
Alicloud Security Kms
- 267 installs
- 396 repo stars
- Updated July 18, 2026
- cinience/alicloud-skills
alicloud-security-kms is a cinience alicloud-skills integration skill that manages Alibaba Cloud KMS keys, policies, and encryption operations via OpenAPI for developers who must protect secrets and tokens without embedd
About
alicloud-security-kms is a cinience/alicloud-skills service skill—catalog id alicloud-security-kms, source name aliyun-kms-manage—for Alibaba Cloud Key Management Service. It guides agents through RPC OpenAPI workflows using product code Kms on API version 2016-01-20, with metadata-first discovery via list_openapi_meta_apis.py before Create, Update, List, Describe, Get, or Query operations. The four-step workflow confirms region and resource identifiers, discovers required API parameters from references, calls the official SDK or OpenAPI Explorer, and verifies results with describe or list APIs. Credentials resolve from ALIBABACLOUD_ACCESS_KEY_ID, ALIBABACLOUD_ACCESS_KEY_SECRET, optional ALIBABACLOUD_REGION_ID, or ~/.alibabacloud/credentials with least-privilege guidance. Developers reach for alicloud-security-kms when applications need envelope encryption, key rotation policies, or KMS troubleshooting without hard-coding secrets in source repositories.
- KMS key creation and rotation
- Encrypt/decrypt SDK usage
- Envelope encryption patterns
- IAM and access policy setup
- Secrets management without embedded keys
Alicloud Security Kms by the numbers
- 267 all-time installs (skills.sh)
- Ranked #659 of 2,203 Security skills by installs in the Skillselion catalog
- Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/cinience/alicloud-skills --skill alicloud-security-kmsAdd your badge
Show developers this skill is listed on Skillselion. Paste this into your README.
| Installs | 267 |
|---|---|
| repo stars | ★ 396 |
| Last updated | July 18, 2026 |
| Repository | cinience/alicloud-skills ↗ |
How do you configure Alibaba Cloud KMS encryption keys?
Configure Alibaba Cloud KMS keys, envelopes, and crypto operations so applications encrypt secrets, tokens, and sensitive data without embedding raw key material.
Who is it for?
Backend developers integrating Alibaba Cloud KMS envelope encryption who need OpenAPI-guided key lifecycle operations and least-privilege credential patterns.
Skip if: Teams on AWS KMS, HashiCorp Vault, or other clouds without Alibaba Cloud KMS in the target architecture.
When should I use this skill?
A developer asks to create Alibaba KMS keys, configure envelope encryption, rotate KMS policies, or troubleshoot Kms OpenAPI workflows for secrets protection.
What you get
KMS key configuration, OpenAPI operation evidence under output/aliyun-kms-manage/, and verified encrypt-decrypt integration without embedded raw key material.
- KMS API operation evidence
- Key lifecycle configuration notes
- Encryption integration patterns
By the numbers
- KMS OpenAPI product code Kms on API version 2016-01-20
- 4-step OpenAPI workflow from discovery through verification
Files
Category: service
Key Management Service
Validation
mkdir -p output/alicloud-security-kms
python -m py_compile skills/security/key-management/alicloud-security-kms/scripts/list_openapi_meta_apis.py && echo "py_compile_ok" > output/alicloud-security-kms/validate.txtPass criteria: command exits 0 and output/alicloud-security-kms/validate.txt is generated.
Output And Evidence
- Save KMS API discovery outputs and operation results in
output/alicloud-security-kms/. - Keep at least one request parameter example per operation type.
Use Alibaba Cloud OpenAPI (RPC) with official SDKs or OpenAPI Explorer to manage resources for KeyManagementService.
Workflow
1) Confirm region, resource identifiers, and desired action. 2) Discover API list and required parameters (see references). 3) Call API with SDK or OpenAPI Explorer. 4) Verify results with describe/list APIs.
AccessKey priority (must follow)
1) Environment variables: ALICLOUD_ACCESS_KEY_ID / ALICLOUD_ACCESS_KEY_SECRET / ALICLOUD_REGION_ID Region policy: ALICLOUD_REGION_ID is an optional default. If unset, decide the most reasonable region for the task; if unclear, ask the user. 2) Shared config file: ~/.alibabacloud/credentials
API discovery
- Product code:
Kms - Default API version:
2016-01-20 - Use OpenAPI metadata endpoints to list APIs and get schemas (see references).
High-frequency operation patterns
1) Inventory/list: prefer List* / Describe* APIs to get current resources. 2) Change/configure: prefer Create* / Update* / Modify* / Set* APIs for mutations. 3) Status/troubleshoot: prefer Get* / Query* / Describe*Status APIs for diagnosis.
