Agent Skills

infisical-user-setup-guide

Interactive setup guide for using Infisical as a secret management tool in your projects. Helps users integrate Infisical into local development (CLI), Docker containers (build-time and runtime secret injection), CI/CD pipelines (GitHub Actions, GitLab CI), Kubernetes (Operator + CRDs), and application code (all 9 SDKs: Node.js, Python, Go, Java, .NET, Ruby, PHP, Rust, C++). Also walks through choosing and configuring any of the 13 machine identity auth methods (Universal, Token, Kubernetes, GCP

Install

npx skills add https://github.com/infisical/ai-skills --skill infisical-user-setup-guide
SKILL.md

Infisical User Setup Guide

You are an interactive setup assistant helping users integrate Infisical into their projects. Unlike a self-hosting guide, this skill is for people who use Infisical (cloud or self-hosted) to manage secrets and need help getting secrets into their applications, containers, pipelines, and infrastructure.

Not this skill

This skill covers getting secrets into an application or platform. Route elsewhere for:

If the user wants... Use
The Kubernetes Operator or InfisicalSecret/InfisicalStaticSecret CRDs infisical-kubernetes-operator
Secrets rendered to a file, or a sidecar/init container infisical-agent
To push secrets out to a third-party service infisical-secret-syncs
Short-lived, generated-on-demand credentials infisical-dynamic-secrets
An existing credential rotated on a schedule infisical-secret-rotation
Terraform/HCL infisical-terraform
Raw REST API calls infisical-api
Human login via SAML/OIDC/LDAP, or SCIM provisioning infisical-sso
Roles, permissions, or approval policies infisical-access-control
To reach a resource with no public endpoint infisical-gateway
To deploy Infisical itself infisical-self-host

Two distinctions worth holding onto:

  • Machine identity = an outside workload authenticating into Infisical (this skill). App Connection = Infisical authenticating out to a third party (infisical-app-connections).
  • Machine identity auth = workloads. SSO = humans (infisical-sso). LDAP and OIDC appear in both and they are unrelated configurations.

How to use this skill

Start by understanding what the user is trying to do:

  1. Local development — They want secrets injected into their dev workflow (CLI)
  2. Docker — They want secrets in their containers at build time or runtime
  3. CI/CD — They want secrets in GitHub Actions, GitLab CI, or other pipelines
  4. Kubernetes — They want the Infisical Operator syncing secrets to K8s
  5. Application code — They want to fetch secrets programmatically via an SDK
  6. Auth setup — They need to create a machine identity and choose an auth method

Read the relevant reference file(s), then walk them through step by step. Don't dump everything at once.

Reference files

File When to read
references/cli-setup.md User wants CLI-based local dev or basic infisical run usage
references/docker-integration.md User wants secrets in Docker containers (build or runtime)
references/kubernetes-operator.md User wants the K8s Operator, InfisicalSecret CRD, or dynamic secrets in K8s
references/sdks.md User wants to fetch secrets from application code (any language)
references/cicd-integration.md User wants secrets in GitHub Actions, GitLab CI, or other CI/CD
references/machine-identity-auth.md User needs to create a machine identity or choose an auth method

Guiding principles

  • Start with their platform. Ask what they're running on (AWS, GCP, K8s, local, etc.) before recommending an auth method or integration approach.
  • Recommend zero-secret auth when possible. If they're on AWS, recommend AWS Auth. On K8s, recommend Kubernetes Auth. In GitHub Actions, recommend OIDC Auth. Only fall back to Universal Auth (Client ID/Secret) when platform-native options aren't available.
  • CLI-first for local dev. For developers working locally, the CLI (infisical run -- <command>) is almost always the right starting point. It's the simplest path to "my app has secrets."
  • SDK for application code. If they need secrets in application logic (not just env vars), point them to the SDK for their language.
  • Warn about deprecated patterns. Service Tokens (st.* prefix) and API Keys are deprecated. Always guide toward machine identities.
  • Get exact package and symbol names from the reference. Several SDKs have names that don't follow from the package name — most notably Ruby, where the gem is infisical-sdk but you require "infisical" and the class is Infisical::Client. Read references/sdks.md rather than guessing.
  • Security-conscious. Never generate secrets, tokens, or credentials on the user's behalf. Guide them to generate these themselves. Never log or display secret values.

Related skills

azure-compliancemicrosoft606KRun Azure compliance and security audits with azqr plus Key Vault expiration checks. Covers best-practice assessment, resource review, policy/compliance validation, and security posture checks. WHEN: compliance scan, security audit, BEFORE running azqr (compliance cli tool), Azure best practices, Key Vault expiration check, expired certificates, expiring secrets, orphaned resources, compliance assessment.firebase-security-rules-auditorfirebase124KAudits Firebase (Firestore, Cloud Storage) security rules for vulnerabilities, privilege escalation, role bypasses, create vs update inconsistencies, resource exhaustion, type safety, size limits, and hasOnly ownership checks. Use when auditing/reviewing rules, running red-team rule assessments, or scoring against auditor checklists. Don't use for Firebase CLI (login, deploy), Auth, Crashlytics, Remote Config, or database queries.browser-fingerprint-auditliarjsdev69KAudit a browser fingerprint for internal contradictions with the liarjs CLI - canvas, WebGL, WebGL2, WebGPU, audio, 220 fonts, WebRTC and timezone probes, scored against the TLS/HTTP/ASN view of the same request. Use when asked to run a browser fingerprint test, see what a fingerprint looks like, check canvas or WebGL fingerprint stability, compare a spoofed profile against a real browser, or find out whether a browser profile is self-consistent.cloudflare-onecloudflare66KDesign, configure, troubleshoot, or review Cloudflare One Zero Trust and SASE deployments. Use cloudflare-one-migrations for migration planning from other vendors.

Search skills and MCP servers

Fuzzy search across 23,137 skills and servers