本文へ移動
cccskills
無料GitHub で公開

matlab-secure-credentials

Store, retrieve, and pass credentials securely in MATLAB using the built-in MATLAB Vault (setSecret, getSecret, importSecrets, secretID) instead of hardcoding. Handles connections to any authenticated service: REST APIs, databases, cloud storage (S3/Azure/GCS), SFTP, and others. Covers API keys, tokens, passwords, SSH passphrases, CI/batch/scheduled jobs, and "keep credentials out of code" requests. Does NOT cover third-party secret managers (HashiCorp Vault, AWS Secrets Manager), OS-level key management, or the connection/query logic itself.

インストール方法を見る

含まれるファイル(2)

  • SKILL.md12.9 KB
  • manifest.yaml721 B

SKILL.md(原文)

インストールする前に、エージェントに与えられる指示の中身を確認できます。

Secure Credentials in MATLAB

Handle API keys, tokens, passwords, and passphrases with the MATLAB Vault, an encrypted store built into MATLAB, instead of hardcoding them. This skill covers the credential — storing it, retrieving it, and passing it into a connection to any authenticated service.

When to Use

  • Connecting to any authenticated service or connection from MATLAB — a REST API, database, cloud storage, SFTP/FTP server, message queue, or any other.
  • Any code that handles an API key, bearer token, password, or SSH key passphrase.
  • Writing CI / batch / scheduled MATLAB that needs credentials with no user present.
  • Refactoring credential-handling code, or persisting a config that includes a secret.
  • A request to "keep credentials out of code," "don't commit secrets," or "do this the secure way."

When NOT to Use

  • Writing the connection/query/transfer logic itself when no credential is involved (e.g. a public API, a local file), or cleaning/transforming/aggregating data once it is in a table or timetable — use the relevant data-import skill (e.g. matlab-analyze-data, matlab-use-database).
  • Integrating a third-party secret manager (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault) — out of scope.
  • OS-level or non-MATLAB key management.

Decision Guide: Which Mechanism

Pick the mechanism by how the credential is supplied, not by habit.

SituationUseNot
Credential is stored and reused across sessionssetSecret once, then getSecret at useHardcoding; a hand-rolled config file
You need to load a set of credentials at once (interactive setup, or non-interactive / CI / headless / scheduled)importSecrets to populate the vault from a secrets file, then getSecret; or, in CI, getenv for a runner-injected valuesetSecret in a headless job — it is only supported interactively
A function accepts credentials from a callersecretID (a reference to the secret, not its value)Storing the value in a struct field or argument
Credential is genuinely a process environment variable — a CI-injected secret, or a cloud SDK convention like AWS_ACCESS_KEY_IDgetenv — this is correctDuplicating it into the vault for no reason

The rule is don't hardcode secrets — not "never use environment variables." getenv is the right tool when the secret is already a process env var; the vault is the right default for credentials you store.

Workflow

  1. Decide the mechanism using the Decision Guide above.
  2. Store or populate the credential:
    • Single secret, interactively: setSecret("MyApiToken") (MATLAB prompts for the value — never pass it as an argument; it takes only the name).
    • A set of secrets at once: importSecrets("secrets.env") loads names+values into the vault with no prompt — handy both for interactive setup and for non-interactive/CI.
  3. Retrieve at point of use with getSecret("MyApiToken"), or hand a secretID("MyApiToken") to APIs that accept one (they resolve it at call time, so the value never lives in a variable).
  4. Wire it into the connection — see Patterns below.
  5. Verify with isSecret("MyApiToken") before reading or removing, and confirm no secret value appears in the script, logs, or any saved file.

