Official agent skill

Secret Scanning

by github in github/awesome-copilot

Guide for configuring and managing GitHub secret scanning, push protection, custom patterns, and secret alert remediation.

OfficialMITAuto-check passedDevOps & Cloud

Install Secret Scanning

skills CLI
$ npx skills add github/awesome-copilot --skill secret-scanning -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install github/awesome-copilot secret-scanning --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/github/awesome-copilot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/secret-scanning .claude/skills/secret-scanning && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secret-scanning
GitHub stars
40k
Used in
1 other repo
Token cost
~2.4k tokens
SKILL.md length
1,056 words
Files
4 (incl. references)
Skills in repo
417
Repo updated
First seen
Licence
MIT

At a glance

Guide for configuring and managing GitHub secret scanning, push protection, custom patterns, and secret alert remediation.

  • Works in 4 steps: Enable Secret Protection → Enable Push Protection → Configure Exclusions (Optional) → …
  • Enabling secret scanning
  • SKILL.md covers When to Use This Skill, How Secret Scanning Works, Core Workflow — Enable Secret… and Core Workflow — Resolve…, plus 4 more sections
  • Calls git

What it does

Secret Scanning is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Guide for configuring and managing GitHub secret scanning, push protection, custom patterns, and secret alert remediation. For pre-commit secret scanning in AI coding agents via the GitHub MCP Server, this skill references the Advanced Security plugin (advanced-security@copilot-plugins). Use this skill when enabling secret scanning, setting up push protection, defining custom patterns, triaging alerts, resolving blocked pushes, or when an agent needs to scan code for secrets before committing.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/alerts-and-remediation.md`, `references/custom-patterns.md` and `references/push-protection.md`).

It sits in DevOps & Cloud, covering Secrets management. It works with GitHub and Model Context Protocol. The repository describes itself as: Community-contributed instructions, agents, skills, and configurations to help you make the most of GitHub Copilot. The licence is MIT.

When your agent uses it

  • Enabling secret scanning
  • Setting up push protection
  • Defining custom patterns
  • Triaging alerts

Example prompts

  • “/secret-scanning”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Enable Secret Protection
  2. Enable Push Protection
  3. Configure Exclusions (Optional)
  4. Enable Additional Features (Optional)

What it can do on your machine

Read from SKILL.md and the folder at commit 727ff2e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • github.blog

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secret Scanning loads about 2.4k tokens when it runs, and up to ~7.2k if it reads all its reference files. Until then it costs about 129 tokens; SKILL.md has 1,056 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~129
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~7.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from github/awesome-copilot at commit 727ff2e, republished under its MIT licence (© github). 1,056 words, ~2,387 tokens.

Download SKILL.mdSave it as .claude/skills/secret-scanning/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
secret-scanning
description
Guide for configuring and managing GitHub secret scanning, push protection, custom patterns, and secret alert remediation. For pre-commit secret scanning in AI coding agents via the GitHub MCP Server, this skill references the Advanced Security plugin (`advanced-security@copilot-plugins`). Use this skill when enabling secret scanning, setting up push protection, defining custom patterns, triaging alerts, resolving blocked pushes, or when an agent needs to scan code for secrets before committing.

Secret Scanning

This skill provides procedural guidance for configuring GitHub secret scanning — detecting leaked credentials, preventing secret pushes, defining custom patterns, and managing alerts.

When to Use This Skill

Use this skill when the request involves:

  • Enabling or configuring secret scanning for a repository or organization
  • Setting up push protection to block secrets before they reach the repository
  • Defining custom secret patterns with regular expressions
  • Resolving a blocked push from the command line
  • Triaging, dismissing, or remediating secret scanning alerts
  • Configuring delegated bypass for push protection
  • Excluding directories from secret scanning via secret_scanning.yml
  • Understanding alert types (user, partner, push protection)
  • Enabling validity checks or extended metadata checks
  • Scanning local code changes for secrets before committing (via MCP / AI coding agent) — see the Pre-Commit Scanning via AI Coding Agents section below for the recommended plugin

How Secret Scanning Works

Secret scanning automatically detects exposed credentials across:

