Skill registry
Agent infrastructurePublic skills

Credentials Management

Secure credential operations — request runtime secrets with scope validation, rotate keys on schedule, revoke on compromise, and audit all access.

What this skill teaches

A reusable playbook for a specific kind of work.

An MCP server tells an agent which actions are available. A skill adds the judgment around those actions: how to recognize the job, which sequence to follow, what to avoid, and how to decide that the result is complete.

Securely manage credentials — list available secrets, request runtime tokens, rotate keys, revoke access, and audit usage. Use when retrieving API keys, rotating secrets, checking credential metadata, auditing access, or validating secret scopes.

Architecture

How Credentials Management guides an ADK-Rust agent.

The skill stays readable and portable because it contains instructions rather than service credentials or business data. ADK-Rust supplies it to the agent, the agent chooses from its reviewed tool boundary, and the connected MCP server performs the authenticated operation.

01

User request

The agent receives a goal expressed in ordinary language.

02

Credentials Management skill

Matches intent, supplies the decision guide, and narrows the tool boundary.

03

ADK-Rust agent

Plans the workflow and streams each meaningful step through the runtime.

04

mcp-credentials-vault

Executes authenticated operations against the system that owns the capability.

05

Verified result

The skill's completion rules shape the evidence returned to the user.

Portable instructions: SKILL.md · Capability boundary: mcp-credentials-vault · Allowed tools: 8

Decision guide

How the agent turns a request into the right action.

These routes come directly from the skill instructions. They help the model recognize intent and select a focused tool or workflow instead of improvising across the entire capability surface.

01

"get secret", "API key", "token"?

request_runtime_secret / request_workload_token

02

"rotate", "renew", "refresh"?

rotate_credential

03

"revoke", "disable", "compromised"?

revoke_credential

04

"audit", "who accessed", "usage"?

audit_credential_access

05

"list", "what secrets", "available"?

list_credentials / get_credential_metadata

06

"validate", "scope", "permission"?

validate_secret_scope

Proven workflows

Repeatable sequences for useful outcomes.

A workflow joins several tool calls into a task the user actually recognizes. The skill explains the sequence and the intended result while ADK-Rust streams the agent's progress through the shared runtime.

011-2 calls

Request Secret

Scope check → deliver with TTL

021 calls

Rotate

Generate new → verify → retire old

031 calls

Revoke

Immediate invalidation

041 calls

Audit

Access log by credential/time

Tool boundary

The skill may use 8 documented tools.

This allowlist is declared by the skill. It keeps the agent focused on the actions needed for this job while mcp-credentials-vault retains responsibility for authentication, validation, and the connected system.

list_credentials
get_credential_metadata
request_runtime_secret
request_workload_token
rotate_credential
revoke_credential
audit_credential_access
validate_secret_scope

Working rules

What the agent should do.

  • Specify purpose/context when requesting secrets
  • Respect TTL — don't cache beyond expiry
  • Rotate on schedule, not just when compromised
  • Audit all access for compliance

Operating boundaries

What the agent should avoid.

  • NEVER log or display credential values in plain text
  • NEVER cache secrets beyond their TTL
  • Don't request broader scope than needed
  • Don't skip audit trail

Install and connect

Add the skill beside the capability it expects.

Install the repository where your ADK-Rust skill loader can discover it, connect mcp-credentials-vault, and confirm the declared tools are available before asking the agent to use the workflow.

Install the skill
git clone https://github.com/zavora-ai/skill-credentials-management.git \
  ~/.skills/skills/credentials-management
ADK-Rust loading shape
let skills = SkillLoader::from_dir("~/.skills/skills").await?;
let skill = skills.load("credentials-management").await?;

let agent = LlmAgentBuilder::new("agent")
    .instruction(skill.instructions())
    .tools(skill.allowed_tools(toolset)?)
    .build()?;

The repository's compatibility statement: Requires mcp-credentials-vault server connected.

Official documentation

Read the complete skill package.

The repository remains authoritative for its exact instructions, examples, helper scripts, assets, MCP requirements, license, and later updates.

Source record

Repository metadata for this skill entry.

View public repository ↗
License
Apache-2.0
Allowed tools
8
References
3
Revision
f6e91eee0584
Updated
May 31, 2026