Agent skill

Secleak Check

by instructa in instructa/agent-skills

Run or install repo security leak checks with BetterLeaks and Trivy.

No licenceAuto-check passedAI & LLM Engineering

Install Secleak Check

skills CLI
$ npx skills add instructa/agent-skills --skill secleak-check -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install instructa/agent-skills secleak-check --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/instructa/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/security/secleak-check .claude/skills/secleak-check && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secleak-check
GitHub stars
139
Token cost
~557 tokens
SKILL.md length
226 words
Files
6 (incl. scripts, references)
Skills in repo
17
Repo updated
First seen
Licence
None found

At a glance

Run or install repo security leak checks with BetterLeaks and Trivy.

  • Works in 5 steps: Confirm cwd and repo root. → For a scan request, run the bundled… → For a setup request, add repo-local… → …
  • Asked to scan for leaked secrets
  • SKILL.md covers Workflow, Bundled command, Manual fallback and Reporting, plus 1 more section
  • Runs JavaScript and Shell scripts from its folder; calls trivy

What it does

Secleak Check is an agent skill from instructa/agent-skills. Run or install repo security leak checks with BetterLeaks and Trivy. Use when asked to scan for leaked secrets, vulnerable dependencies, misconfigurations, add secret-leak guardrails, add BetterLeaks, add forbidden-path hooks, or run secleak-check before release.

Its SKILL.md is about 560 tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including scripts and reference files (for example `README.md`, `references/examples.md` and `references/guardrails.md`).

It sits in AI & LLM Engineering, covering Secrets management, Vulnerability scanning and LLM guardrails. It works with Trivy. The repository describes itself as: A curated collection of agent-skills.

When your agent uses it

  • Asked to scan for leaked secrets
  • Vulnerable dependencies
  • Misconfigurations
  • Add secret-leak guardrails

Example prompts

  • “/secleak-check”

Requirements

  • Node.js
  • A Bash shell

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Confirm cwd and repo root.
  2. For a scan request, run the bundled script from this skill, not a target-repo script.
  3. For a setup request, add repo-local guardrails from references/guardrails.md.
  4. Quote exact failing tool output, but never print raw secret values.
  5. If the bundled script is unavailable, use the manual fallback commands below.

What it can do on your machine

Read from SKILL.md and the folder at commit d49c149. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (JavaScript and Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • trivy

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secleak Check loads about 557 tokens when it runs, and up to ~2.9k if it reads all its reference files. Until then it costs about 69 tokens; SKILL.md has 226 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~69
When it runs · the whole SKILL.md, loaded when a task matches
~557
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 226 words (~557 tokens).

“Resolve scripts/secleak-check.sh relative to this SKILL.md.”

— opening of SKILL.md by instructa
name
secleak-check

Read the full SKILL.md on GitHub

Files

SKILL.md and 5 other files (scripts, references) in skills/security/secleak-check of instructa/agent-skills.

  • SKILL.md
  • README.md
  • references/examples.md
  • references/guardrails.md
  • scripts/block-forbidden-staged-files.mjs
  • scripts/secleak-check.sh

Open the folder on GitHubat commit d49c149

Compare with similar skills

Secleak Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secleak Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secleak Check this skillinstructa/agent-skills139—~557Automated safety check: PassNone
Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.0
Dep Updatestrufflesecurity/trufflehog28k—~1.3kAutomated safety check: PassAGPL-3.0
Security ReviewerJeffallan/claude-skills12k—~1.3kAutomated safety check: PassMIT
Wa Guardrailsaws-samples/sample-well-architected-skills-and-steering273—~2.8kAutomated safety check: PassMIT-0
RAG Security Firstlyonzin/knowledge-rag290—~2.3kAutomated safety check: PassMIT

Similar skills

  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Dep Updates

    trufflesecurity/trufflehog

    Plan and apply Go dependency updates, including advisory-driven bumps, Trivy/govulncheck validation, and supply-chain review.

    28k GitHub stars~1.3k tokensUpdated today
    DevelopmentAuto-check passed
  • Security Reviewer

    Jeffallan/claude-skills

    Audits code and infrastructure for vulnerabilities and produces a severity-rated report with locations and remediation, using SAST, dependency and secrets scans plus manual review.