  • Entire Git history on all branches
  • Issue descriptions, comments, and titles (open and closed)
  • Pull request titles, descriptions, and comments
  • GitHub Discussions titles, descriptions, and comments
  • Wikis and secret gists
Availability
Repository TypeAvailability
Public reposAutomatic, free
Private/internal (org-owned)Requires GitHub Secret Protection on Team/Enterprise Cloud
User-ownedEnterprise Cloud with Enterprise Managed Users

Core Workflow — Enable Secret Scanning

Step 1: Enable Secret Protection
  1. Navigate to repository Settings → Advanced Security
  2. Click Enable next to "Secret Protection"
  3. Confirm by clicking Enable Secret Protection

For organizations, use security configurations to enable at scale:

  • Settings → Advanced Security → Global settings → Security configurations
Step 2: Enable Push Protection

Push protection blocks secrets during the push process — before they reach the repository.

  1. Navigate to repository Settings → Advanced Security
  2. Enable "Push protection" under Secret Protection

Push protection blocks secrets in:

  • Command line pushes
  • GitHub UI commits
  • File uploads
  • REST API requests
  • REST API content creation endpoints
Step 3: Configure Exclusions (Optional)

Create .github/secret_scanning.yml to auto-close alerts for specific directories:

yaml
paths-ignore:
  - "docs/**"
  - "test/fixtures/**"
  - "**/*.example"

Limits:

  • Maximum 1,000 entries in paths-ignore
  • File must be under 1 MB
  • Excluded paths also skip push protection checks

Best practices:

  • Be as specific as possible with exclusion paths
  • Add comments explaining why each path is excluded
  • Review exclusions periodically — remove stale entries
  • Inform the security team about exclusions
Step 4: Enable Additional Features (Optional)

Non-provider patterns — detect private keys, connection strings, generic API keys:

  • Settings → Advanced Security → enable "Scan for non-provider patterns"

AI-powered generic secret detection — uses Copilot to detect unstructured secrets like passwords:

  • Settings → Advanced Security → enable "Use AI detection"

Validity checks — verify if detected secrets are still active:

  • Settings → Advanced Security → enable "Validity checks"
  • GitHub periodically tests detected credentials against provider APIs
  • Status shown in alert: active, inactive, or unknown

Extended metadata checks — additional context about who owns a secret:

  • Requires validity checks to be enabled first
  • Helps prioritize remediation and identify responsible teams

Core Workflow — Resolve Blocked Pushes

When push protection blocks a push from the command line:

Option A: Remove the Secret

If the secret is in the latest commit:

bash
# Remove the secret from the file
# Then amend the commit
git commit --amend --all
git push

If the secret is in an earlier commit:

bash
# Find the earliest commit containing the secret
git log

# Start interactive rebase before that commit
git rebase -i <COMMIT-ID>~1

# Change 'pick' to 'edit' for the offending commit
# Remove the secret, then:
git add .
git commit --amend
git rebase --continue
git push
Option B: Bypass Push Protection
  1. Visit the URL returned in the push error message (as the same user)
  2. Select a bypass reason:
    • It's used in tests — alert created and auto-closed
    • It's a false positive — alert created and auto-closed
    • I'll fix it later — open alert created
  3. Click Allow me to push this secret
  4. Re-push within 3 hours
Option C: Request Bypass Privileges

If delegated bypass is enabled and you lack bypass privileges:

  1. Visit the URL from the push error
  2. Add a comment explaining why the secret is safe
  3. Click Submit request
  4. Wait for email notification of approval/denial
  5. If approved, push the commit; if denied, remove the secret

For detailed bypass and delegated bypass workflows, search references/push-protection.md.

Custom Patterns

Define organization-specific secret patterns using regular expressions.

Show full SKILL.md (428 more words)Show less
Quick Setup
  1. Settings → Advanced Security → Custom patterns → New pattern
  2. Enter pattern name and regex for secret format
  3. Add a sample test string
  4. Click Save and dry run to test (up to 1,000 results)
  5. Review results for false positives
  6. Click Publish pattern
  7. Optionally enable push protection for the pattern
Scopes

Custom patterns can be defined at:

  • Repository level — applies to that repo only
  • Organization level — applies to all repos with secret scanning enabled
  • Enterprise level — applies across all organizations
Copilot-Assisted Pattern Generation

Use Copilot secret scanning to generate regex from a text description of the secret type, including optional example strings.

