Custom secret modifier?

Hi!

Suppose I would need to re-use the SSH certificate secrets engine but do some additional validation on top (e.g. querying an API), what would be the best way to approach this?
Thanks.