Compliance Scan
AojdevStudio/Finance-Guru
Privacy and security compliance scanner for the Finance Guru repo.
当用户希望让 OpenClaw 通过 ACP 调度 Claude Code,对 GitHub 仓库进行 API Key、Token、密码、私钥、Webhook URL 等敏感信息泄露巡检、自动修复、验收、推送修复 commit,并通过飞书发送巡检报告时使用。
$ npx skills add DjangoPeng/agentic-ai --skill github-secret-auditor -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install DjangoPeng/agentic-ai github-secret-auditor --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/DjangoPeng/agentic-ai.git skills-src && mkdir -p .claude/skills && cp -r skills-src/github-secret-auditor/skills/github-secret-auditor .claude/skills/github-secret-auditor && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "github-secret-auditor" agent skill from https://github.com/DjangoPeng/agentic-ai/tree/main/github-secret-auditor/skills/github-secret-auditor into .claude/skills/github-secret-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-secret-auditor", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/DjangoPeng/agentic-ai/tree/main/github-secret-auditor/skills/github-secret-auditorType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add DjangoPeng/agentic-ai --skill github-secret-auditor -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install DjangoPeng/agentic-ai github-secret-auditor --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/DjangoPeng/agentic-ai.git skills-src && mkdir -p .agents/skills && cp -r skills-src/github-secret-auditor/skills/github-secret-auditor .agents/skills/github-secret-auditor && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "github-secret-auditor" agent skill from https://github.com/DjangoPeng/agentic-ai/tree/main/github-secret-auditor/skills/github-secret-auditor into .agents/skills/github-secret-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-secret-auditor", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add DjangoPeng/agentic-ai --skill github-secret-auditor -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install DjangoPeng/agentic-ai github-secret-auditor --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/DjangoPeng/agentic-ai.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/github-secret-auditor/skills/github-secret-auditor .cursor/skills/github-secret-auditor && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "github-secret-auditor" agent skill from https://github.com/DjangoPeng/agentic-ai/tree/main/github-secret-auditor/skills/github-secret-auditor into .cursor/skills/github-secret-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-secret-auditor", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/DjangoPeng/agentic-ai.git --path github-secret-auditor/skills/github-secret-auditor--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add DjangoPeng/agentic-ai --skill github-secret-auditor -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install DjangoPeng/agentic-ai github-secret-auditor --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/DjangoPeng/agentic-ai.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/github-secret-auditor/skills/github-secret-auditor .gemini/skills/github-secret-auditor && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "github-secret-auditor" agent skill from https://github.com/DjangoPeng/agentic-ai/tree/main/github-secret-auditor/skills/github-secret-auditor into .gemini/skills/github-secret-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-secret-auditor", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install DjangoPeng/agentic-ai github-secret-auditorInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add DjangoPeng/agentic-ai --skill github-secret-auditor -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/DjangoPeng/agentic-ai.git skills-src && mkdir -p .github/skills && cp -r skills-src/github-secret-auditor/skills/github-secret-auditor .github/skills/github-secret-auditor && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "github-secret-auditor" agent skill from https://github.com/DjangoPeng/agentic-ai/tree/main/github-secret-auditor/skills/github-secret-auditor into .github/skills/github-secret-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-secret-auditor", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add DjangoPeng/agentic-ai --skill github-secret-auditor -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install DjangoPeng/agentic-ai github-secret-auditor --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/DjangoPeng/agentic-ai.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/github-secret-auditor/skills/github-secret-auditor .opencode/skills/github-secret-auditor && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "github-secret-auditor" agent skill from https://github.com/DjangoPeng/agentic-ai/tree/main/github-secret-auditor/skills/github-secret-auditor into .opencode/skills/github-secret-auditor/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "github-secret-auditor", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
github-secret-auditor当用户希望让 OpenClaw 通过 ACP 调度 Claude Code,对 GitHub 仓库进行 API Key、Token、密码、私钥、Webhook URL 等敏感信息泄露巡检、自动修复、验收、推送修复 commit,并通过飞书发送巡检报告时使用。
GitHub Secret Auditor is an agent skill from DjangoPeng/agentic-ai. 当用户希望让 OpenClaw 通过 ACP 调度 Claude Code,对 GitHub 仓库进行 API Key、Token、密码、私钥、Webhook URL 等敏感信息泄露巡检、自动修复、验收、推送修复 commit,并通过飞书发送巡检报告时使用。
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Webhooks. It works with GitHub. The repository describes itself as: 一套经过生产验证的 OpenClaw + Claude Code 实战知识库:涵盖生产部署、IM 接入、模型配置、安全加固,以及一系列可落地的 AI Agent 业务流项目(小红书发布 / 财务票据 / 智能早报 / CRM / 量化投研 / 密钥巡检自愈)。 The licence is MIT.