    12k GitHub stars~1.3k tokensUpdated 4 days ago
    SecurityAuto-check passed
  • Wa Guardrails

    aws-samples/sample-well-architected-skills-and-steering

    Official

    Generate preventive Well-Architected guardrails — AWS Config rules, Service Control Policies, permission boundaries, CloudWatch alarms, and IaC policy checks (CDK Aspects, cfn-guard, OPA/Sentinel) —…

    273 GitHub stars~2.8k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • RAG Security First

    lyonzin/knowledge-rag

    For any security-related task — threat triage, incident response, MITRE ATT&CK mapping, CVE lookup, exploit analysis, defensive control validation, red/blue/purple team work — always consult the…

    290 GitHub stars~2.3k tokensUpdated 3 days ago
    AI & LLM EngineeringAuto-check passed
  • Container Security

    hardw00t/ai-security-arsenal

    Container and Kubernetes security assessment — image vulnerability scanning, SBOM diff analysis, K8s cluster auditing, RBAC privilege mapping, NetworkPolicy review, container escape testing, and…

    104 GitHub stars~2.8k tokensUpdated 5 mo ago
    SecurityAuto-check passed

More from instructa/agent-skills

All 17 skills in this repo
  • App Spec Packager

    instructa/agent-skills

    A skill your agent uses when the user wants to turn an application, product, startup idea, SaaS, mobile app, web app, API, AI product, or internal tool into a production-ready Markdown specification…

    139 GitHub stars~1.5k tokensUpdated 9 days ago
    Auto-check passed
  • Codex Reviewer

    instructa/agent-skills

    Have Codex review a feature or change from Claude Code, then let Claude address the findings and request verification.

    139 GitHub stars~1.6k tokensUpdated 9 days ago
    Auto-check passed
  • Search Context

    instructa/agent-skills

    Find, clone, inspect, and summarize high-quality GitHub reference repositories for coding agents.

    139 GitHub stars~2.1k tokensUpdated 9 days ago
    Auto-check passed
  • Delegate Fable

    instructa/agent-skills

    Delegate a bounded task from a Codex session to a Fable-powered Cursor Agent in the same Herdr workspace, then wait for and collect the result.

    139 GitHub stars~925 tokensUpdated 9 days ago
    Auto-check passed
  • Delegate Grok

    instructa/agent-skills

    Delegate a bounded task from a Codex session to Grok 4.6 with xhigh reasoning in the same Herdr workspace, then wait for and collect the result.

    139 GitHub stars~951 tokensUpdated 9 days ago
    Auto-check passed
  • Delegate Sol

    instructa/agent-skills

    Delegate a bounded task from a Codex session to GPT-5.6 Sol in the same Herdr workspace, then wait for and collect the result.

    139 GitHub stars~1.2k tokensUpdated 9 days ago
    Auto-check passed

Works with

Questions about Secleak Check

What does Secleak Check do?

Run or install repo security leak checks with BetterLeaks and Trivy. Secleak Check is an agent skill from instructa/agent-skills. Run or install repo security leak checks with BetterLeaks and Trivy.

When should I use Secleak Check?

Secleak Check fits situations like: asked to scan for leaked secrets; vulnerable dependencies; misconfigurations; add secret-leak guardrails.

How do I install Secleak Check in Claude Code?

Run `npx skills add instructa/agent-skills --skill secleak-check -a claude-code`. Or copy the skill folder (skills/security/secleak-check in instructa/agent-skills) into .claude/skills/secleak-check in your project. Claude Code loads it when a task matches its description.

How do I install Secleak Check in Codex?

Run `npx skills add instructa/agent-skills --skill secleak-check -a codex`. Or copy the skill folder (skills/security/secleak-check in instructa/agent-skills) into .agents/skills/secleak-check in your project. Codex loads it when a task matches its description.

Can I use Secleak Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add instructa/agent-skills --skill secleak-check -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secleak-check, .gemini/skills/secleak-check, .github/skills/secleak-check and .opencode/skills/secleak-check in your project.

What does Secleak Check need to run?

Going by SKILL.md and its folder, Secleak Check needs JavaScript and a shell for the scripts in its folder and the command-line tools its instructions call (trivy). Our summary lists: Node.js; A Bash shell.

Does Secleak Check access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Secleak Check safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Secleak Check use?

No licence was found for Secleak Check or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Secleak Check use?

About 557 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.3k tokens, read only when the agent opens those files.

What are the alternatives to Secleak Check?

Skills that share tags, products or a category with Secleak Check: Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Dep Updates (trufflesecurity/trufflehog, 28k stars), Security Reviewer (Jeffallan/claude-skills, 12k stars) and Wa Guardrails (aws-samples/sample-well-architected-skills-and-steering, 273 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secleak Check?

instructa (a GitHub organization) maintains it in instructa/agent-skills, which has 139 GitHub stars. The repository holds 17 skills in this directory. The repository was last updated on September 28, 2026.

Source: instructa/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.