Agent skill

Secret Scanner

by alirezarezvani in alirezarezvani/claude-code-tresor

Detect exposed secrets, API keys, credentials, and tokens in code.

MITAuto-check: warningsDevelopment

Install Secret Scanner

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add alirezarezvani/claude-code-tresor --skill secret-scanner -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install alirezarezvani/claude-code-tresor secret-scanner --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/alirezarezvani/claude-code-tresor.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security/secret-scanner .claude/skills/secret-scanner && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secret-scanner
GitHub stars
777
Token cost
~1.4k tokens
SKILL.md length
305 words
Files
2
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

Detect exposed secrets, API keys, credentials, and tokens in code.

  • Works in 5 steps: Never commit secrets - Use environment… → Use .gitignore - Add .env, secrets.json,… → Rotate exposed secrets - If committed,… → …
  • Security checks
  • SKILL.md covers When I Activate, What I Detect, Alert Examples and Detection Patterns, plus 8 more sections
  • Calls git; needs API_KEY and DB_PASSWORD

What it does

Secret Scanner is an agent skill from alirezarezvani/claude-code-tresor. Detect exposed secrets, API keys, credentials, and tokens in code. Use before commits, on file saves, or when security is mentioned. Prevents accidental secret exposure. Triggers on file changes, git commits, security checks, .env file modifications.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `README.md`).

It sits in Development, covering Commit messages and Secrets management. It works with Amazon Web Services. The repository describes itself as: A world-class collection of Claude Code utilities: autonomous skills, expert agents, slash commands, and prompts that supercharge your development workflow. The licence is MIT.

When your agent uses it

  • Security checks
  • .env file modifications

Example prompts

  • “/secret-scanner”

Requirements

  • Python 3
  • Docker
  • A credential in STRIPE_API_KEY
  • A credential in API_KEY
  • Pre-approved tools (allowed-tools): Read, Grep

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Never commit secrets - Use environment variables
  2. Use .gitignore - Add .env, secrets.json, etc.
  3. Rotate exposed secrets - If committed, rotate immediately
  4. Use secret management - AWS Secrets Manager, HashiCorp Vault
  5. Audit regularly - Review code for exposed secrets

What it can do on your machine

Read from SKILL.md and the folder at commit 4b68050. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • API_KEY
    • DB_PASSWORD
    • STRIPE_API_KEY
    • AWS_ACCESS_KEY_ID

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secret Scanner loads about 1.4k tokens when it runs. Until then it costs about 66 tokens; SKILL.md has 305 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • NoteMentions a .env fileSKILL.md:3
    e changes, git commits, security checks, .env file modifications.
  • NoteMentions a .env fileSKILL.md:16
    - ✅ .env files changed
  • NoteMentions a .env fileSKILL.md:59
    📖 Add to .gitignore: .env
  • NoteMentions a .env fileSKILL.md:84
    🔧 Fix: Use .env file
  • NoteMentions a .env fileSKILL.md:86
    📖 Add .env to .gitignore
  • NoteMentions a .env fileSKILL.md:121
    - .env:5 - Database password (in gitignore - OK)
  • NoteMentions a .env fileSKILL.md:132
    ✅ .env - In .gitignore (good)
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:134
    ✅ .aws/credentials - In .gitignore (good)
  • NoteMentions a .env fileSKILL.md:181
    // .env file (add to .gitignore):
  • NoteMentions a .env fileSKILL.md:201
    - API_KEY=${API_KEY}  # From .env file

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from alirezarezvani/claude-code-tresor at commit 4b68050, republished under its MIT licence (© alirezarezvani). 305 words, ~1,445 tokens.

Download SKILL.mdSave it as .claude/skills/secret-scanner/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
secret-scanner
description
Detect exposed secrets, API keys, credentials, and tokens in code. Use before commits, on file saves, or when security is mentioned. Prevents accidental secret exposure. Triggers on file changes, git commits, security checks, .env file modifications.
allowed-tools
Read, Grep

Secret Scanner Skill

Prevent accidental secret exposure in your codebase.