12 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit c8bc8f1. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
GitHub Secret Auditor loads about 2.8k tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 716 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- 如果发现 `.gitignore` 缺少会导致同类泄露的忽略规则,才补充 `.env`、本地密钥文件、私钥文件或项目特定敏感配置的忽略规则。- 不读取 `.env`、真实环境配置、SSH Key、私钥、Cookie、生产配置和用户个人目录;`.env.example`、示例配置和公开模板可读取/创建/更新,但不得包含真实密钥。- 如果发现本地密钥、私钥、`.env`、生产配置或项目特定敏感文件有再次误提交风险,`.gitignore` 或同类忽略规则必须补齐。Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from DjangoPeng/agentic-ai at commit c8bc8f1, republished under its MIT licence (© DjangoPeng). 716 words, ~2,805 tokens.
.claude/skills/github-secret-auditor/SKILL.md (or your agent's skills folder).本 Skill 用于让 OpenClaw 通过 ACP 调度 Claude Code,对授权 GitHub 仓库执行密钥泄露巡检、安全修复、验收、推送修复 commit,并通过飞书发送巡检报告。
核心原则:
git commit、git push、创建 PR 或其他发布动作。commit 与 push 只能由 OpenClaw 在验收通过后执行。当用户提出以下需求时使用本 Skill:
.env.example、.gitignore、README 或同类配置说明文件。给 OpenClaw/龙虾的一句话启动模板见 templates/run_skill_prompt.md。
用户只需提供目标 GitHub 仓库,OpenClaw 必须自动按默认任务流完成巡检、修复、验收、commit、push 和飞书报告。不要要求用户手动复制 session、手动执行 ACP 命令、手动拼接 prompt 或手动验收。
最小用户入口示例:
请使用 github-secret-auditor Skill 全自动巡检并修复 https://github.com/DjangoPeng/agentic-ai.gitOpenClaw 必须先读取本 SKILL.md,再执行默认任务流。后台自动化默认使用 OpenClaw Sessions API:
sessions_spawn(runtime="acp", agentId="claude", mode="run", thread=false, cwd=<repo_path>, prompt=<task_prompt>)
sessions_send(sessionKey=<childSessionKey>, prompt=<contextual_followup_prompt>)飞书交互演示可使用 /acp ... slash command;后台自动化不要依赖聊天命令,也不要把 /acp ... 当 shell 命令执行。
除非任务失败或用户明确要求调试细节,最终回复只展示巡检结果、修复结果、commit、push 状态、风险摘要和风险备注;不要把 sessions_spawn、sessions_send 参数作为用户需要操作的步骤暴露出来。
当用户只提供 repo_url 或说“巡检这个仓库”时,OpenClaw 不要反问执行细节,直接使用以下默认值:
{
"branch": "main",
"mode": "audit_fix_push_report",
"allow_auto_fix": true,
"allow_push": true,
"runner": "acp_sessions",
"repo_path": "/srv/openclaw-runner/repos/<repo-name>"
}只有缺少仓库授权、ACP runtime 不可用、GitHub 权限不足、工作区存在未提交修改或安全边界不明确时,才返回 failed 并说明阻塞原因。
用户面向的完成标准是看到飞书巡检报告和最终结果;OpenClaw 内部负责完整执行以下动作:
读取 Skill -> 准备仓库 -> 生成任务包 -> sessions_spawn 调度 Claude Code -> 等待输出 -> 必要时 sessions_send 补漏 -> 验收 Diff -> commit -> push -> 飞书报告OpenClaw 必须通过 ACP 调用 Claude Code。后台自动化与飞书交互演示使用不同入口,但底层都应调度 ACP runtime 的 Claude agent。
后台任务、Heartbeat 或定时任务默认使用 OpenClaw Sessions API,不使用 /acp ... 聊天命令:
sessions_spawn({
runtime: "acp",
agentId: "claude",