Key Functions

FunctionPurposeAvailable From
setSecretAdd a secret to the vault; interactive — prompts for the value, takes only the name (Overwrite=true to update)R2024a
getSecretRetrieve a secret value (returns a string scalar)R2024a
isSecretCheck whether a named secret existsR2024a
listSecretsList the names of stored secretsR2024a
removeSecretDelete a secret from the vault (there is no deleteSecret)R2024a
setSecretMetadataAttach metadata (e.g. an expiry date, owner) to a secretR2024a
getSecretMetadataRead a secret's metadata as a dictionaryR2024a
secretIDA reference object carrying a secret's name, not its value; accepted by weboptions and matlab.net.http.CredentialsR2025a
importSecretsLoad a set of secrets from a file into the vault (no prompt)R2026a

Patterns

Store once, retrieve at use

% One-time, at the MATLAB prompt (prompts for the value — do NOT type the secret in code):
setSecret("MyApiToken");

% In your script, read it only where needed:
token = getSecret("MyApiToken");

Optionally record metadata such as an expiry so callers can check freshness before use:

% Metadata values are stored in a dictionary; wrap each value in a cell:
setSecretMetadata("MyApiToken", dictionary("Expires", {datetime(2026,12,31)}));

md = getSecretMetadata("MyApiToken");
expiry = md{"Expires"};            % {} indexing returns the stored value
if expiry < datetime("today")
    error("MyApiToken expired on %s — rotate it with setSecret(...,Overwrite=true).", expiry);
end
token = getSecret("MyApiToken");

Rotate or update a secret

setSecret(...,Overwrite=true) replaces the value of an existing secret — the normal way to rotate a credential (replace it with a new value, e.g. periodically or after expiry). Without Overwrite, setSecret errors on a name that already exists.

setSecret("MyApiToken", Overwrite=true);   % prompts for the new value

REST call with a bearer token

Fetch the token from the vault and set it in the Authorization header.

token = getSecret("MyApiToken");
opts = weboptions( ...
    HeaderFields = ["Authorization", "Bearer " + token], ...
    ContentType  = "json");
data = webread("https://api.example.com/v1/data", opts);

For basic auth, hand weboptions a secretID so the value is resolved at request time and never sits in a variable:

username = getenv("API_USER");   % REPLACE: your service-account user name
opts = weboptions(Username=username, Password=secretID("MyApiPassword"));
data = webread("https://api.example.com/v1/data", opts);

For lower-level requests, matlab.net.http.Credentials also accepts a secretID:

cred = matlab.net.http.Credentials(Password=secretID("MyApiPassword"));

SFTP with a passphrase-protected key

keyFile = fullfile(userpath, "id_rsa");   % REPLACE: path to your private key
s = sftp("sftp.example.com", "reportuser", ...
    PrivateKeyFile       = keyFile, ...
    PrivateKeyPassphrase = getSecret("SftpKeyPassphrase"));
c = onCleanup(@() close(s));
localPaths  = mget(s, "/reports/nightly.csv", tempdir);
reportTable = readtable(localPaths{1});

Password auth instead of a key:

s = sftp("sftp.example.com", "reportuser", Password=getSecret("SftpPassword"));

Database connection

Store the password in the vault and read it at connect time. Keep host/port/database in code; keep the credential out.

conn = postgresql("svc-account", getSecret("PgPassword"), ...
    Server       = "db-prod-01", ...
    PortNumber   = 5432, ...
    DatabaseName = "analytics");
c = onCleanup(@() close(conn));
tables = sqlfind(conn, "");

For a reusable, shareable setup, save a data source once (via the Database Explorer app or databaseConnectionOptions + saveAsDataSource) and connect by name, supplying the password from the vault:

conn = postgresql("analyticsDataSource", "svc-account", getSecret("PgPassword"));

Cloud storage (S3 / Azure Blob / GCS)

MATLAB's file I/O (readtable, datastore, etc.) reads cloud URIs directly and picks up credentials from the SDK's environment variables. When you hold explicit keys, source them from the vault and set the env vars the SDK expects; when running on cloud infrastructure, prefer an attached IAM role and set nothing.

