agentsclimarketplace

Secrets sweeper lite

Skill guildshelf/free-skills/plugins/guildshelf-free/skills/secrets-sweeper-lite

Guildshelf free funnel skills for Claude Code — Apache-2.0. Try before you subscribe: guildshelf.com

Install
npx -y skills add guildshelf/free-skills --skill secrets-sweeper-lite

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

3 things to look at

  • 15 days oldThe repository was created 15 days ago. New is not bad, but a brand new repository carrying a familiar-sounding name is the shape a typosquat arrives in, and there has been no time for anyone else to find a problem with it.
  • no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Quick offline scan of a directory for the 10 most dangerous hardcoded credential types before publishing or sharing — private key blocks, AWS access keys, GitHub tokens, OpenAI / Anthropic / Google API keys, Slack tokens, Stripe live keys, JWTs, and generic key/secret/token assignments (entropy-checked). Prints masked findings straight to the terminal with CI-friendly exit codes; Python stdlib only, zero network calls, writes nothing to disk. Use when the user says "scan for secrets", "check for leaked keys", "did I hardcode a key somewhere", or before open-sourcing or handing off a repo. NOT for rotating or revoking credentials, scanning git history (working tree only), PII / IP-address / tunnel-domain / personal-path detection, custom denylists (names, internal terms), or exportable Markdown/JSON reports — those are in the full Secrets Hygiene Sweeper.

SKILL.md

5.1 KB, ~1.0k tokens by cl100k_base, as published. Nobody here has run it

Secrets Sweeper Lite

Scan anything you are about to publish, open-source, or hand to a contractor for the ten credential types that hurt the most — and get masked terminal findings before it leaves your machine.

When to use / when not to use

Use this skill when:

  • You are about to publish or open-source a directory and want a fast check that it contains no hardcoded keys or tokens.
  • You suspect a key was hardcoded somewhere in a project and want it located.
  • You want a lightweight CI gate that fails a build when a credential appears (exit code 1 on any finding).

Do NOT use this skill for:

  • Rotating, revoking, or validating credentials — the findings tell you where to rotate; the action is yours.
  • Scanning git history — this scans the working tree only.
  • PII coverage (emails, phone numbers, IPs, personal paths) or custom denylist terms (person names, internal codenames) — full version territory.
  • Runtime secret management — this is not a vault or a .env loader.
  • Malware or prompt-injection detection — out of scope by design.

Quick start

python scripts/sweeper_lite.py <target-dir>

That one line scans <target-dir> recursively, prints masked findings to the terminal, and exits 1 if anything was found (0 clean, 2 error).

python scripts/sweeper_lite.py --list-rules     # print the 10-rule table
python scripts/sweeper_lite.py <dir> --quiet    # findings + summary only

The 10 rules

#rule_idSeverityCatches
1private-key-blockCRITICALPEM / OpenSSH / PGP private key headers
2aws-access-key-idCRITICALAWS access key IDs
3github-tokenCRITICALGitHub classic + fine-grained tokens
4openai-keyCRITICALOpenAI classic + project-scoped keys
5anthropic-keyCRITICALAnthropic API keys
6google-api-keyCRITICALGoogle API keys
7slack-tokenCRITICALSlack bot/user/app tokens
8stripe-live-secret-keyCRITICALStripe live secret/restricted keys
9jwtHIGHSigned JSON Web Tokens
10generic-credential-assignmentHIGHkey/secret/token/password = "..." assignments, entropy-checked

Reading the output

  • Each finding prints as SEVERITY file:line:col rule_id masked-match.
  • Matches are masked — first 4 + last 2 characters kept, the rest starred. The output never contains a full secret, so pasting it into an issue or chat cannot become a second leak.
  • Placeholder values (YOUR_API_KEY, <TOKEN>, changeme, example, ...) are suppressed automatically; template files stay quiet.
  • Default-excluded dirs: .git, node_modules, __pycache__, venv, .venv, dist, build. Binary files and files over 5 MB are skipped.

Remediation workflow

  1. Run the scan.
  2. Rotate every CRITICAL credential at its provider console first — treat it as compromised.
  3. Replace hardcoded values with environment variables or a secret manager.
  4. Re-run until the scan reports zero findings.
  5. If a secret was ever committed, clean git history too (git filter-repo or BFG), then rotate again.

Privacy guarantee

Zero network calls: the engine imports Python standard library modules only and never opens a connection — nothing you scan leaves your machine. It also writes nothing to disk.

Lite vs. full

This Lite edition is complete and self-contained for credential scanning. The full Secrets Hygiene Sweeper adds: ~30 more rules (emails, phone numbers, public/private IPs, tunnel domains, personal home paths, more vendors), custom denylists for names and org-internal terms (the only reliable way to catch CJK names), masked Markdown + JSON report export, .sweeperignore and inline pragmas, --fail-on severity gating, and per-finding remediation guides — maintained with model-regression re-testing.

Disclaimer

This tool assists de-identification review; it does not guarantee that a directory is free of sensitive data, and its output is not legal or compliance advice. In principle, always pair automated scanning with human review before publishing.

Guildshelf is not affiliated with Anthropic. Claude is a trademark of Anthropic, used only to describe compatibility.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.