Agent skill

Implementing Secret Scanning With Gitleaks

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

This skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories.

Apache-2.0Auto-check passedDevOps & Cloud

Install Implementing Secret Scanning With Gitleaks

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-secret-scanning-with-gitleaks -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills implementing-secret-scanning-with-gitleaks --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/implementing-secret-scanning-with-gitleaks .claude/skills/implementing-secret-scanning-with-gitleaks && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
implementing-secret-scanning-with-gitleaks
GitHub stars
34k
Token cost
~2.8k tokens
SKILL.md length
547 words
Files
8 (incl. scripts, references, assets)
Skills in repo
644
Repo updated
First seen
Licence
Apache-2.0

At a glance

This skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories.

  • Works in 6 steps: Install and Run Initial Repository Scan → Configure Pre-Commit Hook → Integrate into GitHub Actions → …
  • Tasks that involve Secrets management
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls gitleaks, git and pip; reaches github.com; needs GITHUB_TOKEN and AWS_SECRET_ACCESS_KEY

What it does

Implementing Secret Scanning With Gitleaks is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. This skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories. It addresses configuring pre-commit hooks, CI/CD pipeline integration, custom rule authoring for organization-specific secrets, baseline management for existing repositories, and remediation workflows for exposed credentials.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in DevOps & Cloud, covering Secrets management. It works with Git. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Secrets management

Example prompts

  • “/implementing-secret-scanning-with-gitleaks”

Requirements

  • Python 3
  • Docker
  • A credential in AWS_SECRET_ACCESS_KEY
  • A credential in GITHUB_TOKEN

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Install and Run Initial Repository Scan
  2. Configure Pre-Commit Hook
  3. Integrate into GitHub Actions
  4. Author Custom Detection Rules
  5. Manage Baselines for Existing Repositories
  6. Remediate Exposed Secrets

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • gitleaks
    • git
    • pip
    • brew
    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN
    • AWS_SECRET_ACCESS_KEY
    • REDACTED_AWS_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Implementing Secret Scanning With Gitleaks loads about 2.8k tokens when it runs, and up to ~5.8k if it reads all its reference files. Until then it costs about 94 tokens; SKILL.md has 547 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 547 words, ~2,835 tokens.

Download SKILL.mdSave it as .claude/skills/implementing-secret-scanning-with-gitleaks/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
implementing-secret-scanning-with-gitleaks
description
This skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories. It addresses configuring pre-commit hooks, CI/CD pipeline integration, custom rule authoring for organization-specific secrets, baseline management for existing repositories, and remediation workflows for exposed credentials.
domain
cybersecurity
subdomain
devsecops
tags
devsecops, cicd, secret-scanning, gitleaks, pre-commit, secure-sdlc
version
1.0.0
author
mahipal
license
Apache-2.0
nist_csf
PR.PS-01, GV.SC-07, ID.IM-04, PR.PS-04
mitre_attack
T1195, T1554, T1059.004, T1003, T1110

Implementing Secret Scanning with Gitleaks

When to Use

  • When developers may accidentally commit API keys, passwords, tokens, or private keys to repositories
  • When establishing pre-commit gates that prevent secrets from entering the git history
  • When scanning existing repository history for previously committed secrets that need rotation
  • When compliance requirements mandate secret detection across all source code repositories
  • When migrating from manual secret audits to automated continuous scanning

Do not use for detecting secrets in running applications or memory (use runtime secret detection), for managing secrets after detection (use Vault or AWS Secrets Manager), or for scanning container images (use Trivy or Grype).

Prerequisites

  • Gitleaks v8.18+ installed via binary, Go install, or Docker
  • Pre-commit framework installed for local hook integration
  • Git repository with history to scan
  • CI/CD platform access (GitHub Actions, GitLab CI, or equivalent)

Workflow

Step 1: Install and Run Initial Repository Scan

Perform a baseline scan of the repository to identify all existing secrets in the git history.

bash
# Install Gitleaks
brew install gitleaks  # macOS
# or download binary from https://github.com/gitleaks/gitleaks/releases

# Scan entire git history for secrets
gitleaks detect --source . --report-format json --report-path gitleaks-report.json -v

# Scan only staged changes (for pre-commit)
gitleaks protect --staged --report-format json --report-path gitleaks-staged.json

# Scan specific commit range
gitleaks detect --source . --log-opts="HEAD~10..HEAD" --report-format json

# Scan without git history (filesystem only)
gitleaks detect --source . --no-git --report-format json
Step 2: Configure Pre-Commit Hook