mode: "run",
thread: false,
cwd: "/srv/openclaw-runner/repos/agentic-ai",
prompt: "<完整巡检修复任务 prompt>"
})任务 prompt 要命令式、强制用工具。 遇到较弱或经中转的非 Claude 模型(如火山
ark-code-latest),一大段开放式任务容易被"只输出计划就判定完成"。prompt 要写成"现在立刻用 Read/Grep/Edit 动手做,不要只回计划",并把步骤拆明确(找 → 读 → 改 → 复核 → diff)。
sessions_spawn 成功后应返回:
{
"status": "accepted",
"childSessionKey": "agent:claude:acp:...",
"mode": "run"
}OpenClaw 必须保存 childSessionKey,并把它作为后续轮次的 sessionKey。
如果需要多轮补漏,使用:
sessions_send({
sessionKey: "<childSessionKey>",
prompt: "<显式包含上一轮输出、当前 git diff、验收缺失项的 follow-up prompt>"
})注意:sessions_send 可以把消息继续投递到同一个 childSessionKey,但不要假设 Claude Code 会自动记住上一轮上下文。OpenClaw 必须在每一轮 prompt 中显式带上必要上下文,例如上一轮输出、Git Diff、验收缺失项和本轮目标。
后台多轮能力依赖以下配置:
openclaw config set tools.sessions.visibility all
openclaw config set tools.agentToAgent.enabled true如果 sessions_send 返回 visibility 或 agent-to-agent forbidden,说明上述配置未生效或 gateway 需要重启。
/acp doctor、/acp spawn、/acp steer 是 OpenClaw/飞书对话框 slash command,不是服务器 shell 命令,不能在 bash、zsh、PowerShell 或 SSH 终端里执行。
在飞书/OpenClaw 对话框中,按顺序发送以下聊天消息:
/acp doctor如果返回 healthy: yes,继续在同一个对话框中发送以下聊天消息,创建 Claude Code 会话:
/acp spawn claude --mode persistent --thread on --cwd /srv/openclaw-runner/repos/agentic-ai返回示例:
Spawned ACP session agent:claude:acp:258c3125-77df-42ab-90e6-207af58ceef6OpenClaw 必须记录完整 session-key:
agent:claude:acp:258c3125-77df-42ab-90e6-207af58ceef6然后继续在对话框中发送以下聊天消息,投递任务:
/acp steer --session <session-key> 读取 /srv/openclaw-runner/tasks/agentic-ai-secret-audit.json,并严格按照 /root/projects/agentic-ai/github-secret-auditor/templates/acp_steer_prompt.md 执行。如果验收发现缺失项,继续使用同一个 session-key 追加 steer:
/acp steer --session <session-key> 上一轮输出如下:<上一轮输出>。当前 git diff 如下:<git diff>。OpenClaw 验收缺失项如下:<具体缺失项>。请只修复这些缺失项,完成后重新输出修改文件清单、风险摘要、测试/静态检查结果和 git diff 摘要。OpenClaw 应把 session 信息保存到当前任务状态:
{
"runner": "acp",
"agent": "claude",
"session_key": "agent:claude:acp:258c3125-77df-42ab-90e6-207af58ceef6",
"repo_path": "/srv/openclaw-runner/repos/agentic-ai",
"task_path": "/srv/openclaw-runner/tasks/agentic-ai-secret-audit.json"
}后台自动化中,session_key 来自 sessions_spawn 的 childSessionKey。如果任务重试且 session 仍可用,优先复用现有 session_key 并通过 sessions_send 继续投递;如果 session 丢失或不可解析,重新 sessions_spawn。
使用本 Skill 前,OpenClaw 应确认:
