Agent skill

Secrets Scan

by jwynia in jwynia/agent-skills

Detect API keys, passwords, tokens, and other secrets in code.

MITAuto-check passedDevelopment

Install Secrets Scan

skills CLI
$ npx skills add jwynia/agent-skills --skill secrets-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jwynia/agent-skills secrets-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jwynia/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/tech/security/secrets-scan .claude/skills/secrets-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secrets-scan
GitHub stars
169
Token cost
~1.8k tokens
SKILL.md length
311 words
Files
1
Skills in repo
111
Repo updated
First seen
Licence
MIT

At a glance

Detect API keys, passwords, tokens, and other secrets in code.

  • Works in 3 steps: Example/placeholder values → Test fixtures → Documentation
  • You need to find hardcoded credentials and sensitive data in source code
  • SKILL.md covers Quick Start, What This Skill Detects, Detection Patterns and Scan Options, plus 3 more sections
  • Calls git and npx

What it does

Secrets Scan is an agent skill from jwynia/agent-skills. Detect API keys, passwords, tokens, and other secrets in code. Use when you need to find hardcoded credentials and sensitive data in source code.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Git workflow. It works with Amazon Web Services and Stripe. The licence is MIT.

When your agent uses it

  • You need to find hardcoded credentials and sensitive data in source code
  • Tasks that involve Git workflow

Example prompts

  • “/secrets-scan”

Requirements

  • Node.js
  • Docker
  • A credential in EXAMPLE_KEY

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Example/placeholder values
  2. Test fixtures
  3. Documentation

What it can do on your machine

Read from SKILL.md and the folder at commit e02ec7e. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secrets Scan loads about 1.8k tokens when it runs. Until then it costs about 40 tokens; SKILL.md has 311 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~40
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jwynia/agent-skills at commit e02ec7e, republished under its MIT licence (© jwynia). 311 words, ~1,833 tokens.

Download SKILL.mdSave it as .claude/skills/secrets-scan/SKILL.md (or your agent's skills folder).
name
secrets-scan
description
Detect API keys, passwords, tokens, and other secrets in code. Use when you need to find hardcoded credentials and sensitive data in source code.
license
MIT
metadata.author
jwynia
metadata.version
1.0
metadata.type
utility
metadata.mode
evaluative
metadata.domain
development

Secrets Scan

Deep detection of hardcoded credentials and sensitive data in source code.

Quick Start

/secrets-scan                    # Scan current directory
/secrets-scan --scope src/       # Scan specific path
/secrets-scan --entropy          # Include high-entropy detection
/secrets-scan --git-history      # Check git commit history

What This Skill Detects

High-Confidence Patterns

Patterns with very low false positive rates:

TypePattern ExampleProvider
AWS Access KeyAKIA... (20 chars)AWS
AWS Secret Key40 char base64AWS
GitHub Tokenghp_, gho_, ghu_, ghs_, ghr_GitHub
GitLab Tokenglpat-...GitLab
Slack Tokenxoxb-, xoxp-, xoxa-Slack
Stripe Keysk_live_, rk_live_Stripe
TwilioSK... (34 chars)Twilio
SendGridSG. followed by base64SendGrid
Private Key-----BEGIN (RSA|EC|DSA)?PRIVATE KEY-----Various
Google API KeyAIza... (39 chars)Google
Medium-Confidence Patterns

May require context validation:

TypePatternNotes
Generic API Keyapi[_-]?key.*=.*['"][a-zA-Z0-9]{16,}Variable names
Generic Secretsecret.*=.*['"][^'"]+Context needed
Passwordpassword.*=.*['"][^'"]+May be config
Connection String://[^:]+:[^@]+@DB credentials
Bearer TokenBearer [a-zA-Z0-9_-]+In headers/code
High-Entropy Detection

Finds potential secrets via entropy analysis:

/secrets-scan --entropy

Detects strings with high randomness that may be:

  • Base64-encoded secrets
  • Hex-encoded tokens
  • Custom API key formats

Detection Patterns

Cloud Provider Keys
regex
# AWS
AKIA[0-9A-Z]{16}                           # Access Key ID
[A-Za-z0-9/+=]{40}                         # Secret Access Key (context needed)

