A skill your agent uses when auditing a project for secrets committed to source control, setting up gitleaks, or hardening the "No secrets in source" harness constraint — covers scanning…

Custom licenceAuto-check: notesDevOps & Cloud

Install Secrets Detection

skills CLI
$ npx skills add Habitat-Thinking/ai-literacy-superpowers --skill secrets-detection -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Habitat-Thinking/ai-literacy-superpowers secrets-detection --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Habitat-Thinking/ai-literacy-superpowers.git skills-src && mkdir -p .claude/skills && cp -r skills-src/ai-literacy-superpowers/skills/secrets-detection .claude/skills/secrets-detection && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secrets-detection
GitHub stars
114
Token cost
~2.2k tokens
SKILL.md length
785 words
Files
1
Skills in repo
42
Repo updated
First seen
Licence
Custom licence

At a glance

A skill your agent uses when auditing a project for secrets committed to source control, setting up gitleaks, or hardening the "No secrets in source" harness constraint — covers scanning…

  • Works in 6 steps: Rotate the secret immediately — assume… → Remove from the current codebase —… → Remove from git history — use git… → …
  • Auditing a project for secrets committed to source control
  • SKILL.md covers Overview, Audit Checklist, Installation and Running the Audit, plus 6 more sections
  • Calls gitleaks, git and brew; reaches github.com; needs GITHUB_TOKEN and API_TOKEN

What it does

Secrets Detection is an agent skill from Habitat-Thinking/ai-literacy-superpowers. Use when auditing a project for secrets committed to source control, setting up gitleaks, or hardening the "No secrets in source" harness constraint — covers scanning, baselining, configuration, and CI integration

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in DevOps & Cloud, covering Secrets management and Git workflow. It works with Git. The repository describes itself as: A set of Claude Code and GitHub Copilot plugins providing the AI Literacy framework's complete development workflow — harness engineering, agent orchestration, literate….

When your agent uses it

  • Auditing a project for secrets committed to source control
  • Setting up gitleaks
  • Hardening the No secrets in source harness constraint — covers scanning

Example prompts

  • “No secrets in source”
  • “/secrets-detection”

Requirements

  • Docker
  • A credential in GITHUB_TOKEN
  • A credential in API_TOKEN

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Rotate the secret immediately — assume it has been compromised
  2. Remove from the current codebase — delete or replace with env var
  3. Remove from git history — use git filter-repo or BFG Repo Cleaner
  4. Add to .gitignore — prevent the file from being re-committed
  5. Add a baseline entry if the finding was a false positive
  6. Verify the fix — re-run gitleaks detect and confirm clean

What it can do on your machine

Read from SKILL.md and the folder at commit 9d35995. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gitleaks
    • git
    • brew
    • go
    • gh

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN
    • API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secrets Detection loads about 2.2k tokens when it runs. Until then it costs about 58 tokens; SKILL.md has 785 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~58
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:230
    | `.env.production` | AWS access key ID detected | Critical | Rotate key, remove file, add to `.gitignore` |
  • NoteMentions a .env fileSKILL.md:262
    bfg --delete-files .env.production
  • NoteMentions a .env fileSKILL.md:266
    git filter-repo --invert-of --path .env.production

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Its licence (Custom licence) doesn't allow us to republish the file, so here is its outline and opening line. It has 785 words (~2,216 tokens).

“Secrets in source code — API keys, tokens, passwords, private keys — are one of the most common and most damaging security failures. A single committed secret can grant an attacker access to production systems, and git history means the…”

— opening of SKILL.md by Habitat-Thinking, Custom licence
name
secrets-detection

Read the full SKILL.md on GitHub

Files

Just SKILL.md in ai-literacy-superpowers/skills/secrets-detection of Habitat-Thinking/ai-literacy-superpowers.

Open the folder on GitHubat commit 9d35995

Compare with similar skills

Secrets Detection next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secrets Detection compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secrets Detection this skillHabitat-Thinking/ai-literacy-superpowers114—~2.2kAutomated safety check: NotesCustom licence
Secrets GitleaksAgentSecOps/SecOpsAgentKit2202 repos~4.1kAutomated safety check: PassCustom licence
Leaked Secretsthedaviddias/Front-End-Checklist74k—~596Automated safety check: NotesMIT
Repo Auditzebbern/claude-code-guide4.7k—~831Automated safety check: PassMIT
Git Gh Pat AuthNEventStore/NEventStore1.6k—~828Automated safety check: PassMIT
Vibe CI Supply Chainmistralai/mistral-vibe5.1k—~1kAutomated safety check: PassApache-2.0

Similar skills

  • Secrets Gitleaks

    AgentSecOps/SecOpsAgentKit

    Hardcoded secret detection and prevention in git repositories and codebases using Gitleaks.

    220 GitHub starsUsed in 2 repos~4.1k tokens
    DevOps & CloudAuto-check passed
  • Leaked Secrets

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing client-side JavaScript, HTML source, or git history for exposed credentials, API keys, or tokens.

    74k GitHub stars~596 tokensUpdated 2 days ago
    DevOps & CloudAuto-check: notes
  • Repo Audit

    zebbern/claude-code-guide

    Deep analysis of Git history: identify frequently changed hotspot files, analyze code ownership by contributor, and scan for leaked secrets.