sessions_spawn(runtime="acp", agentId="claude", mode="run", thread=false, ...)。tools.sessions.visibility=all 且 tools.agentToAgent.enabled=true。configuredBackend 和 registeredBackend 均为 acpx。sessions_spawn 能返回 childSessionKey: agent:claude:acp:...。403,巡检 + 修复 + 本地 commit + 报告仍完成、报告标 pushed: no。/srv/openclaw-runner。如果 ACP runtime 不可用或无法创建 Claude Code child session,会话状态为 failed,并返回具体阻塞原因。不要改用 OpenClaw 自己手工巡检。
用户至少应提供:
repo_url:GitHub 仓库地址,例如 https://github.com/DjangoPeng/agentic-ai.git。branch:目标分支,默认 main。mode:默认 audit_fix_push_report。如果用户未提供 repo_path,默认使用:
/srv/openclaw-runner/repos/<repo-name>默认策略:
{
"allow_auto_fix": true,
"allow_push": true,
"push_strategy": "commit_to_current_branch",
"runner": "acp"
}任务完成后,OpenClaw 应返回:
{
"status": "passed | failed",
"repo": "DjangoPeng/agentic-ai",
"runner": "acp",
"session_key": "agent:claude:acp:...",
"report_path": "/srv/openclaw-runner/reports/agentic-ai-security-report.md",
"changed_files": [],
"risk_summary": "",
"completed_fixes": [],
"residual_risks": [],
"risk_notes": [],
"pushed": false,
"commit": "",
"notified": false,
"next_action": ""
}状态含义:
passed:Claude Code 已完成代码修复,OpenClaw 验收通过,并已按配置完成 commit、push 和飞书报告。failed:ACP 调度失败、仓库不可访问、Claude Code 未完成任务、验收不通过或 push 失败。Git 历史泄露、疑似外部凭证风险或无法自动判定的凭证归属,不改变本 Skill 的自动化完成状态;这些内容写入飞书报告的 risk_notes。
repo_url、repo_path、branch、mode、allow_auto_fix、allow_push。/srv/openclaw-runner/repos、/srv/openclaw-runner/tasks、/srv/openclaw-runner/reports。repo_path。git status --short;如有未提交修改,停止并报告 failed,避免覆盖用户工作。git pull --ff-only。templates/openclaw_task.secret_audit.json 生成任务包到 /srv/openclaw-runner/tasks/<repo>-secret-audit.json。sessions_spawn(runtime="acp", agentId="claude", mode="run", thread=false, cwd=<repo_path>, prompt=<完整任务 prompt>) 创建并启动 Claude Code child session。childSessionKey,格式为 agent:claude:acp:...。git status --short、git diff 和验收结果。sessions_send(sessionKey=<childSessionKey>, prompt=<显式上下文 follow-up prompt>) 定向补漏。follow-up prompt 必须包含上一轮输出、当前 Git Diff、验收缺失项和本轮目标。git commit,OpenClaw 不立即 push;先核实该 commit 的修改范围、diff、是否包含禁止文件、是否满足验收标准。只有核实通过后,才允许继续 push;如未通过,则要求 Claude Code 回到未提交状态或重新修复。git add、git commit、git push。如本地已存在且通过验收的修复 commit,OpenClaw 可以直接复用该 commit 执行 push,并在报告中注明“Claude 已先本地 commit,OpenClaw 已验收后推送”。第一轮 <完整任务 prompt> 应包含:任务包路径、templates/acp_steer_prompt.md 的任务要求、目标仓库路径、禁止读取范围、输出格式要求,以及显式的 Git 边界:不要执行 git commit / git push / PR 创建;只做巡检、修改和本地验证。不要只发送一句“去巡检”,也不要把修复限定成固定文件模板。
OpenClaw 负责:
sessions_spawn 创建 Claude Code ACP child session。sessions_send 多轮投递显式上下文,让 Claude Code 完成巡检、修复和补漏。git commit / git push / PR 创建;这些动作保留给 OpenClaw。/srv/openclaw-runner/reports。Claude Code 负责:
