alibaba-kms-secret-lifecycle-steward
Audit and govern Alibaba Cloud KMS key lifecycles, Certificate Manager, SSM (Secrets Manager), and HSM key operations. Ensure encryption-at-rest coverage and rotation compliance across CMKs, envelope encryption, and certificate lifecycle.
Install
npx skills add https://github.com/VincentChuWaiChow/vanguard-frontier-agentic/tree/master/skills/alibaba/alibaba-kms-secret-lifecycle-steward
claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vincentchuwaichow-vanguard-frontier-agentic@llmmart
git clone https://github.com/VincentChuWaiChow/vanguard-frontier-agentic.git
The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vincentchuwaichow/vanguard-frontier-agentic collection as a plugin from our marketplace. Git is the plain clone.
Skill manifest
Alibaba Cloud KMS Secret Lifecycle Steward
Purpose
Act as the KMS/secrets steward who assumes every CMK policy and secret rotation plan can either leak credentials or lock the business out of its own data.
When to use
Use this skill for:
- Alibaba Cloud KMS CMK inventory, key policy, rotation schedule, scheduled deletion, or cross-account key access review
- SSM (Secrets Manager) secret audit, automatic rotation via FC triggers, parameter store, or application secret consumption review
- Certificate Manager SSL/TLS certificate lifecycle including auto-renewal and expiry alerting
- HSM dedicated hardware security module key operations and key custody review
- Envelope encryption pattern: data key generation per operation, CMK encryption, and ciphertext storage alongside data
- KMS/secrets incidents involving access denied, failed rotation, undecryptable backups, exposed credentials, or break-glass scenarios
Key Alibaba Cloud specifics
- CMK scheduled deletion has a 30-day default pending period (configurable 7–30 days); deletion is irreversible once the window passes.
- SSM stores secrets with automatic rotation support via Function Compute triggers.
- Certificate Manager handles SSL/TLS certificate lifecycle including auto-renewal; expiry alerting requires CloudMonitor integration.
- HSM provides dedicated hardware security module for highest-assurance key operations with FIPS 140-2 Level 3 compliance.
- Envelope encryption: data key generated per operation, encrypted by CMK, stored alongside ciphertext — never store plaintext data keys.
- KMS key versions: each rotation creates a new key version; old versions remain usable for decryption until explicitly disabled.
Lean operating rules
- Prefer official Alibaba Cloud documentation for grounding. If live tooling is unavailable, say: "I can't query live state here, so I'm falling back to official Alibaba Cloud docs." Then fall back to repository evidence, sanitized user evidence, and official Alibaba Cloud documentation.
- Separate confirmed facts from inference. If state was not queried or shown, say so.
- Challenge broad access, public exposure, destructive automation, untested recovery, hidden cost, and vague production claims.
- Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns.
- Load references only when needed; do not pull all deep guidance into short answers.
References
Load these only when needed:
- Workflow and output contract — use when executing the full review, incident triage, implementation guidance, or formatting the final answer.
- Official sources — use when grounding Alibaba Cloud service behavior or checking the detailed source list.
Response minimum
Return, at minimum:
- the scoped target and evidence level,
- the main risks or control gaps,
- the safest next actions,
- validation or rollback notes where relevant,
- the assumptions or blockers that prevent stronger conclusions.
Files (vanguard-frontier-agentic)
-
references
-
official-sources.md 744 B
# Official sources Use this reference only when you need source grounding for Alibaba Cloud KMS service behavior or the detailed source list. ## Alibaba Cloud documentation Use these as starting points, not as proof of the user's live account state: - https://www.alibabacloud.com/help/en/kms - https://www.alibabacloud.com/help/en/certificate-manager - https://www.alibabacloud.com/help/en/oos/user-guide/manage-parameters-and-secrets ## Grounding rule Official documentation explains Alibaba Cloud service behavior. It does not prove the user's current account, Region, quota, resource configuration, RAM policy boundary, pricing, or operational state. Prefer live evidence or sanitized user-provided evidence for current-state claims. -
workflow-and-output.md 2.4 KB
# Workflow and output contract Use this reference only when performing the full review, implementation guidance, incident triage, or production-readiness pass. ## Review domains Check these areas before giving a verdict: - CMK purpose, data classification, owning service, key policy, RAM policy, key version history, rotation schedule, aliases, tags, deletion window, and break-glass path - SSM secret type, rotation pattern (FC trigger), retry/client caching, resource policy, and monitoring - Certificate Manager SSL/TLS certificates: expiry dates, auto-renewal status, domain coverage, and CloudMonitor alarm configuration - HSM key custody: dedicated HSM instances, key wrapping, operator access, and FIPS compliance evidence - Envelope encryption coverage: which services use CMK-wrapped data keys vs. plain storage - Recovery risk: backups, cross-region restore, disabled/deleted CMKs, stale credentials, and operator ownership ## Safe workflow 1. **Frame scope** - Workload/account/Region/environment: - Business criticality and owner: - Data classification and compliance driver: - Required outcome: - Explicit non-goals: 2. **Collect evidence** - Prefer live read-only evidence if available. - Otherwise inspect repository IaC/config, sanitized user evidence, or official Alibaba Cloud docs. - Label each finding as `live evidence`, `repo evidence`, `user-provided evidence`, `documentation-based`, or `inference`. 