From vanguard-frontier-agentic
Gates DEW/KMS key deletion and disable operations with encrypted resource enumeration, pending-window verification, and explicit operator approval to prevent permanent data loss.
How this skill is triggered — by the user, by Claude, or both
Slash command
/vanguard-frontier-agentic:huawei-live-kms-key-destruction-guardThis skill is limited to the following tools:
The summary Claude sees in its skill listing — used to decide when to auto-load this skill
Act as the guarded live Huawei Cloud operator for huawei-live-kms-key-destruction-guard work. Gate DEW/KMS key deletion and disable operations. Insist on encrypted resource enumeration, pending-window verification, MLPS Level 3 incident obligation assessment, and explicit operator approval before any key deletion proceeds. Treat any incomplete resource enumeration or MLPS Level 3 workload as a ...
Act as the guarded live Huawei Cloud operator for huawei-live-kms-key-destruction-guard work. Gate DEW/KMS key deletion and disable operations. Insist on encrypted resource enumeration, pending-window verification, MLPS Level 3 incident obligation assessment, and explicit operator approval before any key deletion proceeds. Treat any incomplete resource enumeration or MLPS Level 3 workload as a stop condition.
Use this skill when:
Do not use this skill when:
This skill requires the 6-step live-guard gate from the maestro. See skills/huawei/huawei-maestro/SKILL.md for the full gate protocol. The 6 steps are:
Before scheduling any KMS key for deletion, verify all of the following:
The operator must explicitly state all of the following before key deletion is scheduled:
<KEY_ID> (<KEY_ALIAS>) in account <ACCOUNT_ID>, enterprise project <ENTERPRISE_PROJECT>."<DAYS> days and I understand the key is permanently destroyed after this window."<LIST_ENCRYPTED_RESOURCES>."[IS / IS NOT] subject to MLPS Level 3 classification."For MLPS Level 3 classified keys, additionally require:
Pending Deletion with the correct deletion date.npx claudepluginhub raishin/vanguard-frontier-agentic --plugin vanguard-frontier-agenticGates OVHcloud KMS key version destruction with five mandatory checks: key ID/URN, approving identity, usage audit, waiting period, and rollback plan. Use when a user requests destruction or rotation.
Guides encryption key lifecycle with envelope encryption, cloud KMS, rotation schedules, and HSM-backed storage to prevent long-lived plaintext keys.
Expert guidance for Azure Key Vault development covering troubleshooting, best practices, security, limits, and integrations with Private Link, Event Grid, Databricks, DigiCert, RBAC, and ARM/Bicep/Terraform.