The idea of secretspec is to fix it upstream.
We’ve since created IPC for resolver and provider that Nix will use.
We provide integrations for docker and git using existing credentials helpers but those protocols are subpar.
There’s also devenv machines which allows you to use secretspec when provisioning NixOS machines.
Fixing upstream software will take time, but with integrations guides and coding agents these days it’s not that much work.