposed: <where>. Revoke at <provider console>, issue new, store in <secret store>, redeploy <consumers>, prove the old one is rejected."Priority 0 for a production credential or anything that moves money; 1 otherwise.
-
If you can rotate it, rotate it — the operator asked you to handle it, or your task covers that system. If it needs the operator (a provider console you cannot reach, a hardware token), the task's first line says exactly what they must click.
Done means the old value is refused
A rotation is closed with evidence, not with "rotated":
- the new value is in the secret store the code reads — never in
CLAUDE.md,preferences.md, memory files, a README or any file that is loaded into a model's context (one key in a preferences file reached 605 transcripts); - every consumer was redeployed and uses it (
deploy-landed, config check); - a call with the old value fails — 401/403 from the provider. That is the proof.
Carrying it forward
An open rotation task older than 48 hours goes to the top of the next session's report
and of /inbox, with its age. Do not re-list it in the session log as a fresh item —
link the task. Re-writing a reminder is how the seven-session carry-over happened.
GitHub Repository
Frequently asked questions
What is the secrets-rotation skill?
secrets-rotation is a Claude Skill by avelikiy. Skills package instructions and resources that Claude loads on demand, so Claude can perform secrets-rotation-related tasks without extra prompting.
How do I install secrets-rotation?
Use the install commands on this page: add secrets-rotation to Claude Code as a plugin, or clone its repository into your skills directory, then restart Claude so it picks up the skill.
What category does secrets-rotation belong to?
secrets-rotation is in the Documents category.
Is secrets-rotation free to use?
Yes. secrets-rotation is listed on AIMCP and free to install.
Related Skills
This skill provides semantic versioning (semver) guidelines and changelog formatting standards for software releases. Use it when preparing releases to correctly increment version numbers (major/minor/patch) and structure changelog entries. It includes rules for pre-release identifiers and clear examples for developers.
This skill formats Git commit messages according to the Conventional Commits standard. It provides templates and type definitions (like `feat`, `fix`, `refactor`) to ensure consistency when writing or reviewing commits. Use it during the commit process to create clear, structured commit history.
nano-pdf is a CLI tool that lets developers edit PDFs using natural-language instructions, like changing text or fixing typos on specific pages. It's ideal for quick, programmatic PDF modifications directly from the terminal. Always verify the output, as page numbering can vary between versions.
This skill provides high-performance tokenization using HuggingFace's Rust-based library, processing 1GB of text in under 20 seconds. It supports BPE, WordPiece, and Unigram algorithms while enabling custom tokenizer training and alignment tracking. Use it when you need production-fast tokenization or to build custom tokenizers integrated with the transformers ecosystem.