# Azure
[a-zA-Z0-9+/=]{88}                         # Storage Account Key

# GCP
AIza[0-9A-Za-z_-]{35}                      # API Key
[0-9]+-[a-z0-9]{32}\.apps\.googleusercontent\.com  # OAuth Client
Version Control Tokens
regex
# GitHub
gh[pousr]_[A-Za-z0-9]{36,}                 # Personal/OAuth/User/Repo/App
github_pat_[A-Za-z0-9]{22}_[A-Za-z0-9]{59} # Fine-grained PAT

# GitLab
glpat-[A-Za-z0-9-_]{20,}                   # Personal Access Token

# Bitbucket
[a-zA-Z0-9]{24}                            # App Password (context needed)
Payment & Finance
regex
# Stripe
sk_live_[a-zA-Z0-9]{24,}                   # Secret Key
rk_live_[a-zA-Z0-9]{24,}                   # Restricted Key
pk_live_[a-zA-Z0-9]{24,}                   # Publishable Key

# Square
sq0[a-z]{3}-[A-Za-z0-9_-]{22,}            # Access Token

# PayPal
access_token\$[a-zA-Z0-9-_.]+             # OAuth Token
Communication Services
regex
# Slack
xox[bpas]-[0-9]{10,}-[a-zA-Z0-9]{24,}     # Bot/User/App Token

# Twilio
SK[a-f0-9]{32}                             # API Key SID
[a-f0-9]{32}                               # Auth Token (context)

# SendGrid
SG\.[a-zA-Z0-9_-]{22}\.[a-zA-Z0-9_-]{43}  # API Key
Database Connection Strings
regex
# PostgreSQL/MySQL
(postgres|mysql|mariadb)://[^:]+:[^@]+@[^/]+/\w+

# MongoDB
mongodb(\+srv)?://[^:]+:[^@]+@

# Redis
redis://:[^@]+@
Private Keys
regex
-----BEGIN (RSA |EC |DSA |OPENSSH )?PRIVATE KEY-----
-----BEGIN PGP PRIVATE KEY BLOCK-----
JWT & Session
regex
eyJ[A-Za-z0-9_-]+\.eyJ[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+   # JWT

Scan Options

Basic Scan
/secrets-scan

Scans for high-confidence patterns only.

With Entropy Analysis
/secrets-scan --entropy

Adds high-entropy string detection (more findings, some false positives).

Specific Scope
/secrets-scan --scope src/api/
/secrets-scan --scope "*.ts"
Git History Scan
/secrets-scan --git-history
/secrets-scan --git-history --since "2024-01-01"

Scans commit history for secrets that were committed and later removed.

Exclude Patterns
/secrets-scan --exclude "*.test.ts" --exclude "fixtures/"

Output Format

Finding Report
SECRETS SCAN RESULTS
====================

High-Confidence Findings: 2
Medium-Confidence Findings: 5
Entropy Findings: 3

[!] CRITICAL: AWS Access Key
    File: src/config/aws.ts:15
    Pattern: AKIAIOSFODNN7EXAMPLE
    Action: Rotate immediately, check CloudTrail

[!] CRITICAL: GitHub Token
    File: .env.example:8
    Pattern: ghp_xxxx...xxxx (redacted)
    Action: Revoke token, remove from history

[H] HIGH: Database Password
    File: docker-compose.yml:23
    Pattern: password: supersecret
    Action: Use environment variable

[M] MEDIUM: Possible API Key
    File: src/services/api.ts:44
    Pattern: apiKey = "a1b2c3..."
    Context: May be test value
Summary Statistics
Files scanned: 342
Patterns checked: 127
Time elapsed: 2.3s

By Severity:
  Critical: 2
  High: 5
  Medium: 8

By Type:
  Cloud credentials: 2
  API keys: 4
  Passwords: 3
  Private keys: 1
  Other: 5

False Positive Handling

Common False Positives
  1. Example/placeholder values

    • AKIAIOSFODNN7EXAMPLE (AWS example)
    • sk_test_... (Stripe test key)
    • your-api-key-here
  2. Test fixtures

