Agent skill

Private Secret Scanning

by jamditis in jamditis/claude-skills-journalism

Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports.

MITAuto-check passedDevOps & Cloud

Install Private Secret Scanning

skills CLI
$ npx skills add jamditis/claude-skills-journalism --skill private-secret-scanning -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jamditis/claude-skills-journalism private-secret-scanning --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jamditis/claude-skills-journalism.git skills-src && mkdir -p .claude/skills && cp -r skills-src/security-toolkit/skills/private-secret-scanning .claude/skills/private-secret-scanning && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
private-secret-scanning
GitHub stars
416
Token cost
~1.8k tokens
SKILL.md length
950 words
Files
3 (incl. scripts)
Skills in repo
53
Repo updated
First seen
Licence
MIT

At a glance

Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports.

  • Works in 3 steps: Rotate every live credential first.… → Run history --report… → Commit .gitleaksignore. Later scans…
  • Block committed secrets without GitHub Secret Protection
  • SKILL.md covers Quick start, Scan scopes, Exit codes and failure behavior and What reports contain, plus 5 more sections
  • Runs Shell scripts from its folder; calls git and python3

What it does

Private Secret Scanning is an agent skill from jamditis/claude-skills-journalism. Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports. Use to block committed secrets without GitHub Secret Protection.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts (for example `agents/openai.yaml` and `scripts/secret-scan.sh`).

It sits in DevOps & Cloud, covering Secrets management. It works with GitHub and Git. The repository describes itself as: Claude Code skills for journalism, media, and academia - verification, FOIA, data journalism, academic writing, and more. The licence is MIT.

When your agent uses it

  • Block committed secrets without GitHub Secret Protection
  • Tasks that involve Secrets management

Example prompts

  • “/private-secret-scanning”

Requirements

  • Python 3
  • A Bash shell

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Rotate every live credential first. Accepting a finding does not make it safe.
  2. Run history --report /tmp/secret-report.json, then write its fingerprints to .gitleaksignore at the repo root
  3. Commit .gitleaksignore. Later scans report only new findings. Each line names one commit, file, rule, and line, so a new leak of the same…

What it can do on your machine

Read from SKILL.md and the folder at commit e3e2172. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Private Secret Scanning loads about 1.8k tokens when it runs. Until then it costs about 50 tokens; SKILL.md has 950 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~50
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from jamditis/claude-skills-journalism at commit e3e2172, republished under its MIT licence (© jamditis). 950 words, ~1,778 tokens.

Download SKILL.mdSave it as .claude/skills/private-secret-scanning/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
private-secret-scanning
description
Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports. Use to block committed secrets without GitHub Secret Protection.

Private secret scanning

GitHub push protection and secret scanning are free on public repositories. Private repositories need a paid GitHub Secret Protection license. This skill gives private and shared repositories a deterministic local replacement: a pinned Gitleaks binary, three scan scopes, and git hooks that stop a leak before it leaves the machine.

Everything runs through one script that ships with this skill: scripts/secret-scan.sh. It needs only Bash (3.2 or later, so the macOS default works), git, curl, and python3.

Quick start

bash
SCAN=path/to/private-secret-scanning/scripts/secret-scan.sh

"$SCAN" install          # pinned Gitleaks 8.30.1, SHA-256 checked before install
"$SCAN" self-test        # proves leaks fail and clean repos pass on this machine
cd your-repo
"$SCAN" history --report /tmp/secret-report.json   # one-time audit of every commit
"$SCAN" install-hooks    # pre-commit and pre-push protection from now on

Scan scopes

CommandScansUse it
stagedthe staged diff onlypre-commit hook; fastest
push [RANGE]commits in RANGE, or the commits a git push is about to send (read from pre-push stdin). A new branch or tag is scanned through its full historypre-push hook; catches commits made with --no-verify
historyevery commit reachable from any ref, including files deleted laterfirst adoption, and before a private repo goes public

A secret that was committed and then deleted is still in history. Only history finds it, and only rotating the credential fixes it. Rewriting history does not undo a clone that already happened.

Exit codes and failure behavior

ExitMeaning
0no leaks
1leaks found; each is listed on stderr
2scanner or configuration error

The script fails closed. It exits 2, never 0, when:

  • Gitleaks is missing, cannot run, or is not the pinned version.
  • SECRET_SCAN_CONFIG names a file that does not exist.
  • Gitleaks exits with anything other than 0 or the script's own leak code. Gitleaks also exits 1 on fatal errors, such as a malformed .gitleaks.toml, so 1 from Gitleaks is treated as an error.
  • The Gitleaks exit code and its report disagree, or the report is not a list of findings.
  • A .gitleaks.toml neither extends the built-in rules nor defines its own (see below).
  • A hook scan finds .gitleaks.toml or .gitleaksignore untracked or changed but not committed (staged is enough for staged).
  • A push sends a ref that points at something other than a commit, such as a tag on a blob. Such a ref cannot be scanned as history.
  • The report cannot be read.

