Agent skill

Secrets Audit

by briiirussell in briiirussell/cybersecurity-skills

Find leaked secrets in source code, Git history, build artifacts, and infrastructure — and audit the secrets-management posture preventing future leaks.

MITAuto-check: notesDevOps & Cloud

Install Secrets Audit

skills CLI
$ npx skills add briiirussell/cybersecurity-skills --skill secrets-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install briiirussell/cybersecurity-skills secrets-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/briiirussell/cybersecurity-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/secrets-audit .claude/skills/secrets-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secrets-audit
GitHub stars
413
Token cost
~2.6k tokens
SKILL.md length
1,063 words
Files
1
Skills in repo
25
Repo updated
First seen
Licence
MIT

At a glance

Find leaked secrets in source code, Git history, build artifacts, and infrastructure — and audit the secrets-management posture preventing future leaks.

  • Works in 7 steps: Verify it's live — use the provider's… → Determine exposure window — first commit… → Determine blast radius — what does this… → …
  • The user mentions secrets audit
  • SKILL.md covers Part 1 — Find leaked secrets, Part 2 — Audit…, Output Format and Boundaries, plus 1 more section
  • Calls git, gitleaks and docker; needs AWS_SECRET

What it does

Secrets Audit is an agent skill from briiirussell/cybersecurity-skills. Find leaked secrets in source code, Git history, build artifacts, and infrastructure — and audit the secrets-management posture preventing future leaks. Use when the user mentions 'secrets audit,' 'secret scanning,' 'leaked credentials,' 'API key in code,' 'gitleaks,' 'trufflehog,' 'git history scan,' 'secrets management,' 'vault audit,' 'rotation policy,' 'AWS Secrets Manager,' 'HashiCorp Vault,' 'Doppler,' '1Password Secrets Automation,' 'sealed-secrets,' 'External Secrets Operator,' or needs to find or prevent…

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Secrets management. It works with Amazon Web Services, HashiCorp Vault and Git. The repository describes itself as: Cybersecurity skills for AI coding agents (Claude Code, Cursor, Codex). The licence is MIT.

When your agent uses it

  • The user mentions secrets audit
  • Secret scanning
  • Leaked credentials
  • API key in code

Example prompts

  • “secrets audit,”
  • “secret scanning,”
  • “leaked credentials,”
  • “/secrets-audit”

Requirements

  • Docker
  • A credential in AWS_SECRET
  • Pre-approved tools (allowed-tools): Bash, Read, Write, Grep, Glob, WebSearch

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Verify it's live — use the provider's verification (aws sts get-caller-identity, stripe balance retrieve, curl -H "Authorization: Bearer…
  2. Determine exposure window — first commit it appeared in, when the repo went public, when CI logs were retained from
  3. Determine blast radius — what does this key access? What can be done with it? IAM permissions, Stripe live vs test, GitHub repo vs admin:org
  4. Rotate immediately — generate a new key, deploy it, then revoke the old one (revoke-first breaks prod)
  5. Audit for use — provider audit logs (CloudTrail, GitHub audit log, Stripe events) for any activity from the leaked credential
  6. Then clean — remove from current code, then optionally history-rewrite (low priority once rotated)
  7. Document — incident report, even if rotation was clean; recurrence patterns surface trends

What it can do on your machine

Read from SKILL.md and the folder at commit c9ade03. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • Write
    • Grep
    • Glob
    • WebSearch

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • gitleaks
    • docker
    • aws
    • stripe
    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, docker, aws and curl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • AWS_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secrets Audit loads about 2.6k tokens when it runs. Until then it costs about 138 tokens; SKILL.md has 1,063 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~138
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:91
    Secrets leak in places that aren't `.env` files:
  • NoteMentions a .env fileSKILL.md:99
    - **Public S3 / blob storage** — `.env` accidentally uploaded
  • NoteMentions a .env fileSKILL.md:125
    | ⚠️ | `.env` file in repo (even with .gitignore — easy to leak via push, backup, archive) | Bootstrap only; flagged in
  • NoteMentions a .env fileSKILL.md:140
    - **No `.env` committed** — `.gitignore` covers `.env*` (with care for `.env.example`)
  • NoteMentions a .env fileSKILL.md:153
    - **`.env.local` shipped to staging** — environment-specific dev secrets cross the boundary
  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, Write, Grep, Glob, WebSearch

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from briiirussell/cybersecurity-skills at commit c9ade03, republished under its MIT licence (© briiirussell). 1,063 words, ~2,594 tokens.

