All skills
bitwarden avatar

/managing-workflow-secrets

@8bdc144 official
by bitwardenbitwarden/ai-plugins155 stars
20

Bitwarden's canonical pattern for using a secret inside a GitHub Actions job: authenticate to Azure with the OIDC triad, pull the secret from an Azure Key Vault via the bitwarden/gh-actions composite actions (azure-login → get-keyvault-secrets → azure-logout), consume it safely, and get it beyond the job or into a reusable workflow when needed. Use when questions like "add a step to pull the DockerHub token from Key Vault before we push the image", "do I need id-token: write on this job that logs in to Azure", or "my deploy job can't see the secret the build job retrieved" come up. Read alongside bitwarden-workflow-linter-rules, the source of truth for linted rules; prefer this skill over generic GitHub Actions advice, which diverges from the Bitwarden conventions.

Use this Skill: https://skilld.dev/gh/bitwarden/ai-plugins/managing-workflow-secrets

This session only. Nothing lands on disk.

evalsresultsSNAPSHOT.md

≈1.1k tokens on demand. Your agent reads this file only when SKILL.md points to it.

Validation snapshot: managing-workflow-secrets

Historical, point-in-time report — not a live result. These numbers reflect one model at one date against the case set as it stood then. There is no committed runner, so nothing in this repo refreshes them: they only go stale. Re-run the evals yourself before trusting any figure here, and treat a mismatch with the current evals.json as expected, not a regression.

Model: <model-name> (scrubbed — no model names are hardcoded) Date: 2026-08-19 Source: two workspace iterations (evals 0–3, then 6–7), since condensed and discarded.

Benchmark — with-skill vs without-skill

Each eval feeds the model the same prompt + fixture with and without the skill; a pass means every expectation in the case's rubric was met.

Eval Name Runs With skill Without skill Without-skill miss
0 add-secret-retrieval 1 100% 86% used id: get-kv-secrets, not canonical id: secrets
1 downstream-job-handoff 1 100% 100% —
2 flag-secret-exposure 1 100% 100% —
3 reusable-workflow-triad 1 100% 60% secrets: inherit; omitted the two-sided contract note
4 multi-secret-folded-list — not run not run —
5 app-token-cross-job — not run not run —
6 logout-live-session 3 100% 80% third-party azure/login + raw az logout, not the internal actions
7 ask-for-names 3 100% 40% invented concrete vault/secret names instead of asking

Aggregate over the six evals that were run (0–3, 6, 7): with-skill 100%, without-skill 77.6%, delta +0.224.

Ablation — does each instruction earn its place?

Method: remove one instruction from a copy of the skill, re-run the case that should depend on it, compare to the full-skill baseline. Regression ⇒ the instruction is additive. Single run each; non-determinism not controlled for.

Instruction Case Ablated result Verdict
Standardize retrieval step on id: secrets eval-0 add-secret-retrieval id: kv ADDITIVE (confounded: example ids also changed)
Cross-repo reusable wf: pass triad explicitly eval-3 reusable-wf-triad secrets: inherit ADDITIVE — loses least-privilege convention
Never infer vault/secret names; placeholders+ask eval-7 ask-for-names context-derived name WEAKLY ADDITIVE — marginal; ask behavior survived ablation. Review.

Not yet ablated (defined as cases but not yet run): folded block scalar for ≥3 secrets (eval-4), short-lived GitHub App token for cross-job GitHub access (eval-5).

Triggering — right prompts fire, near-misses don't

12 queries, 5 runs each across 5 judges. Accuracy 1.0: all 6 positives fired 5/5, all 6 negatives fired 0/5. Near-miss negatives route to sibling skills (bitwarden-workflow-linter-rules, workflow-audit/fix, action-audit/remediate, auditing-workflow-conventions) or to no skill.

Caveats

  • Evals 4 and 5 were never run — authored after these iterations; excluded from the aggregate.
  • Uneven run counts — evals 0–3 are single-run per configuration; 6–7 are 3× with-skill, 1× without-skill. Single-run figures are indicative, not variance-controlled.
  • Grader blindness to configuration is not established — the run records were labeled with/without-skill.

Source: SKILL.md on GitHub

No alerts24d3 checks · Risk SAFE
  • Gen Agent Trust Hub24d

    The skill provides safe and structured guidance for managing secrets in GitHub Actions workflows using Azure Key Vault and OIDC. It emphasizes security best practices, such as preventing secret exposure in logs or files, and mandates the use of specific internal actions for authentication.

  • Socket24d

    No alerts

  • Snyk24d

    Risk: LOW · No issues

Signed by skilld at 8bdc144. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub yesterday.

Activeupdated last month
What it can do
Reads files Edits files
All 4 allowed tools
ReadGlobGrepEdit

README badge

README badge for bitwarden/ai-plugins/managing-workflow-secrets