Set up Gitleaks as a pre-commit hook to prevent secrets from being committed.

yaml
# .pre-commit-config.yaml
repos:
  - repo: https://github.com/gitleaks/gitleaks
    rev: v8.21.2
    hooks:
      - id: gitleaks
        name: gitleaks
        description: Detect hardcoded secrets using Gitleaks
        entry: gitleaks protect --staged --verbose --redact
        language: golang
        pass_filenames: false
bash
# Install pre-commit framework
pip install pre-commit

# Install hooks defined in .pre-commit-config.yaml
pre-commit install

# Run against all files (not just staged)
pre-commit run gitleaks --all-files

# Test the hook with a deliberate secret
echo 'AWS_SECRET_ACCESS_KEY="wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY"' >> test.txt
git add test.txt
git commit -m "test"  # Should be blocked by gitleaks
Step 3: Integrate into GitHub Actions
yaml
# .github/workflows/secret-scanning.yml
name: Secret Scanning

on:
  push:
    branches: [main, develop]
  pull_request:
    branches: [main]

jobs:
  gitleaks:
    name: Gitleaks Secret Scan
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
        with:
          fetch-depth: 0  # Full history for comprehensive scanning

      - name: Run Gitleaks
        uses: gitleaks/gitleaks-action@v2
        env:
          GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
          GITLEAKS_LICENSE: ${{ secrets.GITLEAKS_LICENSE }}  # Required for gitleaks-action v2

      # Alternative: Run Gitleaks directly
      - name: Install Gitleaks
        run: |
          wget -q https://github.com/gitleaks/gitleaks/releases/download/v8.21.2/gitleaks_8.21.2_linux_x64.tar.gz
          tar -xzf gitleaks_8.21.2_linux_x64.tar.gz
          chmod +x gitleaks

      - name: Scan for secrets
        run: |
          if [ "${{ github.event_name }}" == "pull_request" ]; then
            ./gitleaks detect \
              --source . \
              --log-opts="${{ github.event.pull_request.base.sha }}..${{ github.event.pull_request.head.sha }}" \
              --report-format sarif \
              --report-path gitleaks.sarif \
              --exit-code 1
          else
            ./gitleaks detect \
              --source . \
              --report-format sarif \
              --report-path gitleaks.sarif \
              --exit-code 1 \
              --baseline-path .gitleaks-baseline.json
          fi

      - name: Upload SARIF
        if: always()
        uses: github/codeql-action/upload-sarif@v3
        with:
          sarif_file: gitleaks.sarif
          category: gitleaks
Step 4: Author Custom Detection Rules

Create organization-specific rules for internal secret patterns.

toml
# .gitleaks.toml
title = "Organization Gitleaks Configuration"

[extend]
useDefault = true  # Include all default rules

# Custom rule for internal API tokens
[[rules]]
id = "internal-api-token"
description = "Internal API token for service-to-service auth"
regex = '''(?i)x-internal-token["\s:=]+["\']?([a-zA-Z0-9_\-]{40,})["\']?'''
entropy = 3.5
keywords = ["x-internal-token"]
tags = ["internal", "api"]

[[rules]]
id = "database-connection-string"
description = "Database connection string with embedded credentials"
regex = '''(?i)(postgres|mysql|mongodb|redis)://[^:]+:[^@]+@[^/]+/\w+'''
keywords = ["postgres://", "mysql://", "mongodb://", "redis://"]
tags = ["database", "credentials"]

[[rules]]
id = "jwt-secret"
description = "JWT signing secret"
regex = '''(?i)(jwt[_-]?secret|jwt[_-]?key)["\s:=]+["\']?([a-zA-Z0-9/+_\-]{32,})["\']?'''
entropy = 3.0
keywords = ["jwt_secret", "jwt-secret", "jwt_key", "jwt-key"]

# Allowlist for test files and known safe patterns
[allowlist]
description = "Global allowlist"
paths = [
  '''(^|/)test(s)?/''',
  '''(^|/)spec/''',
  '''\.test\.(js|ts|py)$''',
  '''\.spec\.(js|ts|py)$''',
  '''__mocks__/''',
  '''fixtures/''',
  '''(^|/)vendor/''',
  '''node_modules/'''
]
regexes = [
  '''EXAMPLE''',
  '''example\.com''',
  '''test[-_]?(key|secret|token|password)''',
  '''(?i)placeholder''',
  '''000000+'''
]
Step 5: Manage Baselines for Existing Repositories

Create a baseline of known findings to avoid blocking development while historical secrets are being rotated.