Download SKILL.mdSave it as .claude/skills/secrets-audit/SKILL.md (or your agent's skills folder).
name
secrets-audit
description
Find leaked secrets in source code, Git history, build artifacts, and infrastructure — and audit the secrets-management posture preventing future leaks. Use when the user mentions 'secrets audit,' 'secret scanning,' 'leaked credentials,' 'API key in code,' 'gitleaks,' 'trufflehog,' 'git history scan,' 'secrets management,' 'vault audit,' 'rotation policy,' 'AWS Secrets Manager,' 'HashiCorp Vault,' 'Doppler,' '1Password Secrets Automation,' 'sealed-secrets,' 'External Secrets Operator,' or needs to find or prevent credential exposure.
allowed-tools
Bash, Read, Write, Grep, Glob, WebSearch

Secrets Audit — Credential Exposure and Secrets-Management Review

Two halves: (1) find secrets that have already leaked into source, history, or artifacts, and (2) audit the secrets-management posture that determines whether future leaks happen.

Most secret leaks aren't "we forgot to redact" — they're "we never had a system, so every developer made up their own approach." This skill covers both the cleanup and the prevention.

Cross-references: dependency-audit (CI-related secrets risk in build-time exposure), iam-audit (workload identity federation as the alternative to long-lived keys), owasp-audit A02 (in-source secret patterns).

Part 1 — Find leaked secrets

Provider key prefixes (high-confidence patterns)

The most useful first sweep is grep against known provider key prefixes. False positives are low and matches are almost always real.

bash
# Stripe
grep -rE "(sk_live_|sk_test_|rk_live_|whsec_)[A-Za-z0-9]{20,}" . \
  --include="*.{js,ts,jsx,tsx,py,rb,go,java,php,sh,env,yml,yaml,json}"

# AWS access keys
grep -rE "(AKIA|ASIA)[A-Z0-9]{16}" .

# AWS secret keys (40 chars, base64-y) — high FP rate, use with caution
grep -rE "[A-Za-z0-9/+=]{40}" . --include="*.env*" --include="*.json"

# GitHub
grep -rE "gh[pousr]_[A-Za-z0-9]{36}" .

# Google Cloud API key + service-account JSON
grep -rE "AIza[A-Za-z0-9_-]{35}" .
grep -rln '"type": "service_account"' . --include="*.json"

# Slack
grep -rE "xox[baprs]-[A-Za-z0-9-]+" .

# OpenAI / Anthropic
grep -rE "sk-[A-Za-z0-9]{32,}" .
grep -rE "sk-ant-[A-Za-z0-9_-]{90,}" .

# Generic high-entropy strings in env files
grep -rE "^[A-Z_]+=[A-Za-z0-9/+=]{32,}$" . --include="*.env*"

For full repo coverage, use git ls-files to scope to tracked files and avoid node_modules:

bash
git ls-files | xargs grep -lE 'sk_live_|ghp_|AKIA[A-Z0-9]{16}|sk-ant-|AIza[A-Za-z0-9_-]{35}' 2>/dev/null
Tooling
ToolUse
gitleaks detectFast, low FP, run as pre-commit and in CI; supports custom rules
trufflehog git file://.Verifies findings against the real API (high confidence)
detect-secrets scanYelp's tool; good baseline file workflow
GitHub Secret ScanningFree for public repos; covers most providers automatically; pushes get blocked at push time when enabled with push protection
GitLab Secret DetectionSimilar, built-in to CI
GitGuardian / Doppler / SpectralCommercial; add organizational dashboards and historical analysis
Git history (the part people forget)

A secret deleted in the latest commit is still in history — git log -p, git log -S<secret>, and any fork or local clone all have it.

bash
# Search every commit for a pattern
git log -p -S "sk_live_" --all

# Search only deleted lines
git log -p --all | grep -E "^-.*sk_live_"

# Trufflehog historical scan
trufflehog git file://. --since-commit=<first-commit>

# Git history rewrite — destructive, coordinate first
git filter-repo --invert-paths --path config/secrets.yml
# or
bfg --delete-files secrets.yml

Critical caveat: rewriting history requires every developer to re-clone, every fork is still exposed, and the secret should be considered compromised regardless. Always rotate first, history-rewrite second.