When I Activate

  • ✅ Before git commits
  • ✅ Files modified/saved
  • ✅ User mentions secrets, keys, or credentials
  • ✅ .env files changed
  • ✅ Configuration files modified

What I Detect

API Keys & Tokens
  • AWS access keys (AKIA...)
  • Stripe API keys (sk_live_..., pk_live_...)
  • GitHub tokens (ghp_...)
  • Google API keys
  • OAuth tokens
  • JWT secrets
Database Credentials
  • Database connection strings
  • MySQL/PostgreSQL passwords
  • MongoDB connection URIs
  • Redis passwords
Private Keys
  • SSH private keys
  • RSA/DSA keys
  • PGP/GPG keys
  • SSL certificates
Authentication Secrets
  • Password variables
  • Auth tokens
  • Session secrets
  • Encryption keys

Alert Examples

API Key Detection
javascript
// You type:
const apiKey = 'sk_live_1234567890abcdef';

// I immediately alert:
🚨 CRITICAL: Exposed Stripe API key detected!
📍 File: config.js, Line 3
🔧 Fix: Use environment variables
  const apiKey = process.env.STRIPE_API_KEY;
📖 Add to .gitignore: .env
AWS Credentials
python
# You type:
aws_access_key = "AKIAIOSFODNN7EXAMPLE"

# I alert:
🚨 CRITICAL: AWS access key exposed!
📍 File: aws_config.py, Line 1
🔧 Fix: Use AWS credentials file or environment variables
  aws_access_key = os.getenv("AWS_ACCESS_KEY_ID")
📖 Never commit AWS credentials
Database Password
yaml
# You type in docker-compose.yml:
environment:
  DB_PASSWORD: "mySecretPassword123"

# I alert:
🚨 CRITICAL: Database password in configuration file!
📍 File: docker-compose.yml, Line 5
🔧 Fix: Use .env file
  DB_PASSWORD: ${DB_PASSWORD}
📖 Add .env to .gitignore

Detection Patterns

Pattern Types

High Confidence:

  • Known API key formats (Stripe, AWS, etc.)
  • Private key headers
  • JWT tokens
  • Connection strings with credentials

Medium Confidence:

  • Variables named "password", "secret", "key"
  • Base64 encoded strings in sensitive contexts
  • Long random strings in assignments

Low Confidence (Flagged for Review):

  • Generic secret patterns
  • Potential credentials in comments

Git Integration

Pre-Commit Protection
bash
# Before commit, I scan:
git add .
git commit

# I block if secrets found:
🚨 CRITICAL: Cannot commit - secrets detected!
📍 3 secrets found:
  - config.js:12 - API key
  - .env:5 - Database password (in gitignore - OK)
  - auth.js:45 - JWT secret

❌ Commit blocked - remove secrets first
.gitignore Validation

I check if sensitive files are in .gitignore:

✅ .env - In .gitignore (good)
⚠️ config/secrets.json - NOT in .gitignore (add it!)
✅ .aws/credentials - In .gitignore (good)

False Positive Handling

Example Files
javascript
// I understand these are examples:
// Example: const apiKey = 'your_api_key_here';
// TODO: Add your API key from environment
Test Files
javascript
// Test fixtures are OK (but flagged for review):
const mockApiKey = 'sk_test_1234567890abcdef';  // ✅ Test key
Documentation
markdown
<!-- Documentation examples are flagged but low priority -->
Set your API key: `export API_KEY=your_key_here`

Relationship with security-auditor

secret-scanner (me): Exposed secrets and credentials security-auditor: Code vulnerability patterns

Together
secret-scanner: Finds hardcoded API key
security-auditor: Finds how the key is used insecurely
Combined: Complete security picture

Quick Fixes

Move to Environment Variables
javascript
// Before:
const apiKey = 'sk_live_abc123';

// After:
const apiKey = process.env.API_KEY;