A hook that exits non-zero blocks the commit or push, so a broken scanner blocks work. It does not let a leak through.

What reports contain

Terminal output and --report files hold five fields per finding: RuleID, File, StartLine, Commit, and Fingerprint. They never hold the secret, the match, or the source line. Gitleaks runs with --redact, its raw report goes to a private temp file that is deleted on exit, and the script copies only those five fields out. The report is written with mode 0600.

The fingerprint (commit:file:rule:line) is enough to find and fix the leak. It is also the line you add to .gitleaksignore to accept a finding.

Show full SKILL.md (498 more words)Show less

Baselines and allowlists

Adopting scanning on an old repo usually turns up findings you have already rotated. Record them instead of turning the scanner off:

  1. Rotate every live credential first. Accepting a finding does not make it safe.

  2. Run history --report /tmp/secret-report.json, then write its fingerprints to .gitleaksignore at the repo root:

    bash
    python3 -c 'import json,sys; print("\n".join(f["Fingerprint"] for f in json.load(open(sys.argv[1]))))' \
      /tmp/secret-report.json >> .gitleaksignore
  3. Commit .gitleaksignore. Later scans report only new findings. Each line names one commit, file, rule, and line, so a new leak of the same secret in another commit still fails.

A .gitleaks.toml replaces the built-in rules unless it extends them. An allowlist-only file therefore turns every detector off, and the script refuses one. Start every config from this:

toml
[extend]
useDefault = true

[allowlist]
description = "synthetic keys in test fixtures"
paths = ['''^tests/fixtures/''']

Keep allowlists narrow. Allow a specific path and rule, such as a test fixture, instead of a whole directory or a broad regex. Never allowlist a rule wholesale because it is noisy. A config that silences a rule also silences the next real leak of that type. Review a .gitleaksignore or allowlist change the way you would review an access-control change.

The script picks up .gitleaks.toml and .gitleaksignore from the repo root automatically. Hooks use them only once they are committed (or staged, for staged). A local edit cannot quietly change what gets through. Set SECRET_SCAN_CONFIG to use a shared config from elsewhere; a relative path is resolved from where you run the script.

Hooks

install-hooks writes pre-commit (runs staged) and pre-push (runs push) into the repository's hooks directory. It refuses to overwrite a hook it did not write; add a call to the script inside that hook instead. git commit --no-verify skips pre-commit, which is why pre-push scans the outgoing range again. A new branch is scanned through its full history, even if a remote-tracking ref says a remote already has those commits. Tracking refs can be stale: git remote set-url points a remote at a new URL, and the old refs stay. This matters when a branch moves from a private remote to a public one.

Keep this public, keep your data private

This skill is generic on purpose. Do not add repository inventories, fleet or host paths, credentials, or real findings to a public copy of it. Keep those in a private repository or local config. Reports belong outside the repository you scanned, or in a gitignored path.

CI

Run the same script in CI for a second check that local --no-verify cannot skip:

yaml
- uses: actions/checkout@v6
  with:
    fetch-depth: 0     # history scans need every commit
- run: path/to/secret-scan.sh install
- run: path/to/secret-scan.sh history

Run this only on hosted runners, or on push events from trusted branches. Never run untrusted pull-request code on a self-hosted runner. A fork's PR can rewrite the scan script itself and then read whatever that runner can reach.

Pinned version

The script pins Gitleaks 8.30.1 and the SHA-256 of each platform build from the release's checksums.txt. To upgrade, change GITLEAKS_VERSION and all four hashes together, then run self-test. Set GITLEAKS_BIN to use a binary you installed another way. It must still report the pinned version.

© jamditis, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in security-toolkit/skills/private-secret-scanning of jamditis/claude-skills-journalism.

  • SKILL.md
  • agents/openai.yaml
  • scripts/secret-scan.sh

Open the folder on GitHubat commit e3e2172

Compare with similar skills

Private Secret Scanning next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Private Secret Scanning compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Private Secret Scanning this skilljamditis/claude-skills-journalism416—~1.8kAutomated safety check: PassMIT
Git Gh Pat AuthNEventStore/NEventStore1.6k—~828Automated safety check: PassMIT
GreptimeDB Release RunbookGreptimeTeam/greptimedb6.7k—~1.4kAutomated safety check: PassApache-2.0
Datadog Data Source GeneratorDataDog/terraform-provider-datadog468—~2.7kAutomated safety check: PassMPL-2.0
Open-Source Release Readinesstrailofbits/skills7.5k—~2.6kAutomated safety check: PassCC-BY-SA-4.0
Openclaw Secret Scanning Maintaineropenclaw/openclaw392k—~2.5kAutomated safety check: PassMIT

Similar skills

  • Git Gh Pat Auth

    NEventStore/NEventStore

    A skill your agent uses when: authenticating git and GitHub CLI for NEventStore tasks, fixing gh auth errors, setting PAT environment variables, preparing a shell session for git push and gh issue…

    1.6k GitHub stars~828 tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • GreptimeDB Release Runbook

    GreptimeTeam/greptimedb

    Runbook for publishing a GreptimeDB version: pick the release branch, verify the Cargo version, then tag, create the GitHub release and open the docs note PR.

