SuoSuo Vault
Paste the following prompt into your AI chat to install this skill:
Please follow https://skillhub.cn/install/skillhub.md to install @user_7c56bd60/suosuo.
About this skill
Problem
In multi-skill and multi-agent projects, secrets often spread across .env, scripts, temporary variables, and session logs. The real issue is not missing encryption, but secrets reappearing in agent calls, WAL logs, and delivered artifacts. Manual review is fragile. SuoSuo Vault breaks key management into checkable stages: storage, injection, scanning, redaction, and delivery gates.
How It Works
The skill uses AES-256 encrypted storage as a vault. JSON holds credentials, and SHA-256 verifies integrity. For sub-agents, it injects secrets into isolated sessions instead of leaving them in the main process. Leak scanning covers patterns such as sk-, ark-, AKID, KEY=, and long base64 strings. WAL logs are recursively redacted for key names, value prefixes, and long strings, reducing the chance that runtime logs become leak paths. Delivery gates quantify risk with scores such as vault_managed=1.0 to hardcoded=0.1, blocking obvious hard-coded or weakly managed secrets at the final checkpoint.
Boundaries
It fits multi-agent projects, CI/CD secret checks, audit compliance, and sub-agent secret distribution. It does not replace a full KMS, permission system, network isolation, or identity provider. If Vault or KMS already exists, treat this as a project-level management and validation layer.
Use Cases
- Use it when a multi-agent project needs to replace exposed credentials in scripts with encrypted vault storage and session-scoped injection.
- Run a pre-release check that detects sk-, AKID, KEY=, and long base64 patterns in build artifacts and blocks hard-coded secrets.
- Redact WAL event logs during audit review so key names, value prefixes, and long strings are hidden while evidence remains traceable.
- Migrate existing .env credentials into AES-256 managed storage and validate delivery risk with a quantified secret security score before handoff.
Best For
- Backend engineers integrating multi-agent systems who need to consolidate scattered API keys from scripts into encrypted vault storage for review.
- DevOps engineers who need CI/CD checks to block hard-coded keys and suspicious long base64 strings before release in delivery pipelines.
- SREs or security engineers who need to redact WAL event logs for key names, prefixes, and long strings during audits.
- Project leads migrating existing .env credentials and wanting a quantified score to manage secret onboarding risk step by step.
Related Skills
Automatically indexes Gradle-cached AAR/JAR dependency classes and returns library coordinates, versions, and public APIs by fully qualified name, using only the Python standard library.
Codifies AMT and YourMT3 training conventions, script patterns, hyperparameters, precision, checkpoints, and NaN safeguards.
Retrieve relevant chunks from a customer-managed PKM dataset by dataset_id and return concise, source-annotated answers.
Convert PRDs, user stories, or functional specs into prioritized test-point checklists covering functional, business-rule, boundary, exception, and non-functional dimensions.