% Explicit keys held in the vault -> set the SDK env vars from getSecret:
setenv("AWS_ACCESS_KEY_ID",     getSecret("AwsAccessKeyId"));
setenv("AWS_SECRET_ACCESS_KEY", getSecret("AwsSecretAccessKey"));
setenv("AWS_DEFAULT_REGION",    "us-east-1");   % REPLACE: bucket region
T = readtable("s3://acme-data/prices/latest.csv");

If the code runs on an EC2 instance / role-enabled environment, skip the keys entirely — the IAM role supplies credentials and no secret needs to live anywhere.

Passing a credential into a function

When a function accepts credentials from its caller, carry a secretID (a reference), never the value. It resolves to the secret only where getSecret is called.

Build the config — it carries a reference, not the token:

config = struct( ...
    "BaseUrl", "https://api.example.com/v1", ...
    "Token",   secretID("MyApiToken"));

Use the config inside the function — resolve the secret only at the point of use:

function report = fetchReport(config)
    arguments
        config (1,1) struct
    end
    token = getSecret(config.Token.Name);
    opts  = weboptions(HeaderFields = ["Authorization", "Bearer " + token]);
    report = webread(config.BaseUrl + "/report", opts);
end

Load a set of secrets at once (setup or CI)

importSecrets loads names+values from a secrets file into the vault with no prompt — useful both for one-shot interactive setup and for headless jobs (where setSecret cannot be used, since it is interactive-only).

% secrets.env — a dotenv file (e.g. from CI secret storage), never committed — with lines like:
%   MyApiToken=abc123
%   PgPassword=hunter2
importSecrets("secrets.env");     % FileType="auto" (default) detects the dotenv format
token = getSecret("MyApiToken");

If the runner injects a credential directly as a process environment variable rather than a file, getenv("MY_TOKEN") is the correct read — no vault needed.

Conventions

  • Always: reach for the vault (setSecret/getSecret) as the default for credentials you store; guard removeSecret with isSecret.
  • Always: to load several secrets at once, or in any headless/CI context, use importSecrets, not setSecret.
  • Never: hardcode a secret in a .m file, or write a secret value into a struct or a log — pass a secretID reference instead.
  • Prefer: passing secretID(...) to weboptions/Credentials over materializing the value with getSecret when the API accepts a reference.
  • Env vars are fine when the credential is genuinely a process env var (CI secret, cloud SDK convention) — don't over-correct into the vault where it adds nothing.

Common Mistakes

MistakeWhy It's WrongCorrect Approach
Hardcoding a token/password in the .m fileLeaks into version control; rotates badlygetSecret("Name") from the vault
Writing a secret value into a struct field or argument a function passes aroundPlaintext secret leaves the vaultCarry a secretID reference; resolve with getSecret at use
setSecret in a CI/batch/scheduled jobIt is only supported interactively — no value can be enteredimportSecrets populates the vault non-interactively
Calling deleteSecretNo such function existsremoveSecret("Name"), guarded by isSecret
Saving a credential to a .mat file with save() and reading it back with load()Writes the plaintext secret to disk, unencrypted and often committedKeep the value in the vault; persist only a secretID reference and resolve with getSecret at use

Errors and What They Mean

Error identifierWhen it occursFix
MATLAB:authnz:secretapis:KeyAlreadyExists — "A secret named 'X' already exists. Set 'Overwrite' to true…"setSecret("X") when X is already in the vaultTo rotate/update, call setSecret("X", Overwrite=true); otherwise pick a new name
MATLAB:authnz:secretapis:SecretValueNotFound — "No secret value found for secret name 'X'…"getSecret("X") when X was never stored (or the name is misspelled/wrong case)Store it first (setSecret/importSecrets); guard reads with isSecret("X"). Secret names are case-sensitive
MATLAB:authnz:secretapis:RemoveSecretFailed — "…No secret found for secret name 'X'."removeSecret("X") when X is not in the vaultGuard with if isSecret("X"); removeSecret("X"); end

Copyright 2026 The MathWorks, Inc.


