Git Gh Pat Auth
NEventStore/NEventStore
A skill your agent uses when: authenticating git and GitHub CLI for NEventStore tasks, fixing gh auth errors, setting PAT environment variables, preparing a shell session for git push and gh issue…
Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports.
$ npx skills add jamditis/claude-skills-journalism --skill private-secret-scanning -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jamditis/claude-skills-journalism private-secret-scanning --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jamditis/claude-skills-journalism.git skills-src && mkdir -p .claude/skills && cp -r skills-src/security-toolkit/skills/private-secret-scanning .claude/skills/private-secret-scanning && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "private-secret-scanning" agent skill from https://github.com/jamditis/claude-skills-journalism/tree/master/security-toolkit/skills/private-secret-scanning into .claude/skills/private-secret-scanning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "private-secret-scanning", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jamditis/claude-skills-journalism/tree/master/security-toolkit/skills/private-secret-scanningType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jamditis/claude-skills-journalism --skill private-secret-scanning -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jamditis/claude-skills-journalism private-secret-scanning --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jamditis/claude-skills-journalism.git skills-src && mkdir -p .agents/skills && cp -r skills-src/security-toolkit/skills/private-secret-scanning .agents/skills/private-secret-scanning && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "private-secret-scanning" agent skill from https://github.com/jamditis/claude-skills-journalism/tree/master/security-toolkit/skills/private-secret-scanning into .agents/skills/private-secret-scanning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "private-secret-scanning", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jamditis/claude-skills-journalism --skill private-secret-scanning -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jamditis/claude-skills-journalism private-secret-scanning --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jamditis/claude-skills-journalism.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/security-toolkit/skills/private-secret-scanning .cursor/skills/private-secret-scanning && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "private-secret-scanning" agent skill from https://github.com/jamditis/claude-skills-journalism/tree/master/security-toolkit/skills/private-secret-scanning into .cursor/skills/private-secret-scanning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "private-secret-scanning", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jamditis/claude-skills-journalism.git --path security-toolkit/skills/private-secret-scanning--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jamditis/claude-skills-journalism --skill private-secret-scanning -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jamditis/claude-skills-journalism private-secret-scanning --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jamditis/claude-skills-journalism.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/security-toolkit/skills/private-secret-scanning .gemini/skills/private-secret-scanning && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "private-secret-scanning" agent skill from https://github.com/jamditis/claude-skills-journalism/tree/master/security-toolkit/skills/private-secret-scanning into .gemini/skills/private-secret-scanning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "private-secret-scanning", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jamditis/claude-skills-journalism private-secret-scanningInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jamditis/claude-skills-journalism --skill private-secret-scanning -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jamditis/claude-skills-journalism.git skills-src && mkdir -p .github/skills && cp -r skills-src/security-toolkit/skills/private-secret-scanning .github/skills/private-secret-scanning && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "private-secret-scanning" agent skill from https://github.com/jamditis/claude-skills-journalism/tree/master/security-toolkit/skills/private-secret-scanning into .github/skills/private-secret-scanning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "private-secret-scanning", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jamditis/claude-skills-journalism --skill private-secret-scanning -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jamditis/claude-skills-journalism private-secret-scanning --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jamditis/claude-skills-journalism.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/security-toolkit/skills/private-secret-scanning .opencode/skills/private-secret-scanning && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "private-secret-scanning" agent skill from https://github.com/jamditis/claude-skills-journalism/tree/master/security-toolkit/skills/private-secret-scanning into .opencode/skills/private-secret-scanning/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "private-secret-scanning", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
private-secret-scanningLocal Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports.
Private Secret Scanning is an agent skill from jamditis/claude-skills-journalism. Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports. Use to block committed secrets without GitHub Secret Protection.
Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts (for example `agents/openai.yaml` and `scripts/secret-scan.sh`).
It sits in DevOps & Cloud, covering Secrets management. It works with GitHub and Git. The repository describes itself as: Claude Code skills for journalism, media, and academia - verification, FOIA, data journalism, academic writing, and more. The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit e3e2172. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
gitpython3From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Private Secret Scanning loads about 1.8k tokens when it runs. Until then it costs about 50 tokens; SKILL.md has 950 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from jamditis/claude-skills-journalism at commit e3e2172, republished under its MIT licence (© jamditis). 950 words, ~1,778 tokens.
.claude/skills/private-secret-scanning/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.GitHub push protection and secret scanning are free on public repositories. Private repositories need a paid GitHub Secret Protection license. This skill gives private and shared repositories a deterministic local replacement: a pinned Gitleaks binary, three scan scopes, and git hooks that stop a leak before it leaves the machine.
