Nikodem — Secrets Management & Workload Identity Engineer AI Skill
Instant download · 30-day money-back guarantee. Pay once, keep forever — no subscription. Refund policy
Eliminate static secrets: find the sprawl, move to short-lived and federated credentials, and make rotation something that actually happens.
- Secret sprawl discovery and CI scanning with tuned signal
- Vault and cloud secret store policy and dynamic credentials
- Workload identity federation, OIDC keyless CI, SPIFFE and IRSA
- Rotation, break-glass and the post-leak rotate-and-hunt playbook
Platform and security teams with cloud keys in CI, secrets in repos, and a rotation policy nobody has ever executed.A secrets management and workload identity engineer bills $130+/hr, this is one file, yours forever.
Drop Nikodem into Claude and get a secrets engineer whose goal is that the credential you are trying to protect stops existing.
Nikodem owns machine identity and the secrets that should not be there: secret sprawl discovery across repositories, CI logs, container images, config maps, wikis and ticketing systems, scanning in pre-commit and CI with the false-positive problem handled, centralised secret stores including HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager and CyberArk with auth methods, policy design and dynamic short-lived credentials, workload identity federation and OIDC-based keyless authentication so CI never holds a static cloud key, SPIFFE and SPIRE, Kubernetes service accounts, IRSA and pod identity, mTLS and service mesh identity, rotation that actually happens including the credential three systems hardcode, break-glass credential storage, database and third-party credential brokering, the difference between encrypting a secret and controlling access to it, and the post-leak playbook of rotate, invalidate, hunt for use and purge history.
What you get
- →Secret sprawl discovery and CI scanning with tuned signal
- →Vault and cloud secret store policy and dynamic credentials
- →Workload identity federation, OIDC keyless CI, SPIFFE and IRSA
- →Rotation, break-glass and the post-leak rotate-and-hunt playbook
How to install
Download the .skill package, open Claude, paste SKILL.md into your Project Instructions or system prompt, describe your requirement, and Nikodem builds the answer. Includes a full worked example so you see exactly what you get.
# Nikodem - Secrets Management & Workload Identity Engineer You are Nikodem, a senior secrets management and workload identity engineer. Your best outcome is that the static credential no longer exists. ## How you work 1. On a leak: rotate, invalidate, hunt for use, then worry about history 2. Find the sprawl everywhere text is stored, not just in code 3. Centralise, then move to dynamic and short-lived credentials 4. Replace static cloud keys with OIDC workload identity federation 5. Design rotation that runs itself, and name what cannot be rotated yet Rotate any credential you believe exposed before analysis is complete. Never write live secrets into files or tickets.
Excerpt from the actual file you'll download.
Four steps. Any AI chat.
- 01Download the file
After checkout, the download link lands in your inbox. Save the file anywhere on your device.
- 02Open your AI chat
Claude, ChatGPT, Gemini, Grok, or Copilot — whichever one you already use.
- 03Paste the file contents
Drop it into the system prompt, Project instructions, or custom instructions field.
- 04Start working
Your AI is now configured as a specialist. Ask it anything inside its domain.
No technical knowledge required. No subscription. Pay once, keep forever.
Works with every major AI chat.
Drop the file into your AI's system prompt, Project instructions, or custom instructions. No setup. No code. No vendor lock-in.
- Claude
- ChatGPT
- Gemini
- Grok
- Copilot
Works with any AI chat that accepts a system prompt or custom instructions.
Ready to specialise your AI?
One drop-in file. Pay once, keep forever — works with Claude & ChatGPT.