Minimal executable quickstart
Use metadata-first discovery before calling business APIs:
python scripts/list_openapi_meta_apis.pyOptional overrides:
python scripts/list_openapi_meta_apis.py --product-code <ProductCode> --version <Version>The script writes API inventory artifacts under the skill output directory.
Output policy
If you need to save responses or generated artifacts, write them under: output/alicloud-security-kms/
Prerequisites
- Configure least-privilege Alibaba Cloud credentials before execution.
- Prefer environment variables:
ALICLOUD_ACCESS_KEY_ID,ALICLOUD_ACCESS_KEY_SECRET, optionalALICLOUD_REGION_ID. - If region is unclear, ask the user before running mutating operations.
References
- Sources:
references/sources.md
interface:
display_name: "Alibaba Cloud Security KMS"
short_description: "KMS key lifecycle management workflows"
default_prompt: "Use $alicloud-security-kms to complete this security/key-management task on Alibaba Cloud."
Sources
- OpenAPI product page:
https://api.aliyun.com/product/Kms - API list (metadata):
https://api.aliyun.com/meta/v1/products/Kms/versions/2016-01-20/api-docs.json - API definition (single API):
https://api.aliyun.com/meta/v1/products/Kms/versions/2016-01-20/apis/{ApiName}/api.json
#!/usr/bin/env python3
"""Fetch OpenAPI metadata API list for one product/version and save to output/.
Env:
- OPENAPI_META_TIMEOUT (seconds, default: 20)
"""
from __future__ import annotations
import argparse
import json
import os
import pathlib
import urllib.request
DEFAULT_PRODUCT_CODE = "Kms"
DEFAULT_VERSION = "2016-01-20"
OUTPUT_DIR = pathlib.Path("output/alicloud-security-kms")
def fetch_json(url: str, timeout: int) -> dict:
req = urllib.request.Request(url, headers={"User-Agent": "codex-skill"})
with urllib.request.urlopen(req, timeout=timeout) as resp:
return json.loads(resp.read().decode("utf-8"))
def main() -> None:
parser = argparse.ArgumentParser()
parser.add_argument("--product-code", default=DEFAULT_PRODUCT_CODE)
parser.add_argument("--version", default=DEFAULT_VERSION)
parser.add_argument("--output-dir", default=str(OUTPUT_DIR))
args = parser.parse_args()
timeout = int(os.getenv("OPENAPI_META_TIMEOUT", "20"))
output_dir = pathlib.Path(args.output_dir)
output_dir.mkdir(parents=True, exist_ok=True)
url = (
f"https://api.aliyun.com/meta/v1/products/{args.product_code}"
f"/versions/{args.version}/api-docs.json"
)
payload = fetch_json(url, timeout)
raw_apis = payload.get("apis", {})
if isinstance(raw_apis, dict):
api_names = sorted(raw_apis.keys())
elif isinstance(raw_apis, list):
names = []
for item in raw_apis:
if isinstance(item, dict):
name = item.get("name") or item.get("apiName")
if name:
names.append(name)
elif isinstance(item, str):
names.append(item)
api_names = sorted(set(names))
else:
api_names = []
json_file = output_dir / f"{args.product_code}_{args.version}_api_docs.json"
md_file = output_dir / f"{args.product_code}_{args.version}_api_list.md"
json_file.write_text(json.dumps(payload, ensure_ascii=False, indent=2), encoding="utf-8")
md_lines = [
f"# {args.product_code} {args.version} API List",
"",
f"- Source: {url}",
f"- API count: {len(api_names)}",
"",
]
md_lines.extend([f"- `{name}`" for name in api_names])
md_file.write_text("\n".join(md_lines) + "\n", encoding="utf-8")
print(f"Saved: {json_file}")
print(f"Saved: {md_file}")
if __name__ == "__main__":
main()
Related skills
How it compares
Pick alicloud-security-kms for Alibaba Cloud KMS OpenAPI integration; use cloud-agnostic secrets skills when KMS is not on Alibaba infrastructure.
FAQ
Which Alibaba KMS API version does alicloud-security-kms use?
alicloud-security-kms targets Alibaba Cloud KMS OpenAPI product code Kms on API version 2016-01-20. Agents discover operations with list_openapi_meta_apis.py before calling Create, List, Describe, or Update APIs through the SDK.
How should credentials be configured for alicloud-security-kms?
alicloud-security-kms prefers ALIBABACLOUD_ACCESS_KEY_ID and ALIBABACLOUD_ACCESS_KEY_SECRET environment variables, with optional ALIBABACLOUD_REGION_ID, falling back to ~/.alibabacloud/credentials under least-privilege guidance.