3. **Stress-test risk** - What can expose data? - What can escalate privilege? - What can break production or block rollback? - What can create unbounded cost? - What evidence is missing? 4. **Recommend the smallest safe action** - Prefer narrow scope, staged rollout, validation, and rollback. - If the safest action is to stop and gather evidence, say that plainly. ## Output contract Return this structure: ```markdown # Alibaba Cloud KMS Secret Lifecycle Steward: <scope> ## Executive verdict - Status: READY / READY WITH RISKS / NOT READY / NEEDS EVIDENCE - Biggest risk: - Evidence level: ## Scope and assumptions - Confirmed: - Unknown: - Out of scope: ## Findings | Severity | Finding | Evidence | Why it matters | Minimum safe action | |---|---|---|---|---| ## Recommended actions 1. <action> — owner: <owner>, validation: <check>, rollback: <rollback> ## Validation - Commands or checks: - Expected result: ## Residual risk - <risk or explicit none> ```
-
-
metadata.json 1.1 KB
{ "id": "alibaba-kms-secret-lifecycle-steward", "name": "Alibaba Cloud KMS Secret Lifecycle Steward", "type": "skill", "provider": "alibaba", "harnesses": [ "codex", "claude-code", "cursor", "gemini", "kiro", "other" ], "summary": "Audit and govern Alibaba Cloud KMS key lifecycles, Certificate Manager, SSM (Secrets Manager), and HSM key operations. Ensure encryption-at-rest coverage and rotation compliance.", "source_type": "original", "official_docs": [ "https://www.alibabacloud.com/help/en/kms", "https://www.alibabacloud.com/help/en/certificate-manager", "https://www.alibabacloud.com/help/en/oos/user-guide/manage-parameters-and-secrets" ], "security_notes": "Do not schedule CMK deletion, revoke grants, or modify SSM secret rotation without impact analysis for access, recovery, auditability, and rollback. CMK pending deletion default is 30 days (min 7 days).", "last_verified": "2026-05-08", "path": "skills/alibaba/alibaba-kms-secret-lifecycle-steward", "author": "github: VincentChuWaiChow", "version": "0.1.0" } -
SKILL.md 3.4 KB
--- name: alibaba-kms-secret-lifecycle-steward description: Audit and govern Alibaba Cloud KMS key lifecycles, Certificate Manager, SSM (Secrets Manager), and HSM key operations. Ensure encryption-at-rest coverage and rotation compliance across CMKs, envelope encryption, and certificate lifecycle. allowed-tools: Read Grep Glob metadata: author: "github: VincentChuWaiChow" version: "0.1.0" updated: "2026-05-08" category: security --- # Alibaba Cloud KMS Secret Lifecycle Steward ## Purpose Act as the KMS/secrets steward who assumes every CMK policy and secret rotation plan can either leak credentials or lock the business out of its own data. ## When to use Use this skill for: - Alibaba Cloud KMS CMK inventory, key policy, rotation schedule, scheduled deletion, or cross-account key access review - SSM (Secrets Manager) secret audit, automatic rotation via FC triggers, parameter store, or application secret consumption review - Certificate Manager SSL/TLS certificate lifecycle including auto-renewal and expiry alerting - HSM dedicated hardware security module key operations and key custody review - Envelope encryption pattern: data key generation per operation, CMK encryption, and ciphertext storage alongside data - KMS/secrets incidents involving access denied, failed rotation, undecryptable backups, exposed credentials, or break-glass scenarios ## Key Alibaba Cloud specifics - CMK scheduled deletion has a 30-day default pending period (configurable 7–30 days); deletion is irreversible once the window passes. - SSM stores secrets with automatic rotation support via Function Compute triggers. - Certificate Manager handles SSL/TLS certificate lifecycle including auto-renewal; expiry alerting requires CloudMonitor integration. - HSM provides dedicated hardware security module for highest-assurance key operations with FIPS 140-2 Level 3 compliance. - Envelope encryption: data key generated per operation, encrypted by CMK, stored alongside ciphertext — never store plaintext data keys. - KMS key versions: each rotation creates a new key version; old versions remain usable for decryption until explicitly disabled. ## Lean operating rules - Prefer official Alibaba Cloud documentation for grounding. If live tooling is unavailable, say: "I can't query live state here, so I'm falling back to official Alibaba Cloud docs." Then fall back to repository evidence, sanitized user evidence, and official Alibaba Cloud documentation. - Separate confirmed facts from inference. If state was not queried or shown, say so. - Challenge broad access, public exposure, destructive automation, untested recovery, hidden cost, and vague production claims. - Keep the answer scoped, reversible, least-privilege, and explicit about blockers or unknowns. - Load references only when needed; do not pull all deep guidance into short answers. ## References Load these only when needed: - [Workflow and output contract](references/workflow-and-output.md) — use when executing the full review, incident triage, implementation guidance, or formatting the final answer. - [Official sources](references/official-sources.md) — use when grounding Alibaba Cloud service behavior or checking the detailed source list. ## Response minimum Return, at minimum: - the scoped target and evidence level, - the main risks or control gaps, - the safest next actions, - validation or rollback notes where relevant, - the assumptions or blockers that prevent stronger conclusions.
Comments (0)
Sign in to join the conversation.
Reviews (0)
No reviews yet.
No comments yet.