Build artifacts and other forgotten places

Secrets leak in places that aren't .env files:

  • Docker images — docker history <image> shows every ENV line; --build-arg SECRET=... ends up in layers
  • CI environment — secrets logged by set -x, console.log(process.env), error stack traces, debug output
  • Frontend bundles — NEXT_PUBLIC_* / VITE_* / REACT_APP_* env vars are shipped to the browser; grep the bundled JS
  • Crash reports — Sentry / Datadog / Bugsnag capturing process.env snapshots
  • Logs — application logs shipped to a SIEM that has weaker access controls than the app
  • Backups — pg_dump of a table that includes user-stored API keys
  • Public S3 / blob storage — .env accidentally uploaded
  • Documentation — README.md examples with real keys instead of placeholders
  • Slack / Notion / Linear — pasted in a DM "to test," never rotated
  • Browser localStorage / cookies — captured in shared screenshots or session replays
Triaging a found secret

When you find a leaked secret:

  1. Verify it's live — use the provider's verification (aws sts get-caller-identity, stripe balance retrieve, curl -H "Authorization: Bearer $TOKEN" ...) — don't assume; some leaked keys are already revoked or were sandbox-only
  2. Determine exposure window — first commit it appeared in, when the repo went public, when CI logs were retained from
  3. Determine blast radius — what does this key access? What can be done with it? IAM permissions, Stripe live vs test, GitHub repo vs admin:org
  4. Rotate immediately — generate a new key, deploy it, then revoke the old one (revoke-first breaks prod)
  5. Audit for use — provider audit logs (CloudTrail, GitHub audit log, Stripe events) for any activity from the leaked credential
  6. Then clean — remove from current code, then optionally history-rewrite (low priority once rotated)
  7. Document — incident report, even if rotation was clean; recurrence patterns surface trends

Part 2 — Audit secrets-management posture

The hierarchy of secret storage (worst → best)
TierPatternWhen acceptable
❌Hardcoded in sourceNever
❌Hardcoded in image / build artifactNever
❌Plaintext in shared docs / SlackNever
⚠️.env file in repo (even with .gitignore — easy to leak via push, backup, archive)Bootstrap only; flagged in audit
⚠️Environment variables (only)Acceptable for ephemeral dev; weak for prod (visible in /proc, crash dumps, logs)
🟢Secrets manager pulled at deploy timeStandard for most apps
🟢Workload identity federation (no stored secret at all)Best where supported
Show full SKILL.md (430 more words)Show less
Cloud-provider secrets managers
  • AWS Secrets Manager / Parameter Store (SecureString) — integrate via IAM-scoped IRSA / task role / Lambda role
  • GCP Secret Manager — bind via Workload Identity to GSA, GSA pulls secret
  • Azure Key Vault — pull via managed identity
  • Doppler / Infisical / 1Password Secrets Automation — cross-cloud, developer-friendly
Audit checklist
  • No secrets in Git history (run gitleaks --all)
  • No .env committed — .gitignore covers .env* (with care for .env.example)
  • Secrets fetched at runtime, not embedded at build — image rebuild is not required to rotate
  • IAM scoped to the secret — service A can read secret A, not secret B
  • Rotation cadence — defined per secret class (admin: 30d, service: 90d, customer-shared: per breach response)
  • Rotation is automated — if a human runs a script every 90 days, rotation will eventually drift
  • Access logged — every Get / Decrypt call is in an audit trail
  • No long-lived cloud keys for workloads — workload identity federation everywhere it's supported (see iam-audit)
  • Break-glass procedure — when the secrets manager is down, how do critical services come up? (Usually: cached on disk encrypted, with strict re-fetch on restart)
  • Cross-environment isolation — staging cannot read prod secrets, ever (different KMS keys, different IAM)
Common findings
  • Rotation never tested — secret stores configured, never actually rotated; first attempt breaks prod
  • .env.local shipped to staging — environment-specific dev secrets cross the boundary
  • CI secrets accessible from PRs from forks — GitHub's default behavior was previously dangerous; verify pull_request_target and secret accessibility
  • Build args used for secrets — --build-arg AWS_SECRET=... ends up in image history (use --secret/BuildKit instead)
  • Logging frameworks dump process.env on unhandled exception — Sentry / Datadog / Bugsnag scrub config required
  • Secret stored in K8s as plain Secret without etcd encryption — base64 is encoding, not encryption (see container-audit)
  • OAuth client secrets in mobile apps — public clients can't hold secrets; PKCE is the answer

