Secret scan
Scan a repository for committed secrets (API keys, tokens, private keys) including git history. Use when auditing a codebase for leaked credentials, before open-sourcing, or when reviewing an unfamiliar repo. Complements the security-audit surface scan, which only covers the current tree.From its SKILL.md
npx -y skills add K95M65/AI_ONBOARD --skill secret-scanAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
SKILL.md
1.5 KB, 296 tokens by cl100k_base, as published. Nobody here has run it
Secret scan
When to use
Hunting for committed secrets across the current tree and git history. Complements
security-audit's surface-scan.sh, which greps only the working tree.
Steps
- Run
bash scripts/scan.sh [path]. It prefers a real scanner and falls back to grep:gitleaks detect(tree + history) if installed — best.- else
trufflehog filesystemif installed. - else a best-effort grep over tracked files — tree only, history not covered (it says so).
- For each hit: confirm it's a real secret (not a placeholder or test fixture), and determine whether it's live.
- If a live secret is found: rotate it first. A committed secret must be assumed compromised — removing it from the code is not enough.
- If it's in history, note that scrubbing requires a history rewrite (
git filter-repo) and rotation; a new commit that deletes the file does not remove it from history.
Notes
- Rotate first, scrub second. Order matters.
- The grep fallback is shallow (tree only, limited patterns) — install
gitleaksfor real history coverage: https://github.com/gitleaks/gitleaks.
What ships with it: 1 file
1.3 KB alongside SKILL.md, 1 of them executable
scripts/
- scan.shruns1.3 KB