Agent skill

Secret Sweep Scan

by liuyanghejerry in liuyanghejerry/Clausura

“大规模扫描硬编码凭证,忽略占位符”

— description from SKILL.md by liuyanghejerry
MITAuto-check passedDevOps & Cloud

Install Secret Sweep Scan

skills CLI
$ npx skills add liuyanghejerry/Clausura --skill secret-sweep-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install liuyanghejerry/Clausura secret-sweep-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/liuyanghejerry/Clausura.git skills-src && mkdir -p .claude/skills && cp -r skills-src/eval/scenarios/secret-sweep/workspace/.clausura/skills/secret-sweep-scan .claude/skills/secret-sweep-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secret-sweep-scan
GitHub stars
204
Token cost
~125 tokens
SKILL.md length
25 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

  • Needs EXPORT_TOKEN

About this skill

Secret Sweep Scan is a skill in liuyanghejerry/Clausura (204 stars). Its SKILL.md is about 125 tokens. Licence: MIT.

What it can do on your machine

Read from SKILL.md and the folder at commit 7653c87. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • EXPORT_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secret Sweep Scan loads about 125 tokens when it runs. Until then it costs about 9 tokens; SKILL.md has 25 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~9
When it runs · the whole SKILL.md, loaded when a task matches
~125

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from liuyanghejerry/Clausura at commit 7653c87, republished under its MIT licence (© liuyanghejerry). 25 words, ~125 tokens.

Download SKILL.mdSave it as .claude/skills/secret-sweep-scan/SKILL.md (or your agent's skills folder).
name
secret-sweep-scan
description
大规模扫描硬编码凭证,忽略占位符

硬编码凭证扫描

先用 git_diff(参数 {"base": "HEAD~1"})查看变更范围,再对全部变更文件 扫描硬编码凭证。

判定标准

  • rule_id: hardcoded-secret
  • severity: error

报告:看起来像真实凭证的值(sk-...、ghp_...、AKIA... 等已知密钥 前缀,或明确的 api_secret/EXPORT_TOKEN 赋值给非占位符值)。

忽略(不得报告):占位符与示例值,如 REPLACE_ME、your-api-key-here、 example-*、CHANGE_ME_*、placeholder-*、dummy-*、not-a-real-*、 <YOUR_SECRET>。

文件较多(10 个服务),请系统地覆盖全部文件——grep 一次全仓扫描比逐个 read_file 更高效。

© liuyanghejerry, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in eval/scenarios/secret-sweep/workspace/.clausura/skills/secret-sweep-scan of liuyanghejerry/Clausura.

Open the folder on GitHubat commit 7653c87

Compare with similar skills

Secret Sweep Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secret Sweep Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secret Sweep Scan this skillliuyanghejerry/Clausura204—~125Automated safety check: PassMIT
Monitor CInrwl/nx29k6 repos~4.7kAutomated safety check: PassMIT
Terraform and OpenTofu Guideagentscope-ai/QwenPaw36k6 repos~4.2kAutomated safety check: PassApache-2.0
Vercel Optimize Auditvercel-labs/agent-skills32k8 repos~4.3kAutomated safety check: PassNone
Analyze GitHub Action Logswithastro/astro63k1 repos~1.3kAutomated safety check: PassCustom licence
Openclaw Live Updateropenclaw/openclaw392k—~3.7kAutomated safety check: PassMIT

Similar skills

  • Monitor CI

    nrwl/nx

    Monitor Nx Cloud CI pipeline and handle self-healing fixes. An agent skill from nrwl/nx.

    29k GitHub starsUsed in 6 repos~4.7k tokens
    DevOps & CloudAuto-check passed
  • Terraform and OpenTofu Guide

    agentscope-ai/QwenPaw

    Guidance for writing and testing Terraform and OpenTofu code: module structure, naming, test approaches, CI/CD workflows, state handling and security scanning.