For detailed custom pattern configuration, search references/custom-patterns.md.

Alert Management

Alert Types
TypeDescriptionVisibility
User alertsSecrets found in repositorySecurity tab
Push protection alertsSecrets pushed via bypassSecurity tab (filter: bypassed: true)
Partner alertsSecrets reported to providerNot shown in repo (provider-only)
Alert Lists
  • Default alerts — supported provider patterns and custom patterns
  • Generic alerts — non-provider patterns and AI-detected secrets (limited to 5,000 per repo)
Remediation Priority
  1. Rotate the credential immediately — this is the critical action
  2. Review the alert for context (location, commit, author)
  3. Check validity status: active (urgent), inactive (lower priority), unknown
  4. Remove from Git history if needed (time-intensive, often unnecessary after rotation)
Dismissing Alerts

Dismiss with a documented reason:

  • False positive — detected string is not a real secret
  • Revoked — credential has already been revoked
  • Used in tests — secret is only in test code

For detailed alert types, validity checks, and REST API, search references/alerts-and-remediation.md.

Pre-Commit Scanning via AI Coding Agents

For scanning code changes for secrets inside an AI coding agent before committing, install the Advanced Security plugin which provides the run_secret_scanning MCP tool and a dedicated scanning skill.

GitHub Copilot CLI:

bash
/plugin install advanced-security@copilot-plugins

Visual Studio Code:

  • In Copilot Chat, open Chat: Plugins (or use @agentPlugins) and install the advanced-security plugin
  • Then run /secret-scanning in Copilot Chat

See: Advanced Security Plugin — Secret Scanning Skill

Announced in Secret scanning in AI coding agents via the GitHub MCP Server (March 2026)

Reference Files

For detailed documentation, load the following reference files as needed:

  • references/push-protection.md — Push protection mechanics, bypass workflow, delegated bypass, user push protection
    • Search patterns: bypass, delegated, bypass request, command line, REST API, user push protection
  • references/custom-patterns.md — Custom pattern creation, regex syntax, dry runs, Copilot regex generation, scopes
    • Search patterns: custom pattern, regex, dry run, publish, organization, enterprise, Copilot
  • references/alerts-and-remediation.md — Alert types, validity checks, extended metadata, generic alerts, secret removal, REST API
    • Search patterns: user alert, partner alert, validity, metadata, generic, remediation, git history, REST API

© github, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/secret-scanning of github/awesome-copilot.

  • SKILL.md
  • references/alerts-and-remediation.md
  • references/custom-patterns.md
  • references/push-protection.md

Open the folder on GitHubat commit 727ff2e

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in github/awesome-copilot, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Secret Scanning next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secret Scanning compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secret Scanning this skillgithub/awesome-copilot40k1 repos~2.4kAutomated safety check: PassMIT
Prepare Cloudflare Production DeploymentLubomirGeorgiev/cloudflare-workers-nextjs-saas-template786—~5.9kAutomated safety check: NotesMIT
Release Allpaperboytm/spool592—~1.1kAutomated safety check: PassCustom licence
Keypaste Designnotinferred/keypaste160—~865Automated safety check: PassAGPL-3.0
Secure GitHub Actionsvechain/x-app-template450—~1.2kAutomated safety check: PassMIT
Private Secret Scanningjamditis/claude-skills-journalism416—~1.8kAutomated safety check: PassMIT

Similar skills

  • Prepare Cloudflare Production Deployment

    LubomirGeorgiev/cloudflare-workers-nextjs-saas-template

    Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.

    786 GitHub stars~5.9k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Release All

    paperboytm/spool

    Publish the complete Spool CLI release train: synchronized versions, npm packages, the GitHub release, and the matching production web deployment.

    592 GitHub stars~1.1k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Keypaste Design

    notinferred/keypaste

    Keep keypaste's desktop screens, CLI output, site, README and brand assets on brand.

    160 GitHub stars~865 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Secure GitHub Actions

    vechain/x-app-template

    Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.

    450 GitHub stars~1.2k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Private Secret Scanning

    jamditis/claude-skills-journalism

    Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports.