// .env file (add to .gitignore):
API_KEY=sk_live_abc123
Use Secret Management
javascript
// AWS Secrets Manager
const AWS = require('aws-sdk');
const secrets = new AWS.SecretsManager();
const secret = await secrets.getSecretValue({ SecretId: 'myApiKey' }).promise();
Configuration Files
yaml
# docker-compose.yml
services:
  app:
    environment:
      - API_KEY=${API_KEY}  # From .env file

# .env (gitignored)
API_KEY=sk_live_abc123

Sandboxing Compatibility

Works without sandboxing: ✅ Yes (recommended) Works with sandboxing: ✅ Yes

  • Filesystem: Read-only access
  • Network: None required
  • Configuration: None required

Customization

Add company-specific secret patterns:

bash
cp -r ~/.claude/skills/security/secret-scanner \
      ~/.claude/skills/security/company-secret-scanner

# Edit SKILL.md to add:
# - Internal API key formats
# - Company-specific secret patterns
# - Custom detection rules

Best Practices

  1. Never commit secrets - Use environment variables
  2. Use .gitignore - Add .env, secrets.json, etc.
  3. Rotate exposed secrets - If committed, rotate immediately
  4. Use secret management - AWS Secrets Manager, HashiCorp Vault
  5. Audit regularly - Review code for exposed secrets

Emergency Response

If Secret Committed
  1. Rotate the secret immediately
  2. Remove from git history
    bash
    git filter-branch --force --index-filter \
      "git rm --cached --ignore-unmatch config/secrets.json" \
      --prune-empty --tag-name-filter cat -- --all
  3. Force push (coordinate with team)
  4. Update all deployments with new secret
  • security-auditor skill: Vulnerability detection
  • @code-reviewer sub-agent: Security review
  • /review command: Comprehensive security check

© alirezarezvani, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/security/secret-scanner of alirezarezvani/claude-code-tresor.

  • SKILL.md
  • README.md

Open the folder on GitHubat commit 4b68050

Compare with similar skills

Secret Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secret Scanner compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secret Scanner this skillalirezarezvani/claude-code-tresor777—~1.4kAutomated safety check: WarnMIT
Git HooksProrise-cool/Claude-Code-Multi-Agent305—~3.6kAutomated safety check: NotesNone
Varlock Claude Skillaiskillstore/marketplace4305 repos~226Automated safety check: PassNone
Codex GuardAkimiya-z/codex-guard138—~564Automated safety check: PassMIT
Security SecretsIgorWarzocha/Opencode-Workflows122—~1.2kAutomated safety check: NotesNone
Scanning For Hardcoded Secretsjeremylongshore/tons-of-skills-marketplace2.8k—~2.1kAutomated safety check: NotesMIT

Similar skills

  • Git Hooks

    Prorise-cool/Claude-Code-Multi-Agent

    Central authority on git hook implementations, modern best practices, and tooling for .NET/C, JavaScript/TypeScript, Python, and polyglot repositories.

    305 GitHub stars~3.6k tokensUpdated 23 days ago
    DevelopmentAuto-check: notes
  • Varlock Claude Skill

    aiskillstore/marketplace

    Secure environment variable management ensuring secrets are never exposed in Claude sessions, terminals, logs, or git commits

    430 GitHub starsUsed in 5 repos~226 tokens
    DevelopmentAuto-check passed
  • Codex Guard

    Akimiya-z/codex-guard

    Pre-submit hygiene check for AI-agent-authored pull requests.

    138 GitHub stars~564 tokensUpdated 7 days ago
    DevelopmentAuto-check passed
  • Security Secrets

    IgorWarzocha/Opencode-Workflows

    Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows.

    122 GitHub stars~1.2k tokensUpdated 8 mo ago
    SecurityAuto-check: notes
  • Scanning For Hardcoded Secrets

    jeremylongshore/tons-of-skills-marketplace

    Scan a source-code tree for hardcoded credentials embedded in source files: AWS access keys, GitHub tokens, Stripe keys, Slack tokens, Anthropic API keys, OpenAI keys, JWT signing secrets, generic…

    2.8k GitHub stars~2.1k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Audit Env Variables

    qdhenry/Claude-Command-Suite

    Analyze environment variables in JavaScript/TypeScript projects.