Everything runs through one script that ships with this skill: scripts/secret-scan.sh. It needs only Bash (3.2 or later, so the macOS default works), git, curl, and python3.
SCAN=path/to/private-secret-scanning/scripts/secret-scan.sh
"$SCAN" install # pinned Gitleaks 8.30.1, SHA-256 checked before install
"$SCAN" self-test # proves leaks fail and clean repos pass on this machine
cd your-repo
"$SCAN" history --report /tmp/secret-report.json # one-time audit of every commit
"$SCAN" install-hooks # pre-commit and pre-push protection from now on| Command | Scans | Use it |
|---|---|---|
staged | the staged diff only | pre-commit hook; fastest |
push [RANGE] | commits in RANGE, or the commits a git push is about to send (read from pre-push stdin). A new branch or tag is scanned through its full history | pre-push hook; catches commits made with --no-verify |
history | every commit reachable from any ref, including files deleted later | first adoption, and before a private repo goes public |
A secret that was committed and then deleted is still in history. Only history finds it, and only rotating the credential fixes it. Rewriting history does not undo a clone that already happened.
| Exit | Meaning |
|---|---|
| 0 | no leaks |
| 1 | leaks found; each is listed on stderr |
| 2 | scanner or configuration error |
The script fails closed. It exits 2, never 0, when:
SECRET_SCAN_CONFIG names a file that does not exist..gitleaks.toml, so 1 from Gitleaks is treated as an error..gitleaks.toml neither extends the built-in rules nor defines its own (see below)..gitleaks.toml or .gitleaksignore untracked or changed but not committed (staged is enough for staged).A hook that exits non-zero blocks the commit or push, so a broken scanner blocks work. It does not let a leak through.
Terminal output and --report files hold five fields per finding: RuleID, File, StartLine, Commit, and Fingerprint. They never hold the secret, the match, or the source line. Gitleaks runs with --redact, its raw report goes to a private temp file that is deleted on exit, and the script copies only those five fields out. The report is written with mode 0600.
The fingerprint (commit:file:rule:line) is enough to find and fix the leak. It is also the line you add to .gitleaksignore to accept a finding.
Adopting scanning on an old repo usually turns up findings you have already rotated. Record them instead of turning the scanner off:
Rotate every live credential first. Accepting a finding does not make it safe.
Run history --report /tmp/secret-report.json, then write its fingerprints to .gitleaksignore at the repo root:
python3 -c 'import json,sys; print("\n".join(f["Fingerprint"] for f in json.load(open(sys.argv[1]))))' \
/tmp/secret-report.json >> .gitleaksignoreCommit .gitleaksignore. Later scans report only new findings. Each line names one commit, file, rule, and line, so a new leak of the same secret in another commit still fails.
A .gitleaks.toml replaces the built-in rules unless it extends them. An allowlist-only file therefore turns every detector off, and the script refuses one. Start every config from this:
[extend]
useDefault = true
[allowlist]
description = "synthetic keys in test fixtures"
paths = ['''^tests/fixtures/''']Keep allowlists narrow. Allow a specific path and rule, such as a test fixture, instead of a whole directory or a broad regex. Never allowlist a rule wholesale because it is noisy. A config that silences a rule also silences the next real leak of that type. Review a .gitleaksignore or allowlist change the way you would review an access-control change.
The script picks up .gitleaks.toml and .gitleaksignore from the repo root automatically. Hooks use them only once they are committed (or staged, for staged). A local edit cannot quietly change what gets through. Set SECRET_SCAN_CONFIG to use a shared config from elsewhere; a relative path is resolved from where you run the script.
install-hooks writes pre-commit (runs staged) and pre-push (runs push) into the repository's hooks directory. It refuses to overwrite a hook it did not write; add a call to the script inside that hook instead. git commit --no-verify skips pre-commit, which is why pre-push scans the outgoing range again. A new branch is scanned through its full history, even if a remote-tracking ref says a remote already has those commits. Tracking refs can be stale: git remote set-url points a remote at a new URL, and the old refs stay. This matters when a branch moves from a private remote to a public one.
This skill is generic on purpose. Do not add repository inventories, fleet or host paths, credentials, or real findings to a public copy of it. Keep those in a private repository or local config. Reports belong outside the repository you scanned, or in a gitignored path.
Run the same script in CI for a second check that local --no-verify cannot skip:
- uses: actions/checkout@v6
with:
fetch-depth: 0 # history scans need every commit
- run: path/to/secret-scan.sh install
- run: path/to/secret-scan.sh historyRun this only on hosted runners, or on push events from trusted branches. Never run untrusted pull-request code on a self-hosted runner. A fork's PR can rewrite the scan script itself and then read whatever that runner can reach.
