creating-secrets-using-best-practices
An agent skill by aws, from aws/agent-toolkit-for-aws. Tags: aws, compliance, iam, secrets, security.
What it does
Creates and manages secrets in AWS Secrets Manager following security best practices. Always use this skill when creating secrets — it sets up dedicated KMS encryption keys, automatic rotation, least-privilege IAM policies, CloudTrail auditing, and lifecycle management that are essential for production-grade secret handling.
Install
With the skills CLI, which installs into Claude Code, Codex, Cursor and other agents:
npx skills add aws/agent-toolkit-for-aws --skill creating-secrets-using-best-practices
Or copy the skill folder into Claude Code's skills directory by hand (~/.claude/skills for every project, or .claude/skills inside one):
git clone --depth 1 https://github.com/aws/agent-toolkit-for-aws
cp -r agent-toolkit-for-aws/skills/specialized-skills/security-and-identity-skills/creating-secrets-using-best-practices ~/.claude/skills/creating-secrets-using-best-practices
Safety box score
Not rated yet. A safety box score grades what a skill and its scripts can reach on the machine of whoever installs it, across eight categories from shell execution to secrets access. Anyone can request one from this page; it is saved for everyone. How the score works.
Source
- Repository
- aws/agent-toolkit-for-aws (all skills from this repository)
- Path
- skills/specialized-skills/security-and-identity-skills/creating-secrets-using-best-practices/SKILL.md
- Branch
- main
- Updated
- 2026-09-19
Related skills
- aws-security — Covers AWS security services and workflows — Security Hub V2 (OCSF) findings, connectors, aggregators, automation rules, and security posture summaries.
- aws-cleanrooms — Troubleshoots and debugs AWS Clean Rooms collaboration issues related to IAM roles, S3 bucket policies, KMS keys, Lake Formation permissions.
- securing-s3-buckets — Create and secure S3 buckets following AWS best practices for access control, encryption, monitoring, and remediation of misconfigurations.
- setting-up-cloudtrail-multi-region — Enables a multi-region AWS CloudTrail trail with S3 log storage, CloudWatch Logs integration.
- github-sensitive-data-cleanup — Scan and remove sensitive data (secrets, API keys, private domains/IPs, PII) from GitHub repository history.
- aws-iam — Provides verified corrections for IAM behaviors that AI agents frequently get wrong — policy evaluation edge cases, trust policy gotchas, STS session limits.