    4.7k GitHub stars~831 tokensUpdated today
    DevelopmentAuto-check passed
  • Git Gh Pat Auth

    NEventStore/NEventStore

    A skill your agent uses when: authenticating git and GitHub CLI for NEventStore tasks, fixing gh auth errors, setting PAT environment variables, preparing a shell session for git push and gh issue…

    1.6k GitHub stars~828 tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Vibe CI Supply Chain

    mistralai/mistral-vibe

    Official

    Git workflow, CI/GitHub Actions, and supply-chain pinning rules for Mistral Vibe.

    5.1k GitHub stars~1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed

More from Habitat-Thinking/ai-literacy-superpowers

All 42 skills in this repo
  • Advocatus Diaboli

    Habitat-Thinking/ai-literacy-superpowers

    A skill your agent uses when acting as the adversarial spec reviewer — raises steel-manned objections across six categories before plan approval, requires evidence per objection, and discloses what…

    114 GitHub stars~4.2k tokensUpdated 18 days ago
    Auto-check passed
  • AI Literacy Assessment

    Habitat-Thinking/ai-literacy-superpowers

    This skill should be used when the user asks to "assess AI literacy", "run an assessment", "check literacy level", "evaluate our AI collaboration", "where are we on the framework", or wants to…

    114 GitHub stars~3.7k tokensUpdated 18 days ago
    Auto-check passed
  • Carpaccio

    Habitat-Thinking/ai-literacy-superpowers

    A skill your agent uses when acting as the cadence governor — slices a raw task description into thin, end-to-end-complete pieces before any spec is written; produces a structured slicing record for…

    114 GitHub stars~1.8k tokensUpdated 18 days ago
    Auto-check passed
  • Choice Cartographer

    Habitat-Thinking/ai-literacy-superpowers

    A skill your agent uses when acting as the decision-archaeology agent — surfaces decisions a spec has made (including the silent ones), emits each material choice as a Henney-style pattern story for…

    114 GitHub stars~4.1k tokensUpdated 18 days ago
    Auto-check passed
  • Constraint Design

    Habitat-Thinking/ai-literacy-superpowers

    This skill should be used when the user asks to "add a constraint", "design a constraint", "write a harness rule", "choose enforcement type", "promote a constraint", "configure a verification slot"…

    114 GitHub stars~1.8k tokensUpdated 18 days ago
    Auto-check passed
  • Cost Tracking

    Habitat-Thinking/ai-literacy-superpowers

    A skill your agent uses when the user wants to capture AI tool costs, review spending trends, set cost budgets, or integrate cost data into health snapshots — guides quarterly cost capture, records…

    114 GitHub stars~1.7k tokensUpdated 18 days ago
    Auto-check passed

Works with

Questions about Secrets Detection

What does Secrets Detection do?

A skill your agent uses when auditing a project for secrets committed to source control, setting up gitleaks, or hardening the "No secrets in source" harness constraint — covers scanning…. Secrets Detection is an agent skill from Habitat-Thinking/ai-literacy-superpowers.

When should I use Secrets Detection?

Secrets Detection fits situations like: auditing a project for secrets committed to source control; setting up gitleaks; hardening the No secrets in source harness constraint — covers scanning.

How do I install Secrets Detection in Claude Code?

Run `npx skills add Habitat-Thinking/ai-literacy-superpowers --skill secrets-detection -a claude-code`. Or copy the skill folder (ai-literacy-superpowers/skills/secrets-detection in Habitat-Thinking/ai-literacy-superpowers) into .claude/skills/secrets-detection in your project. Claude Code loads it when a task matches its description.

How do I install Secrets Detection in Codex?

Run `npx skills add Habitat-Thinking/ai-literacy-superpowers --skill secrets-detection -a codex`. Or copy the skill folder (ai-literacy-superpowers/skills/secrets-detection in Habitat-Thinking/ai-literacy-superpowers) into .agents/skills/secrets-detection in your project. Codex loads it when a task matches its description.

Can I use Secrets Detection in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Habitat-Thinking/ai-literacy-superpowers --skill secrets-detection -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secrets-detection, .gemini/skills/secrets-detection, .github/skills/secrets-detection and .opencode/skills/secrets-detection in your project.

What does Secrets Detection need to run?

Going by SKILL.md and its folder, Secrets Detection needs the command-line tools its instructions call (gitleaks, git, brew, go and gh) and credentials named GITHUB_TOKEN and API_TOKEN. Our summary lists: Docker; A credential in GITHUB_TOKEN; A credential in API_TOKEN.

Does Secrets Detection access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Secrets Detection safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Secrets Detection use?

Secrets Detection has a licence file (the repository's licence) that doesn't match a standard licence. Read it on GitHub before reusing the skill.

How many tokens does Secrets Detection use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Secrets Detection?

Skills that share tags, products or a category with Secrets Detection: Secrets Gitleaks (AgentSecOps/SecOpsAgentKit, 220 stars), Leaked Secrets (thedaviddias/Front-End-Checklist, 74k stars), Repo Audit (zebbern/claude-code-guide, 4.7k stars) and Git Gh Pat Auth (NEventStore/NEventStore, 1.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secrets Detection?

Habitat-Thinking (a GitHub organization) maintains it in Habitat-Thinking/ai-literacy-superpowers, which has 114 GitHub stars. The repository holds 42 skills in this directory. The repository was last updated on September 20, 2026.

Source: Habitat-Thinking/ai-literacy-superpowers on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.