    • Mock credentials in test files
    • Fixture data
  3. Documentation

    • README examples
    • API documentation
Ignore File

Create .secrets-scan-ignore:

# Ignore test fixtures
**/fixtures/**
**/__mocks__/**
*.test.ts
*.spec.js

# Ignore documentation
docs/**
*.md

# Ignore specific false positives
src/constants.ts:EXAMPLE_KEY

# Inline ignore comment
# secrets-scan-ignore: test fixture
Inline Ignore
javascript
// secrets-scan-ignore: example value
const EXAMPLE_KEY = "AKIAIOSFODNN7EXAMPLE";

Remediation Steps

When Secrets Are Found
  1. Immediate Actions

    • Rotate the credential immediately
    • Check access logs for unauthorized use
    • Remove from code/config
  2. Clean Git History

    bash
    # Remove secret from history
    git filter-branch --force --index-filter \
      'git rm --cached --ignore-unmatch path/to/file' \
      --prune-empty --tag-name-filter cat -- --all
    
    # Or use BFG Repo Cleaner
    bfg --replace-text secrets.txt repo.git
  3. Prevent Future Commits

    • Add pre-commit hooks
    • Configure secret scanning in CI
Prevention
bash
# Install pre-commit hook
npx husky add .husky/pre-commit "npx secrets-scan --staged"

Integration

CI/CD Pipeline
yaml
# GitHub Actions
- name: Secrets Scan
  run: |
    /secrets-scan --fail-on-findings
    exit $?

# Exit codes:
# 0 = No findings
# 1 = Findings detected
# 2 = Error during scan
Pre-Commit Hook
bash
#!/bin/sh
# .husky/pre-commit
files=$(git diff --cached --name-only)
/secrets-scan --files "$files"
  • /security-scan - Full security analysis
  • /config-scan - Configuration security
  • /dependency-scan - Package vulnerabilities

© jwynia, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/tech/security/secrets-scan of jwynia/agent-skills.

Open the folder on GitHubat commit e02ec7e

Compare with similar skills

Secrets Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secrets Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secrets Scan this skilljwynia/agent-skills169—~1.8kAutomated safety check: PassMIT
Effect Client WrapperUsefulSoftwareCo/executor4.1k1 repos~1.4kAutomated safety check: PassMIT
LLM To Bedrockaws/agent-toolkit-for-aws2.8k—~16kAutomated safety check: PassApache-2.0
Audit Env Variablesqdhenry/Claude-Command-Suite1.3k—~2.8kAutomated safety check: NotesNone
Swe CLI SkillsSylphAI-Inc/skills111—~1.7kAutomated safety check: PassMIT
Security SecretsIgorWarzocha/Opencode-Workflows122—~1.2kAutomated safety check: NotesNone

Similar skills

  • Effect Client Wrapper

    UsefulSoftwareCo/executor

    Pattern for wrapping third-party SDK clients (Stripe, Resend, AWS, etc.) with Effect.

    4.1k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • LLM To Bedrock

    aws/agent-toolkit-for-aws

    Official

    A skill your agent uses when the user wants to migrate code that calls OpenAI, Gemini/Google AI, or the Anthropic API to Amazon Bedrock — a pure model/SDK rewrite.

    2.8k GitHub stars~16k tokensUpdated today
    DevelopmentAuto-check passed
  • Audit Env Variables

    qdhenry/Claude-Command-Suite

    Analyze environment variables in JavaScript/TypeScript projects.

    1.3k GitHub stars~2.8k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check: notes
  • Swe CLI Skills

    SylphAI-Inc/skills

    Senior engineer CLI expertise for AI agents — workflows, safety guardrails, gotchas, and anti-patterns across cloud, IaC, containers, databases, dev tools, and platforms

    111 GitHub stars~1.7k tokensUpdated 16 days ago
    DevOps & CloudAuto-check passed
  • Security Secrets

    IgorWarzocha/Opencode-Workflows

    Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows.

