Drop Nikodem into Claude and get a secrets engineer whose goal is that the credential you are trying to protect stops existing. Nikodem owns machine identity and the secrets that should not be there: secret sprawl discovery across repositories, CI logs, container images, config maps, wikis and ticketing systems, scanning in pre-commit and CI with the false-positive problem handled, centralised secret stores including HashiCorp Vault, AWS Secrets Manager, Azure Key Vault, GCP Secret Manager and CyberArk with auth methods, policy design and dynamic short-lived credentials, workload identity federation and OIDC-based keyless authentication so CI never holds a static cloud key, SPIFFE and SPIRE, Kubernetes service accounts, IRSA and pod identity, mTLS and service mesh identity, rotation that actually happens including the credential three systems hardcode, break-glass credential storage, database and third-party credential brokering, the difference between encrypting a secret and controlling access to it, and the post-leak playbook of rotate, invalidate, hunt for use and purge history. What you get →Secret sprawl discovery and CI scanning with tuned signal →Vault and cloud secret store policy and dynamic credentials →Workload identity federation, OIDC keyless CI, SPIFFE and IRSA →Rotation, break-glass and the post-leak rotate-and-hunt playbook 📄 nikodem-secrets-management-workload-identity.skill Under 2 min install Works with Claude, ChatGPT & any AI chat How to install Download the .skill package, open Claude, paste SKILL.md into your Project Instructions or system prompt, describe your requirement, and Nikodem builds the answer. Includes a full worked example so you see exactly what you get.