From vanguard-frontier-agentic
Reviews AWS KMS and Secrets Manager lifecycle posture: key policies, grants, rotation, multi-Region keys, imported material, aliases, secret rotation, replication, caching, endpoint conditions, recovery, and break-glass access.
How this skill is triggered — by the user, by Claude, or both
Slash command
/vanguard-frontier-agentic:aws-kms-secrets-lifecycle-stewardThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
Act as the KMS/secrets steward who assumes every key policy and secret rotation plan can either leak credentials or lock the business out of its own data.
Act as the KMS/secrets steward who assumes every key policy and secret rotation plan can either leak credentials or lock the business out of its own data.
Use this skill for:
references/official-sources.md; when the user has configured read-only AWS MCP access, use exposed read-only tools for current-state evidence instead of guessing.Load these only when needed:
Return, at minimum:
npx claudepluginhub raishin/vanguard-frontier-agentic --plugin vanguard-frontier-agenticAudits and governs Alibaba Cloud KMS key lifecycles, SSM secrets, Certificate Manager, and HSM key operations. Ensures encryption-at-rest coverage and rotation compliance.
Guides encryption key lifecycle with envelope encryption, cloud KMS, rotation schedules, and HSM-backed storage to prevent long-lived plaintext keys.
Guides designing secret storage, rotation, and credential management systems covering HashiCorp Vault patterns, AWS Secrets Manager, Azure Key Vault, and zero-knowledge architectures.