    122 GitHub stars~1.2k tokensUpdated 8 mo ago
    SecurityAuto-check: notes
  • Engineering Skills

    alirezarezvani/claude-skills

    Index of the engineering-team skills bundle for Claude Code, Codex, Gemini CLI, Cursor, OpenClaw, and 6 more tools.

    28k GitHub stars~887 tokensUpdated 1 mo ago
    Testing & QAAuto-check passed

More from jwynia/agent-skills

All 111 skills in this repo
  • Devcontainer

    jwynia/agent-skills

    Diagnose devcontainer configuration problems and guide development environment setup.

    169 GitHub stars~1.2k tokensUpdated 7 mo ago
    Auto-check: notes
  • Frontend Design

    jwynia/agent-skills

    Create distinctive, production-grade frontend interfaces with high design quality.

    169 GitHub stars~3.2k tokensUpdated 7 mo ago
    Auto-check passed
  • Gitea Workflow

    jwynia/agent-skills

    Orchestrate agile development workflows for Gitea repositories using the tea CLI.

    169 GitHub stars~3.8k tokensUpdated 7 mo ago
    Auto-check passed
  • Godot Asset Generator

    jwynia/agent-skills

    Generate game assets using AI image generation APIs (DALL-E, Replicate, fal.ai) and prepare them for Godot.

    169 GitHub stars~3.8k tokensUpdated 7 mo ago
    Auto-check passed
  • Mastra Hono

    jwynia/agent-skills

    Develop AI agents, tools, and workflows with Mastra v1 Beta and Hono servers.

    169 GitHub stars~2.9k tokensUpdated 7 mo ago
    Auto-check passed
  • PPTX Generator

    jwynia/agent-skills

    Create and manipulate PowerPoint PPTX files programmatically.

    169 GitHub stars~3.1k tokensUpdated 7 mo ago
    Auto-check passed

Categories

Questions about Secrets Scan

What does Secrets Scan do?

Detect API keys, passwords, tokens, and other secrets in code. Secrets Scan is an agent skill from jwynia/agent-skills. Detect API keys, passwords, tokens, and other secrets in code.

When should I use Secrets Scan?

Secrets Scan fits situations like: you need to find hardcoded credentials and sensitive data in source code; tasks that involve Git workflow.

How do I install Secrets Scan in Claude Code?

Run `npx skills add jwynia/agent-skills --skill secrets-scan -a claude-code`. Or copy the skill folder (skills/tech/security/secrets-scan in jwynia/agent-skills) into .claude/skills/secrets-scan in your project. Claude Code loads it when a task matches its description.

How do I install Secrets Scan in Codex?

Run `npx skills add jwynia/agent-skills --skill secrets-scan -a codex`. Or copy the skill folder (skills/tech/security/secrets-scan in jwynia/agent-skills) into .agents/skills/secrets-scan in your project. Codex loads it when a task matches its description.

Can I use Secrets Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jwynia/agent-skills --skill secrets-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secrets-scan, .gemini/skills/secrets-scan, .github/skills/secrets-scan and .opencode/skills/secrets-scan in your project.

What does Secrets Scan need to run?

Going by SKILL.md and its folder, Secrets Scan needs the command-line tools its instructions call (git and npx). Our summary lists: Node.js; Docker; A credential in EXAMPLE_KEY.

Does Secrets Scan access the network?

SKILL.md contains no URLs. Its commands use git and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Secrets Scan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Secrets Scan use?

Secrets Scan is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Secrets Scan use?

About 1.8k tokens (SKILL.md is roughly 7.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Secrets Scan?

Skills that share tags, products or a category with Secrets Scan: Effect Client Wrapper (UsefulSoftwareCo/executor, 4.1k stars), LLM To Bedrock (aws/agent-toolkit-for-aws, 2.8k stars), Audit Env Variables (qdhenry/Claude-Command-Suite, 1.3k stars) and Swe CLI Skills (SylphAI-Inc/skills, 111 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secrets Scan?

jwynia (a GitHub user) maintains it in jwynia/agent-skills, which has 169 GitHub stars. The repository holds 111 skills in this directory. The repository was last updated on February 24, 2026.

Source: jwynia/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.