    1.3k GitHub stars~2.8k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check: notes

More from alirezarezvani/claude-code-tresor

  • API Documenter

    alirezarezvani/claude-code-tresor

    Auto-generate API documentation from code and comments. An agent skill from alirezarezvani/claude-code-tresor.

    777 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Code Reviewer

    alirezarezvani/claude-code-tresor

    Automatic code quality and best practices analysis. An agent skill from alirezarezvani/claude-code-tresor.

    777 GitHub stars~1.8k tokensUpdated 3 mo ago
    Auto-check passed
  • Dependency Auditor

    alirezarezvani/claude-code-tresor

    Check dependencies for known vulnerabilities using npm audit, pip-audit, etc.

    777 GitHub stars~1.2k tokensUpdated 3 mo ago
    Auto-check: notes
  • Git Commit Helper

    alirezarezvani/claude-code-tresor

    Generate conventional commit messages automatically. An agent skill from alirezarezvani/claude-code-tresor.

    777 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check: notes
  • Readme Updater

    alirezarezvani/claude-code-tresor

    Keep README files current with project changes. An agent skill from alirezarezvani/claude-code-tresor.

    777 GitHub stars~1.5k tokensUpdated 3 mo ago
    Auto-check passed
  • Test Generator

    alirezarezvani/claude-code-tresor

    Automatically suggest tests for new functions and components.

    777 GitHub stars~1.6k tokensUpdated 3 mo ago
    Auto-check passed

Questions about Secret Scanner

What does Secret Scanner do?

Detect exposed secrets, API keys, credentials, and tokens in code. Secret Scanner is an agent skill from alirezarezvani/claude-code-tresor. Detect exposed secrets, API keys, credentials, and tokens in code.

When should I use Secret Scanner?

Secret Scanner fits situations like: security checks; .env file modifications.

How do I install Secret Scanner in Claude Code?

Run `npx skills add alirezarezvani/claude-code-tresor --skill secret-scanner -a claude-code`. Or copy the skill folder (skills/security/secret-scanner in alirezarezvani/claude-code-tresor) into .claude/skills/secret-scanner in your project. Claude Code loads it when a task matches its description.

How do I install Secret Scanner in Codex?

Run `npx skills add alirezarezvani/claude-code-tresor --skill secret-scanner -a codex`. Or copy the skill folder (skills/security/secret-scanner in alirezarezvani/claude-code-tresor) into .agents/skills/secret-scanner in your project. Codex loads it when a task matches its description.

Can I use Secret Scanner in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add alirezarezvani/claude-code-tresor --skill secret-scanner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secret-scanner, .gemini/skills/secret-scanner, .github/skills/secret-scanner and .opencode/skills/secret-scanner in your project.

What does Secret Scanner need to run?

Going by SKILL.md and its folder, Secret Scanner needs the command-line tools its instructions call (git) and credentials named API_KEY, DB_PASSWORD, STRIPE_API_KEY and AWS_ACCESS_KEY_ID. Our summary lists: Python 3; Docker; A credential in STRIPE_API_KEY; A credential in API_KEY. Its frontmatter pre-approves these tools: Read, Grep.

Does Secret Scanner access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Secret Scanner safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Secret Scanner use?

Secret Scanner is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Secret Scanner use?

About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Secret Scanner?

Skills that share tags, products or a category with Secret Scanner: Git Hooks (Prorise-cool/Claude-Code-Multi-Agent, 305 stars), Varlock Claude Skill (aiskillstore/marketplace, 430 stars), Codex Guard (Akimiya-z/codex-guard, 138 stars) and Security Secrets (IgorWarzocha/Opencode-Workflows, 122 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secret Scanner?

alirezarezvani (a GitHub user) maintains it in alirezarezvani/claude-code-tresor, which has 777 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on July 3, 2026.

Source: alirezarezvani/claude-code-tresor on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.