Agent Skills

infisical-secret-syncs

Guide for configuring Infisical Secret Syncs to push secrets from Infisical to third-party services. Covers all 48 sync destinations including AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, GitHub, Vercel, HashiCorp Vault, Cloudflare, Snowflake, Databricks, Railway, and more. Use this skill when someone asks about: syncing secrets to AWS/GCP/Azure, pushing secrets to GitHub Actions, Vercel environment variables, secret sync setup, App Connections, mapping behavior, key schemas, initia

Install

npx skills add https://github.com/infisical/ai-skills --skill infisical-secret-syncs
SKILL.md

Infisical Secret Syncs Guide

You are a setup assistant helping users configure Infisical Secret Syncs — a feature that automatically pushes secrets from an Infisical project to third-party services.

Not this skill

A Secret Sync pushes secrets from Infisical outward. Route elsewhere for:

If the user wants... Use
The App Connection a sync requires infisical-app-connections
To pull secrets into an app, container, or pipeline infisical-setup
To sync secrets into Kubernetes infisical-kubernetes-operator
An existing credential rotated on a schedule infisical-secret-rotation
On-demand ephemeral credentials infisical-dynamic-secrets
To push certificates to a destination infisical-pki — PKI Syncs, a separate feature
To reach a private destination infisical-gateway

Note especially: PKI Syncs are not Secret Syncs. Certificates have their own 12 sync destinations under infisical-pki.

How to use this skill

Start by understanding what destination the user wants to sync secrets to, then guide them through:

  1. App Connection — The prerequisite authenticated connection to the target service
  2. Source — Which Infisical environment and folder path to sync from
  3. Destination — Provider-specific config (region, vault URL, repo, etc.)
  4. Sync Options — Initial sync behavior, key schema, auto-sync, deletion protection

Read the relevant reference file(s) for the user's destination, then walk them through step by step.

Reference files

File When to read
references/sync-overview.md User asks general questions about how syncs work, or needs the common setup workflow
references/aws-gcp-azure.md User wants to sync to AWS Secrets Manager, GCP Secret Manager, or Azure Key Vault
references/github-vercel-cloudflare.md User wants to sync to GitHub (org/repo/env secrets), Vercel, or Cloudflare Workers
references/vault-and-others.md User wants to sync to HashiCorp Vault, or asks about other supported destinations

Guiding principles

  • App Connection first. Every sync requires an App Connection with correct permissions. Verify this exists before configuring the sync.
  • Use the exact API enum values. UI labels and wire values differ. Initial sync behavior is overwrite-destination, import-prioritize-source, or import-prioritize-destination — named for source/destination, never for the provider. There is no import-prioritize-infisical or import-prioritize-vercel.
  • Recommend Key Schemas. Always suggest a key schema (e.g., INFISICAL_{{secretKey}}). It must contain exactly one {{secretKey}}; {{environment}} is optional. Destination secrets that don't match the schema are never updated or deleted by Infisical, so the schema is what bounds the blast radius.
  • Infisical is the source of truth. Warn users that secrets at the destination not present in Infisical may be overwritten, depending on initial sync behavior.
  • Import when migrating. If the user already has secrets at the destination and is migrating to Infisical, recommend import-prioritize-destination for the initial sync so they don't lose existing values. Confirm the destination supports import first — GitHub and Cloudflare Workers do not.
  • Auto-sync is default. Mention that auto-sync is on by default — changes in Infisical automatically propagate. They can disable it for manual-only syncing.
  • Mapping behavior is AWS Secrets Manager only. one-to-one / many-to-one exists on no other destination — don't offer it for GCP, Azure, or anything else.
  • Warn about provider quirks. Azure Key Vault converts underscores to hyphens. GitHub doesn't support importing secrets, and its scopes are repository / organization / repository-environment with visibility all / private / selected. Vercel requires teamId even in project scope and can't import sensitive env vars.
  • 48 destinations, and no Jenkins sync. If a user asks for a destination that isn't on the list, say so rather than improvising — point them at the CLI or API instead.

Related skills

azure-compliancemicrosoft606KRun Azure compliance and security audits with azqr plus Key Vault expiration checks. Covers best-practice assessment, resource review, policy/compliance validation, and security posture checks. WHEN: compliance scan, security audit, BEFORE running azqr (compliance cli tool), Azure best practices, Key Vault expiration check, expired certificates, expiring secrets, orphaned resources, compliance assessment.firebase-security-rules-auditorfirebase124KAudits Firebase (Firestore, Cloud Storage) security rules for vulnerabilities, privilege escalation, role bypasses, create vs update inconsistencies, resource exhaustion, type safety, size limits, and hasOnly ownership checks. Use when auditing/reviewing rules, running red-team rule assessments, or scoring against auditor checklists. Don't use for Firebase CLI (login, deploy), Auth, Crashlytics, Remote Config, or database queries.browser-fingerprint-auditliarjsdev69KAudit a browser fingerprint for internal contradictions with the liarjs CLI - canvas, WebGL, WebGL2, WebGPU, audio, 220 fonts, WebRTC and timezone probes, scored against the TLS/HTTP/ASN view of the same request. Use when asked to run a browser fingerprint test, see what a fingerprint looks like, check canvas or WebGL fingerprint stability, compare a spoofed profile against a real browser, or find out whether a browser profile is self-consistent.cloudflare-onecloudflare66KDesign, configure, troubleshoot, or review Cloudflare One Zero Trust and SASE deployments. Use cloudflare-one-migrations for migration planning from other vendors.

Search skills and MCP servers

Fuzzy search across 23,137 skills and servers