Safe repo
My personal SDLC toolbelt for AI coding agents — PRD to ship.
npx -y skills add helderberto/agent-skills --skill safe-repoAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 12 stars12 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
Check for sensitive data in repository. Use when user asks to "check for sensitive data", "/safe-repo", or wants to verify no company/credential data is in the repository. Use `--diff` mode to scope to staged + unstaged changes only (e.g., before commit). Don't use for general code review, adding .gitignore entries, or scanning non-git directories.
SKILL.md
2.0 KB, as published. Nobody here has run it
Safe Repository Check
Context
Security audit for sensitive data in repository. Check for credentials, API keys, company-specific information, and PII.
Modes
- Default (full-scan): scans all git-tracked files plus history. Use for periodic audits or first-time repo review.
--diff: scans only staged + unstaged changes (git diff+git diff --cached). Use before commit or when called fromreview/shipworkflows. Fast, no false positives from pre-existing files.
Workflow
Default (full-scan)
- Run
bash scripts/scan-secrets.shto scan all tracked files for credential patterns (see references/patterns.md for full pattern list) - Check for sensitive tracked files (.env, secrets)
- Analyze git history for removed secrets
- Review
.gitignorefor proper patterns - Report findings (see assets/report-template.md)
--diff mode
- Compute changed files:
git diff --name-only HEAD+git diff --name-only --cached - Scan only those files against the credential patterns
- Skip history analysis (not relevant for in-flight changes)
- Report findings scoped to changed files only
Rules
- Only check git-tracked files (
git ls-files) - ignore local configs - Check current tracked files AND git history
- Filter false positives: minified JS, node_modules, test fixtures, docs
- Verify
.gitignorecovers sensitive patterns - Report tracked files with secrets and historical commits
- Never output actual secret values in report
Error Handling
- If git history scan is slow → limit to last 100 commits with
git log --oneline -100