agentsclimarketplace

Secret scan

Skill K95M65/AI_ONBOARD/skills/secret-scan

Scan a repository for committed secrets (API keys, tokens, private keys) including git history. Use when auditing a codebase for leaked credentials, before open-sourcing, or when reviewing an unfamiliar repo. Complements the security-audit surface scan, which only covers the current tree.From its SKILL.md

Install
npx -y skills add K95M65/AI_ONBOARD --skill secret-scan

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

SKILL.md

1.5 KB, 296 tokens by cl100k_base, as published. Nobody here has run it

Secret scan

When to use

Hunting for committed secrets across the current tree and git history. Complements security-audit's surface-scan.sh, which greps only the working tree.

Steps

  1. Run bash scripts/scan.sh [path]. It prefers a real scanner and falls back to grep:
    • gitleaks detect (tree + history) if installed — best.
    • else trufflehog filesystem if installed.
    • else a best-effort grep over tracked files — tree only, history not covered (it says so).
  2. For each hit: confirm it's a real secret (not a placeholder or test fixture), and determine whether it's live.
  3. If a live secret is found: rotate it first. A committed secret must be assumed compromised — removing it from the code is not enough.
  4. If it's in history, note that scrubbing requires a history rewrite (git filter-repo) and rotation; a new commit that deletes the file does not remove it from history.

Notes

  • Rotate first, scrub second. Order matters.
  • The grep fallback is shallow (tree only, limited patterns) — install gitleaks for real history coverage: https://github.com/gitleaks/gitleaks.

What ships with it: 1 file

1.3 KB alongside SKILL.md, 1 of them executable

scripts/

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.