    416 GitHub stars~1.8k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Deploy To Hosting

    hostinger/api-mcp-server

    Deploy an existing project to a website on Hostinger web hosting (Shared, Cloud or Agency plans) and keep it deployed: picks the right deploy for static sites, Node.js apps (Next.js, Nuxt, Express…

    159 GitHub stars~2.7k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes

More from github/awesome-copilot

All 417 skills in this repo
  • Acquire Codebase Knowledge

    github/awesome-copilot

    Official

    Maps an unfamiliar codebase into seven evidence-backed documents in docs/codebase/, using a scan script and templates, for onboarding or architecture write-ups.

    40k GitHub starsUsed in 1 repo~2.3k tokens
    Auto-check passed
  • Azure Architecture Autopilot

    github/awesome-copilot

    Official

    Designs Azure infrastructure from a natural-language description, or diagrams an existing resource group, then refines the design through conversation and deploys it with Bicep.

    40k GitHub starsUsed in 1 repo~1.9k tokens
    Auto-check passed
  • Draw.io Diagram Generator

    github/awesome-copilot

    Official

    Generates, edits and validates draw.io files with correct mxGraph XML, covering flowcharts, architecture, sequence, ER and UML class diagrams.

    40k GitHub starsUsed in 1 repo~4.9k tokens
    Auto-check passed
  • Credit Risk Data Cleaning

    github/awesome-copilot

    Official

    Cleans raw credit data and screens variables before loan modeling, dropping unstable, noisy or redundant features and writing an Excel report of every step.

    40k GitHub starsUsed in 1 repo~1.5k tokens
    Auto-check passed
  • Daily Focus Board

    github/awesome-copilot

    Official

    Builds a warm, browser-based daily focus board the user updates by talking to their agent, with Eisenhower priorities, a brain-dump box and kind not-today carryover.

    40k GitHub stars~3k tokensUpdated today
    Auto-check passed
  • Python Pypi Package Builder

    github/awesome-copilot

    Official

    End-to-end skill for building, testing, linting, versioning, and publishing a production-grade Python library to PyPI.

    40k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Categories

Questions about Secret Scanning

What does Secret Scanning do?

Guide for configuring and managing GitHub secret scanning, push protection, custom patterns, and secret alert remediation. Secret Scanning is an agent skill from github/awesome-copilot, published by the product's own GitHub organization. Guide for configuring and managing GitHub secret scanning, push protection, custom patterns, and secret alert remediation.

When should I use Secret Scanning?

Secret Scanning fits situations like: enabling secret scanning; setting up push protection; defining custom patterns; triaging alerts.

How do I install Secret Scanning in Claude Code?

Run `npx skills add github/awesome-copilot --skill secret-scanning -a claude-code`. Or copy the skill folder (skills/secret-scanning in github/awesome-copilot) into .claude/skills/secret-scanning in your project. Claude Code loads it when a task matches its description.

How do I install Secret Scanning in Codex?

Run `npx skills add github/awesome-copilot --skill secret-scanning -a codex`. Or copy the skill folder (skills/secret-scanning in github/awesome-copilot) into .agents/skills/secret-scanning in your project. Codex loads it when a task matches its description.

Can I use Secret Scanning in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add github/awesome-copilot --skill secret-scanning -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secret-scanning, .gemini/skills/secret-scanning, .github/skills/secret-scanning and .opencode/skills/secret-scanning in your project.

What does Secret Scanning need to run?

Going by SKILL.md and its folder, Secret Scanning needs the command-line tools its instructions call (git).

Does Secret Scanning access the network?

SKILL.md names 2 domains. As links in the text: github.com and github.blog. This is read from the text; nothing was executed.

Is Secret Scanning safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Secret Scanning use?

Secret Scanning is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Secret Scanning use?

About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.8k tokens, read only when the agent opens those files.

What are the alternatives to Secret Scanning?

Skills that share tags, products or a category with Secret Scanning: Prepare Cloudflare Production Deployment (LubomirGeorgiev/cloudflare-workers-nextjs-saas-template, 786 stars), Release All (paperboytm/spool, 592 stars), Keypaste Design (notinferred/keypaste, 160 stars) and Secure GitHub Actions (vechain/x-app-template, 450 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secret Scanning?

github (a GitHub organization, an official publisher) maintains it in github/awesome-copilot, which has 39,748 GitHub stars. The repository holds 417 skills in this directory. The repository was last updated on October 7, 2026.

Source: github/awesome-copilot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.