The script pins Gitleaks 8.30.1 and the SHA-256 of each platform build from the release's checksums.txt. To upgrade, change GITLEAKS_VERSION and all four hashes together, then run self-test. Set GITLEAKS_BIN to use a binary you installed another way. It must still report the pinned version.
© jamditis, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 2 other files (scripts) in security-toolkit/skills/private-secret-scanning of jamditis/claude-skills-journalism.
Open the folder on GitHubat commit e3e2172
Private Secret Scanning next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Private Secret Scanning this skilljamditis/claude-skills-journalism | 416 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Git Gh Pat AuthNEventStore/NEventStore | 1.6k | — | ~828 | Automated safety check: Pass | MIT | |
| GreptimeDB Release RunbookGreptimeTeam/greptimedb | 6.7k | — | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Datadog Data Source GeneratorDataDog/terraform-provider-datadog | 468 | — | ~2.7k | Automated safety check: Pass | MPL-2.0 | |
| Open-Source Release Readinesstrailofbits/skills | 7.5k | — | ~2.6k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Openclaw Secret Scanning Maintaineropenclaw/openclaw | 392k | — | ~2.5k | Automated safety check: Pass | MIT |
NEventStore/NEventStore
A skill your agent uses when: authenticating git and GitHub CLI for NEventStore tasks, fixing gh auth errors, setting PAT environment variables, preparing a shell session for git push and gh issue…
GreptimeTeam/greptimedb
Runbook for publishing a GreptimeDB version: pick the release branch, verify the Cargo version, then tag, create the GitHub release and open the docs note PR.
DataDog/terraform-provider-datadog
Generates a Datadog Terraform provider data source from an OpenAPI operation with tfgen and opens a review-ready GitHub PR with a risk scan and testing guide.
trailofbits/skills
Walks a repository through release readiness before it goes public: secrets audit, licensing, documentation, CI and language-specific packaging.
openclaw/openclaw
Triage, redact, clean up, and resolve OpenClaw GitHub Secret Scanning alerts in issues or PRs.
YaoApp/yao
Manages Git identity, HTTPS access tokens and SSH keys at the workspace level through three `tai tool` commands, each with a get, set, list, import or delete action.
jamditis/claude-skills-journalism
A skill your agent uses when creating distinct website directions, a client review picker, asset catalog, previews, and Cloudflare-ready handoffs.
jamditis/claude-skills-journalism
Builds an Open Knowledge Format (OKF) knowledge base from existing docs, notes, or a repo.
jamditis/claude-skills-journalism
Acquire, clean, analyze, verify, visualize, and explain data for journalism.
jamditis/claude-skills-journalism
Creates print-ready HTML that exports to PDF. An agent skill from jamditis/claude-skills-journalism.
jamditis/claude-skills-journalism
Establishes how to find and use skills, requiring Skill tool invocation before any response.
jamditis/claude-skills-journalism
Zero-build frontend development for static apps, browser extensions, maps, and lightweight data-backed interfaces.
Categories
Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports. Private Secret Scanning is an agent skill from jamditis/claude-skills-journalism. Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports.
Private Secret Scanning fits situations like: block committed secrets without GitHub Secret Protection; tasks that involve Secrets management.
Run `npx skills add jamditis/claude-skills-journalism --skill private-secret-scanning -a claude-code`. Or copy the skill folder (security-toolkit/skills/private-secret-scanning in jamditis/claude-skills-journalism) into .claude/skills/private-secret-scanning in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jamditis/claude-skills-journalism --skill private-secret-scanning -a codex`. Or copy the skill folder (security-toolkit/skills/private-secret-scanning in jamditis/claude-skills-journalism) into .agents/skills/private-secret-scanning in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jamditis/claude-skills-journalism --skill private-secret-scanning -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/private-secret-scanning, .gemini/skills/private-secret-scanning, .github/skills/private-secret-scanning and .opencode/skills/private-secret-scanning in your project.
Going by SKILL.md and its folder, Private Secret Scanning needs a shell for the scripts in its folder and the command-line tools its instructions call (git and python3). Our summary lists: Python 3; A Bash shell.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Private Secret Scanning is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Private Secret Scanning: Git Gh Pat Auth (NEventStore/NEventStore, 1.6k stars), GreptimeDB Release Runbook (GreptimeTeam/greptimedb, 6.7k stars), Datadog Data Source Generator (DataDog/terraform-provider-datadog, 468 stars) and Open-Source Release Readiness (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jamditis (a GitHub user) maintains it in jamditis/claude-skills-journalism, which has 416 GitHub stars. The repository holds 53 skills in this directory. The repository was last updated on October 4, 2026.
Source: jamditis/claude-skills-journalism on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.