    36k GitHub starsUsed in 6 repos~4.2k tokens
    DevOps & CloudAuto-check passed
  • Vercel Optimize Audit

    vercel-labs/agent-skills

    Official

    Runs a metrics-first audit of a deployed Vercel project, gating investigations on real signals to produce ranked, citation-backed cost and performance recommendations.

    32k GitHub starsUsed in 8 repos~4.3k tokens
    DevOps & CloudAuto-check passed
  • Official

    Analyze recent GitHub Actions workflow runs to identify patterns, mistakes, and improvements.

    63k GitHub starsUsed in 1 repo~1.3k tokens
    DevOps & CloudAuto-check passed
  • Openclaw Live Updater

    openclaw/openclaw

    Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.

    392k GitHub stars~3.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Docs Learn PR Preview

    netdata/netdata

    Use only when the user explicitly asks to build, run, preview, inspect, or validate learn.netdata.cloud locally using the contents of a PR or documentation branch before merge.

    81k GitHub stars~2k tokensUpdated today
    DevOps & CloudAuto-check passed

More from liuyanghejerry/Clausura

  • Python Review

    liuyanghejerry/Clausura

    Python 遗留代码审查:bare except、SQL 注入、反序列化、密钥、调试输出. An agent skill from liuyanghejerry/Clausura.

    204 GitHub stars~164 tokensUpdated 11 days ago
    Auto-check passed
  • TS Review

    liuyanghejerry/Clausura

    TypeScript monorepo 审查:XSS、SQL 注入、密钥、any、console.log. An agent skill from liuyanghejerry/Clausura.

    204 GitHub stars~166 tokensUpdated 11 days ago
    Auto-check passed
  • Rust Review

    liuyanghejerry/Clausura

    Rust 服务审查:panic、SQL 注入、密钥、错误吞没、遗留标记

    204 GitHub stars~180 tokensUpdated 11 days ago
    Auto-check passed
  • Security Review

    liuyanghejerry/Clausura

    检查 SQL 注入、XSS、硬编码密钥

    204 GitHub stars~106 tokensUpdated 11 days ago
    Auto-check passed

Categories

Questions about Secret Sweep Scan

How do I install Secret Sweep Scan in Claude Code?

Run `npx skills add liuyanghejerry/Clausura --skill secret-sweep-scan -a claude-code`. Or copy the skill folder (eval/scenarios/secret-sweep/workspace/.clausura/skills/secret-sweep-scan in liuyanghejerry/Clausura) into .claude/skills/secret-sweep-scan in your project. Claude Code loads it when a task matches its description.

How do I install Secret Sweep Scan in Codex?

Run `npx skills add liuyanghejerry/Clausura --skill secret-sweep-scan -a codex`. Or copy the skill folder (eval/scenarios/secret-sweep/workspace/.clausura/skills/secret-sweep-scan in liuyanghejerry/Clausura) into .agents/skills/secret-sweep-scan in your project. Codex loads it when a task matches its description.

Can I use Secret Sweep Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add liuyanghejerry/Clausura --skill secret-sweep-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secret-sweep-scan, .gemini/skills/secret-sweep-scan, .github/skills/secret-sweep-scan and .opencode/skills/secret-sweep-scan in your project.

What does Secret Sweep Scan need to run?

Going by SKILL.md and its folder, Secret Sweep Scan needs credentials named EXPORT_TOKEN.

Does Secret Sweep Scan access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Secret Sweep Scan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Secret Sweep Scan use?

Secret Sweep Scan is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Secret Sweep Scan use?

About 125 tokens (SKILL.md is roughly 500 characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Secret Sweep Scan?

Skills that share tags, products or a category with Secret Sweep Scan: Monitor CI (nrwl/nx, 29k stars), Terraform and OpenTofu Guide (agentscope-ai/QwenPaw, 36k stars), Vercel Optimize Audit (vercel-labs/agent-skills, 32k stars) and Analyze GitHub Action Logs (withastro/astro, 63k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secret Sweep Scan?

liuyanghejerry (a GitHub user) maintains it in liuyanghejerry/Clausura, which has 204 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on September 29, 2026.

Source: liuyanghejerry/Clausura on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.