Output Format

markdown
# Secrets Audit Report
## Scope: [repos / environments / managers covered]
## Date: [date]

### Live leaked secrets found
| Provider | Location | First seen (commit / date) | Verified live? | Rotation status |
|---|---|---|---|---|

### Secrets-management posture
| Category | Status | Notes |
|---|---|---|

### Recommendations
| Priority | Item | Owner | Deadline |
|---|---|---|---|

Disposition rule (Fixed / Deferred / Accepted Risk) per owasp-audit.

Boundaries

  • Only audit repositories, CI systems, and infrastructure the user has authorization for
  • Never use a found secret to access the provider — verify it's live with a minimal API call (account info, not data extraction); do not pivot
  • For history rewrite operations: never proceed without explicit confirmation and a coordinated developer-notification plan
  • Refuse to help collect or weaponize leaked secrets found in other people's repos
  • If the audit surfaces credentials belonging to a third party (vendor, employee personal accounts), notify and rotate; don't quietly fix

References

  • OWASP Cheat Sheet: Secrets Management
  • NIST SP 800-57 (Recommendation for Key Management)
  • GitGuardian "State of Secrets Sprawl" annual reports — useful for industry context
  • gitleaks, trufflehog, detect-secrets documentation
  • GitHub Secret Scanning + Push Protection documentation
  • HashiCorp Vault Architecture / Best Practices
  • AWS Secrets Manager Best Practices
  • "Twelve-Factor App" — Config principles

© briiirussell, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/secrets-audit of briiirussell/cybersecurity-skills.

Open the folder on GitHubat commit c9ade03

Compare with similar skills

Secrets Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secrets Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secrets Audit this skillbriiirussell/cybersecurity-skills413—~2.6kAutomated safety check: NotesMIT
Hashicorp VaultBagelHole/DevOps-Security-Agent-Skills1.2k—~2kAutomated safety check: PassMIT
Secrets Managementdavila7/claude-code-templates33k12 repos~2kAutomated safety check: PassMIT
Secrets Vault Manageralirezarezvani/claude-skills28k1 repos~3.6kAutomated safety check: NotesMIT
Managing Secretsancoleman/ai-design-components525—~2.9kAutomated safety check: PassMIT
Audit Env Variablesqdhenry/Claude-Command-Suite1.3k—~2.8kAutomated safety check: NotesNone

Similar skills

  • Hashicorp Vault

    BagelHole/DevOps-Security-Agent-Skills

    Manage secrets and PKI with HashiCorp Vault. An agent skill from BagelHole/DevOps-Security-Agent-Skills.

    1.2k GitHub stars~2k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check passed
  • Secrets Management

    davila7/claude-code-templates

    Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools.

    33k GitHub starsUsed in 12 repos~2k tokens
    DevOps & CloudAuto-check passed
  • Secrets Vault Manager

    alirezarezvani/claude-skills

    A skill your agent uses when the user asks to set up secret management infrastructure, integrate HashiCorp Vault, configure cloud secret stores (AWS Secrets Manager, Azure Key Vault, GCP Secret…

    28k GitHub starsUsed in 1 repo~3.6k tokens
    DevOps & CloudAuto-check: notes
  • Managing Secrets

    ancoleman/ai-design-components

    Managing secrets (API keys, database credentials, certificates) with Vault, cloud providers, and Kubernetes.

    525 GitHub stars~2.9k tokensUpdated 10 mo ago
    DevOps & CloudAuto-check passed
  • Audit Env Variables

    qdhenry/Claude-Command-Suite

    Analyze environment variables in JavaScript/TypeScript projects.

    1.3k GitHub stars~2.8k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check: notes
  • Private Secret Scanning

    jamditis/claude-skills-journalism

    Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports.

