agentsclimarketplace

Trufflehog cli

Skill addxai/enterprise-harness-engineering/skills/trufflehog-cli

Enterprise-grade AI Agent Skills for software development, DevOps, SRE, security, and product teams. Compatible with Claude Code, Cursor, Windsurf, Gemini CLI, GitHub Copilot, and 30+ AI coding agents.

Install
npx -y skills add addxai/enterprise-harness-engineering --skill trufflehog-cli

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

What its author says it does

Copied from the file, not written here

Perform local secret scanning, remote repository scanning, pre-commit integration, and single-credential verification using TruffleHog CLI. Triggers when the user mentions trufflehog, secret scan, leaked credential investigation, Git history scan, remote repo scan, pre-commit, or post-rotation credential verification.

SKILL.md

5.2 KB, as published. Nobody here has run it

trufflehog-cli

Unified entry point Skill for TruffleHog CLI in this repository.

Load modules on demand:

For reproducible, auditable installation workflows, use the built-in scripts:

For pre-commit, use the built-in wrapper script:

Description

Treat this Skill as the company's standard operating manual for TruffleHog CLI.

It covers four primary workflows:

  • Local scanning: developer workstation files and local Git history
  • Pre-commit integration: block new leaks before they are committed
  • Remote repository scanning: scan a single HTTPS remote repository
  • Credential verification: confirm whether a leaked credential is still active

Do not extend this Skill into general-purpose SAST, dependency vulnerability scanning, or code auditing.

Rules

Rule 1 - Read the unified baseline first

Read install-and-baseline.md first.

Baseline rules apply to all workflows:

  • Version is sourced from trufflehog-version.txt as the single source of truth
  • Must use official GitHub Release binaries and verify the official checksum
  • All commands must include --no-update by default
  • Scan artifacts go to the system temp directory, never the repository root
  • Tokens must not appear in repository URLs or command-line arguments
  • Reports may only use TruffleHog's Redacted output; raw secret values must never be printed

Rule 2 - Select one primary workflow at a time

Determine the task type first, then load the corresponding reference:

Do not load all references at once by default.

Rule 3 - Match commands to scenarios

Choose the command family based on the actual scan scope:

  • trufflehog filesystem .: current workspace files
  • trufflehog git file://...: local repository history
  • trufflehog git <https-repo-url>: remote repository history
  • trufflehog analyze: only when an interactive TUI session is available

Do not force the same command onto every scenario.

Rule 4 - Least privilege first

Follow least-privilege for credentials:

  • For remote repository clone scanning, prefer read_repository
  • Only escalate to read_api/api when GitLab API-level verification is needed (e.g., PAT self-check)
  • Prefer short-lived credentials and explicitly clean up after the workflow completes

Rule 5 - Reports must clearly state scope and boundaries

Every result summary must include:

  • Scan target
  • Actual command family used
  • Execution directory or target repository
  • Result file location
  • Count of verified vs unknown findings
  • Scope constraints (e.g., --branch, --since-commit, --max-depth)

Do not claim coverage of branches that were not explicitly scanned.

Examples

Bad

User says “scan the repo,” and I run a generic command, write JSON to the repo root,
output plaintext secrets, and conclude “all branches are clean.”

Problems:

  • Command does not match scope
  • Pollutes the workspace
  • Leaks sensitive information
  • Conclusion exceeds actual coverage

Good

Confirm version, installation, and output strategy per the unified baseline first,
then select a single workflow with its corresponding command;
artifacts go to a temp directory, and the report clearly states what was and was not covered.

Strengths:

  • Single entry point + single baseline avoids duplicate maintenance
  • Progressive loading keeps the main document concise
  • Centralized rules simplify collaboration and auditing
  • Output is traceable and does not leak sensitive information

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.