レビュー

まだレビューはありません。使ってみた感想をお寄せください。

同じリポジトリのスキル

概要と使いどころ

Guide for accessing financial and economic data in MATLAB using the Datafeed Toolbox. Covers Bloomberg (market data via bloomberg/blp/bloombergHypermedia), FRED (Federal Reserve economic data via fredrs), Haver Analytics (economic data via haver/haverdirect/haverview), and LSEG Datastream (historical data via datastreamws). Use when connecting to any of these data providers from MATLAB.

日本語の概要は準備中です。原文の説明を表示しています。

matlab/matlab-agentic-toolkit1,1492026年10月9日 更新

Read BEFORE writing any code that adds Additive White Gaussian Noise (AWGN) to signals and converts between SNR, Eb/No, Es/No, and per-subcarrier SNR for communications simulations, using awgn(), convertSNR(), berawgn(). The default MATLAB patterns for AWGN (e.g., 'measured' option, manual SNR formulas) produce subtly incorrect results. This skill specifies the correct calling conventions, required function usage, and critical anti-patterns that must be avoided.

日本語の概要は準備中です。原文の説明を表示しています。

matlab/matlab-agentic-toolkit1,1492026年10月9日 更新

Analyze AMS waveform data using Mixed-Signal Blockset utilities: phase noise measurement, clock jitter, anti-aliased resampling, timing measurements, lock time, INL/DNL, ADC/DAC calibration, HSpice import. Use when analyzing time-domain voltage from PLL/VCO/clock simulations, measuring phase noise from variable-step solver output, computing jitter, or resampling non-uniform data.

日本語の概要は準備中です。原文の説明を表示しています。

matlab/matlab-agentic-toolkit1,1492026年10月9日 更新

Design and analyze electrically large antenna structures using MATLAB Antenna Toolbox. Covers reflector antennas (parabolic, Cassegrain, Gregorian, offset, corner, cylindrical, spherical, custom STL), reflectarrays and reconfigurable intelligent surfaces (RIS), antennas installed on platforms (vehicles, aircraft, ships, satellites), and radar cross section (RCS) analysis. Includes solver selection (MoM-PO, PO, MoM, FMM), mesh control, and GPU acceleration. Use when the user wants to design a dish/reflector antenna, reflectarray, analyze an antenna on a platform, or compute RCS.

日本語の概要は準備中です。原文の説明を表示しています。

matlab/matlab-agentic-toolkit1,1492026年10月9日 更新

Analyze data using MATLAB. Use when the task involves tables, timetables, time-series data, numeric arrays, sensor matrices, or gridded data — including but not limited to exploring, row filtering, sorting, cleaning, transforming, aggregating, smoothing, padding, trimming, and answering questions about data. MATLAB provides extensive, easy-to-use built-in functions for these workflows with no additional products required.

日本語の概要は準備中です。原文の説明を表示しています。

matlab/matlab-agentic-toolkit1,1492026年10月9日 更新

S-parameters, insertion loss, fields, currents, mesh control, and solver selection for RF PCB performance validation. TRIGGER: user asks to compute S-parameters, analyze insertion/return loss, extract fields or currents, compare MoM vs FEM, or control mesh for any RF PCB component. Invoke BEFORE writing sparameters() or solver code — API is non-obvious. SKIP: designing or creating components (use the specific matlab-design-pcb-* skill), material/stackup setup only (use matlab-manage-pcb-material), optimization sweeps (use matlab-optimize-pcb-design), PDN/IR-drop analysis (use matlab-analyze-pcb-pdn).

日本語の概要は準備中です。原文の説明を表示しています。

matlab/matlab-agentic-toolkit1,1492026年10月9日 更新

matlab のスキルをすべて見る

このスキルの問題を報告する