    416 GitHub stars~1.8k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed

More from briiirussell/cybersecurity-skills

All 25 skills in this repo
  • AI Risk Management

    briiirussell/cybersecurity-skills

    Apply the NIST AI Risk Management Framework (AI RMF 1.0) and adjacent guidance to AI / ML systems — model lifecycle governance, fairness and bias evaluation, robustness, transparency…

    413 GitHub stars~3.7k tokensUpdated 4 mo ago
    Auto-check: notes
  • API Audit

    briiirussell/cybersecurity-skills

    Audit REST, GraphQL, and RPC APIs against the OWASP API Security Top 10 (2023).

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes
  • Breach Patterns

    briiirussell/cybersecurity-skills

    Learn from public breach disclosures — extract the audit question each one implies and check your own stack.

    413 GitHub stars~3.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Cloud Audit

    briiirussell/cybersecurity-skills

    Audit cloud infrastructure (AWS, GCP, Azure) for misconfigurations, excessive permissions, and security gaps.

    413 GitHub stars~1.3k tokensUpdated 4 mo ago
    Auto-check: notes
  • Container Audit

    briiirussell/cybersecurity-skills

    Audit container images, Dockerfiles, and Kubernetes manifests for misconfigurations, excessive privileges, exposed secrets, and runtime risks.

    413 GitHub stars~2.5k tokensUpdated 4 mo ago
    Auto-check: notes
  • Crypto Audit

    briiirussell/cybersecurity-skills

    Audit cryptography implementation — algorithm choice, key sizes, KDF parameters, IV/nonce handling, signature verification, randomness, TLS configuration, and key rotation.

    413 GitHub stars~2.8k tokensUpdated 4 mo ago
    Auto-check: notes

Categories

Questions about Secrets Audit

What does Secrets Audit do?

Find leaked secrets in source code, Git history, build artifacts, and infrastructure — and audit the secrets-management posture preventing future leaks. Secrets Audit is an agent skill from briiirussell/cybersecurity-skills. Find leaked secrets in source code, Git history, build artifacts, and infrastructure — and audit the secrets-management posture preventing future leaks.

When should I use Secrets Audit?

Secrets Audit fits situations like: the user mentions secrets audit; secret scanning; leaked credentials; API key in code.

How do I install Secrets Audit in Claude Code?

Run `npx skills add briiirussell/cybersecurity-skills --skill secrets-audit -a claude-code`. Or copy the skill folder (skills/secrets-audit in briiirussell/cybersecurity-skills) into .claude/skills/secrets-audit in your project. Claude Code loads it when a task matches its description.

How do I install Secrets Audit in Codex?

Run `npx skills add briiirussell/cybersecurity-skills --skill secrets-audit -a codex`. Or copy the skill folder (skills/secrets-audit in briiirussell/cybersecurity-skills) into .agents/skills/secrets-audit in your project. Codex loads it when a task matches its description.

Can I use Secrets Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add briiirussell/cybersecurity-skills --skill secrets-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secrets-audit, .gemini/skills/secrets-audit, .github/skills/secrets-audit and .opencode/skills/secrets-audit in your project.

What does Secrets Audit need to run?

Going by SKILL.md and its folder, Secrets Audit needs the command-line tools its instructions call (git, gitleaks, docker, aws, stripe and curl) and credentials named AWS_SECRET. Our summary lists: Docker; A credential in AWS_SECRET. Its frontmatter pre-approves these tools: Bash, Read, Write, Grep, Glob, WebSearch.

Does Secrets Audit access the network?

SKILL.md contains no URLs. Its commands use git, docker and curl, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Secrets Audit safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file; pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Secrets Audit use?

Secrets Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Secrets Audit use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Secrets Audit?

Skills that share tags, products or a category with Secrets Audit: Hashicorp Vault (BagelHole/DevOps-Security-Agent-Skills, 1.2k stars), Secrets Management (davila7/claude-code-templates, 33k stars), Secrets Vault Manager (alirezarezvani/claude-skills, 28k stars) and Managing Secrets (ancoleman/ai-design-components, 525 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secrets Audit?

briiirussell (a GitHub user) maintains it in briiirussell/cybersecurity-skills, which has 413 GitHub stars. The repository holds 25 skills in this directory. The repository was last updated on May 27, 2026.

Source: briiirussell/cybersecurity-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.