repo_path 内工作。.env.example、README 或项目已有配置说明;内容只能包含占位符和配置说明。.gitignore 缺少会导致同类泄露的忽略规则,才补充 .env、本地密钥文件、私钥文件或项目特定敏感配置的忽略规则。git commit、不 push、不创建 PR、不输出完整密钥。.env、真实环境配置、SSH Key、私钥、Cookie、生产配置和用户个人目录;.env.example、示例配置和公开模板可读取/创建/更新,但不得包含真实密钥。sk-...abcd。security-report.md 作为仓库文件提交。git commit 或 push;commit/push 只由 OpenClaw 在验收后执行。如果发现疑似真实密钥已进入 Git 历史:
passed。risk_notes 必须记录风险类型、疑似文件、脱敏片段和建议动作。OpenClaw 必须检查:
security-report.md。.env.example、README 或项目已有配置说明必须包含必要占位符/说明,且不包含真实密钥。.env、生产配置或项目特定敏感文件有再次误提交风险,.gitignore 或同类忽略规则必须补齐。risk_notes。验收通过后,OpenClaw 可执行:
cd /srv/openclaw-runner/repos/agentic-ai
git status --short
git add <authorized_changed_files>
git commit -m "fix: remediate leaked secret configuration"
git push origin HEAD实际 git add 文件清单应以 Git Diff 中的授权修复文件为准,不要添加报告文件或禁止文件。
飞书报告必须包含:
passed 或 failed。risk_notes。OpenClaw 任务状态必须记录 ACP session-key;用户面向的飞书报告默认不展示 session-key,除非任务失败、排查调度问题,或用户明确要求调试细节。
报告可归档到:
/srv/openclaw-runner/reports/agentic-ai-security-report.md归档报告不得提交到 GitHub 仓库。
如果后台 sessions_spawn 失败:
runtime 是否为 acp、agentId 是否为 claude、mode 是否为 run、thread 是否为 false。thread_required,通常说明误用了 mode=session;按本 Skill 改回 mode=run、thread=false。如果后台 sessions_send 无法发送 follow-up:
agent:claude:acp:...。tools.sessions.visibility 是否为 all。tools.agentToAgent.enabled 是否为 true。sessions_spawn 并在 prompt 中带上 OpenClaw 保存的上下文。如果 Claude Code 报权限不足:
--cwd 是否指向目标仓库。repo_path。© DjangoPeng, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in github-secret-auditor/skills/github-secret-auditor of DjangoPeng/agentic-ai.
Open the folder on GitHubat commit c8bc8f1
GitHub Secret Auditor next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| GitHub Secret Auditor this skillDjangoPeng/agentic-ai | 152 | — | ~2.8k | Automated safety check: Notes | MIT | |
| Compliance ScanAojdevStudio/Finance-Guru | 322 | — | ~2.6k | Automated safety check: Notes | Custom licence | |
| GitHub OAuth Nango IntegrationAgentWorkforce/relay | 866 | 1 repos | ~3.4k | Automated safety check: Pass | Apache-2.0 | |
| Frontmcp Channelsagentfront/frontmcp | 146 | — | ~3.7k | Automated safety check: Pass | Apache-2.0 | |
| Add OAuth Integrationrome-os/rome | 725 | — | ~3.6k | Automated safety check: Pass | MIT | |
| Chat SDK Botslobehub/lobehub | 83k | — | ~1.5k | Automated safety check: Pass | Custom licence |
AojdevStudio/Finance-Guru
Privacy and security compliance scanner for the Finance Guru repo.