    6.7k GitHub stars~1.4k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Datadog Data Source Generator

    DataDog/terraform-provider-datadog

    Official

    Generates a Datadog Terraform provider data source from an OpenAPI operation with tfgen and opens a review-ready GitHub PR with a risk scan and testing guide.

    468 GitHub stars~2.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Official

    Walks a repository through release readiness before it goes public: secrets audit, licensing, documentation, CI and language-specific packaging.

    7.5k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Triage, redact, clean up, and resolve OpenClaw GitHub Secret Scanning alerts in issues or PRs.

    392k GitHub stars~2.5k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Manages Git identity, HTTPS access tokens and SSH keys at the workspace level through three `tai tool` commands, each with a get, set, list, import or delete action.

    8.1k GitHub stars~712 tokensUpdated 2 days ago
    DevelopmentAuto-check passed

More from jamditis/claude-skills-journalism

All 53 skills in this repo
  • Web Design Picker

    jamditis/claude-skills-journalism

    A skill your agent uses when creating distinct website directions, a client review picker, asset catalog, previews, and Cloudflare-ready handoffs.

    416 GitHub stars~3.1k tokensUpdated 5 days ago
    Auto-check passed
  • Okf Wiki

    jamditis/claude-skills-journalism

    Builds an Open Knowledge Format (OKF) knowledge base from existing docs, notes, or a repo.

    416 GitHub stars~4.7k tokensUpdated 5 days ago
    Auto-check passed
  • Data Journalism

    jamditis/claude-skills-journalism

    Acquire, clean, analyze, verify, visualize, and explain data for journalism.

    416 GitHub stars~1.6k tokensUpdated 5 days ago
    Auto-check passed
  • Document Design

    jamditis/claude-skills-journalism

    Creates print-ready HTML that exports to PDF. An agent skill from jamditis/claude-skills-journalism.

    416 GitHub stars~1.9k tokensUpdated 5 days ago
    Auto-check passed
  • Using Superjawn

    jamditis/claude-skills-journalism

    Establishes how to find and use skills, requiring Skill tool invocation before any response.

    416 GitHub stars~1.5k tokensUpdated 5 days ago
    Auto-check passed
  • Zero Build Frontend

    jamditis/claude-skills-journalism

    Zero-build frontend development for static apps, browser extensions, maps, and lightweight data-backed interfaces.

    416 GitHub stars~1.5k tokensUpdated 5 days ago
    Auto-check passed

Works with

Categories

Questions about Private Secret Scanning

What does Private Secret Scanning do?

Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports. Private Secret Scanning is an agent skill from jamditis/claude-skills-journalism. Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports.

When should I use Private Secret Scanning?

Private Secret Scanning fits situations like: block committed secrets without GitHub Secret Protection; tasks that involve Secrets management.

How do I install Private Secret Scanning in Claude Code?

Run `npx skills add jamditis/claude-skills-journalism --skill private-secret-scanning -a claude-code`. Or copy the skill folder (security-toolkit/skills/private-secret-scanning in jamditis/claude-skills-journalism) into .claude/skills/private-secret-scanning in your project. Claude Code loads it when a task matches its description.

How do I install Private Secret Scanning in Codex?

Run `npx skills add jamditis/claude-skills-journalism --skill private-secret-scanning -a codex`. Or copy the skill folder (security-toolkit/skills/private-secret-scanning in jamditis/claude-skills-journalism) into .agents/skills/private-secret-scanning in your project. Codex loads it when a task matches its description.

Can I use Private Secret Scanning in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jamditis/claude-skills-journalism --skill private-secret-scanning -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/private-secret-scanning, .gemini/skills/private-secret-scanning, .github/skills/private-secret-scanning and .opencode/skills/private-secret-scanning in your project.

What does Private Secret Scanning need to run?

Going by SKILL.md and its folder, Private Secret Scanning needs a shell for the scripts in its folder and the command-line tools its instructions call (git and python3). Our summary lists: Python 3; A Bash shell.

Does Private Secret Scanning access the network?

SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.

Is Private Secret Scanning safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Private Secret Scanning use?

Private Secret Scanning is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Private Secret Scanning use?

About 1.8k tokens (SKILL.md is roughly 7.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Private Secret Scanning?

Skills that share tags, products or a category with Private Secret Scanning: Git Gh Pat Auth (NEventStore/NEventStore, 1.6k stars), GreptimeDB Release Runbook (GreptimeTeam/greptimedb, 6.7k stars), Datadog Data Source Generator (DataDog/terraform-provider-datadog, 468 stars) and Open-Source Release Readiness (trailofbits/skills, 7.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Private Secret Scanning?

jamditis (a GitHub user) maintains it in jamditis/claude-skills-journalism, which has 416 GitHub stars. The repository holds 53 skills in this directory. The repository was last updated on October 4, 2026.

Source: jamditis/claude-skills-journalism on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.