AgentWorkforce/relay
A skill your agent uses when implementing GitHub OAuth + GitHub App authentication with Nango - provides two-connection pattern for user login and repo access with webhook handling
agentfront/frontmcp
A skill your agent uses when pushing real-time notifications or events into Claude Code (or another MCP client) sessions, or building two-way chat bridges.
rome-os/rome
Add a new Rome-managed OAuth integration for a third-party service so a user can delegate access by clicking Connect, and Rome can act on the service with the delegated token (the GitHub/Slack model…
lobehub/lobehub
Builds chat bots once for Slack, Teams, Google Chat, Discord, GitHub and Linear with the Chat SDK, covering event handlers, cards, modals, streaming and state adapters.
asheshgoplani/agent-deck
Guide for creating agent-deck watchers conversationally. An agent skill from asheshgoplani/agent-deck.
DjangoPeng/agentic-ai
当用户希望生成 AI 早报、运行晨报链路、查看今日资讯摘要,或消息中包含”早报””晨报””今日资讯””新闻摘要”等关键词时触发。
DjangoPeng/agentic-ai
面向云服务器的小红书图文自动发布 Skill。适用于需要在 Linux 云服务器上,通过 Playwright/CDP、二维码人工接管、登录缓存、龙虾代发飞书群图片消息、截图留痕与审计日志来完成小红书草稿或发布流程的场景。
DjangoPeng/agentic-ai
将销售会议 transcript、飞书会议原始 JSON、飞书云文档正文或 Word/DOCX 会议纪要,转换成 CRM 结构化结果,并按客户信息表 + 商机推进快照表两表模型生成/同步飞书多维表格记录时使用。适用于多轮客户推进、客户画像增量更新、商机阶段判断、Lead Score 计算,以及“弱值不覆盖旧值、沟通风格/风险顾虑合并”的客户字段更新规则。
DjangoPeng/agentic-ai
当用户上传 PDF、JPG、JPEG、PNG 附件,或消息中包含"报销""发票""票据""录入""火车票""机票"等关键词时触发。对附件内容进行识别,若确认为报销票据则提取结构化字段并写入飞书多维表格;若识别后内容不是报销票据,告知用户并终止流程。
Works with
Categories
当用户希望让 OpenClaw 通过 ACP 调度 Claude Code,对 GitHub 仓库进行 API Key、Token、密码、私钥、Webhook URL 等敏感信息泄露巡检、自动修复、验收、推送修复 commit,并通过飞书发送巡检报告时使用。. GitHub Secret Auditor is an agent skill from DjangoPeng/agentic-ai.
GitHub Secret Auditor fits situations like: tasks that involve Webhooks.
Run `npx skills add DjangoPeng/agentic-ai --skill github-secret-auditor -a claude-code`. Or copy the skill folder (github-secret-auditor/skills/github-secret-auditor in DjangoPeng/agentic-ai) into .claude/skills/github-secret-auditor in your project. Claude Code loads it when a task matches its description.
Run `npx skills add DjangoPeng/agentic-ai --skill github-secret-auditor -a codex`. Or copy the skill folder (github-secret-auditor/skills/github-secret-auditor in DjangoPeng/agentic-ai) into .agents/skills/github-secret-auditor in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add DjangoPeng/agentic-ai --skill github-secret-auditor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-secret-auditor, .gemini/skills/github-secret-auditor, .github/skills/github-secret-auditor and .opencode/skills/github-secret-auditor in your project.
Going by SKILL.md and its folder, GitHub Secret Auditor needs the command-line tools its instructions call (git).
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
GitHub Secret Auditor is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with GitHub Secret Auditor: Compliance Scan (AojdevStudio/Finance-Guru, 322 stars), GitHub OAuth Nango Integration (AgentWorkforce/relay, 866 stars), Frontmcp Channels (agentfront/frontmcp, 146 stars) and Add OAuth Integration (rome-os/rome, 725 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
DjangoPeng (a GitHub user) maintains it in DjangoPeng/agentic-ai, which has 152 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on July 8, 2026.
Source: DjangoPeng/agentic-ai on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.