bash
# Generate baseline from current state
gitleaks detect --source . --report-format json --report-path .gitleaks-baseline.json

# Subsequent scans compare against baseline (only new findings trigger failures)
gitleaks detect --source . --baseline-path .gitleaks-baseline.json --exit-code 1

# Review baseline periodically and remove entries as secrets are rotated
cat .gitleaks-baseline.json | python3 -m json.tool | head -50
Step 6: Remediate Exposed Secrets

When a secret is detected, follow the rotation and history cleanup procedure.

bash
# 1. Immediately rotate the exposed credential
#    - Revoke the old API key/token in the service provider
#    - Generate a new credential
#    - Store the new credential in a secrets manager

# 2. Remove secret from git history using git-filter-repo
pip install git-filter-repo

# Create expressions file for secrets to remove
cat > /tmp/expressions.txt << 'EOF'
regex:AKIA[0-9A-Z]{16}==>REDACTED_AWS_KEY
regex:(?i)password\s*=\s*"[^"]*"==>password="REDACTED"
EOF

git filter-repo --replace-text /tmp/expressions.txt --force

# 3. Force-push the cleaned history (coordinate with team)
# git push --force --all  # WARNING: Requires team coordination

# 4. Add the secret pattern to .gitleaks.toml rules
# 5. Update the baseline file to remove the resolved finding

Key Concepts

TermDefinition
SecretAny credential, token, key, or sensitive string that should not appear in source code
Pre-commit HookGit hook that runs before a commit is created, blocking commits containing detected secrets
EntropyMeasure of randomness in a string; high-entropy strings are more likely to be secrets
BaselineSnapshot of existing findings used to differentiate new secrets from pre-existing ones
AllowlistConfiguration specifying paths, patterns, or commits to exclude from detection
SARIFStatic Analysis Results Interchange Format for uploading findings to security dashboards
git-filter-repoTool for rewriting git history to remove sensitive data from all commits
Show full SKILL.md (212 more words)Show less

Tools & Systems

  • Gitleaks: Open-source secret detection tool supporting pre-commit hooks, CI/CD, and historical scanning
  • pre-commit: Framework for managing and maintaining multi-language pre-commit hooks
  • git-filter-repo: History rewriting tool for removing secrets from git history
  • TruffleHog: Alternative secret scanner with verified secret detection capabilities
  • GitHub Secret Scanning: Native GitHub feature that detects secrets matching partner patterns

Common Scenarios

Scenario: Onboarding Secret Scanning on a Legacy Repository

Context: A 5-year-old repository has never been scanned. The team needs to enable secret scanning without blocking all development while historical secrets are rotated.

Approach:

  1. Run gitleaks detect against full history and generate a baseline JSON file
  2. Triage each finding: classify as active (needs rotation), inactive (already rotated), or false positive
  3. Immediately rotate all active secrets and update consuming services
  4. Commit the baseline file (excluding active secrets that have been fixed)
  5. Enable pre-commit hooks for new development immediately
  6. Add CI/CD scanning with the baseline to catch only new secrets
  7. Progressively reduce the baseline as historical secrets are rotated

Pitfalls: Generating a baseline without triaging means accepting risk on unrotated secrets. Never assume a historical secret is inactive without verifying with the service provider. Running git-filter-repo on a shared repository without coordination will cause rebase conflicts for all team members.

Output Format

Gitleaks Secret Scanning Report
=================================
Repository: org/web-application
Scan Type: Full History
Commits Scanned: 4,523
Date: 2026-02-23

FINDINGS:
  Total: 12
  New (not in baseline): 3
  Baseline (pre-existing): 9

NEW FINDINGS (blocking):
  [1] AWS Access Key ID
      Rule: aws-access-key-id
      File: src/config/aws.py:23
      Commit: a1b2c3d (2026-02-22, dev@company.com)
      Secret: AKIA...REDACTED
      Entropy: 3.8

  [2] GitHub Personal Access Token
      Rule: github-pat
      File: scripts/deploy.sh:15
      Commit: d4e5f6g (2026-02-21, ops@company.com)
      Secret: ghp_...REDACTED
      Entropy: 4.2

  [3] Internal API Token
      Rule: internal-api-token
      File: src/services/auth.py:89
      Commit: h7i8j9k (2026-02-20, dev@company.com)

QUALITY GATE: FAILED (3 new findings)
Action: Rotate exposed credentials immediately.

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/implementing-secret-scanning-with-gitleaks of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Implementing Secret Scanning With Gitleaks next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Implementing Secret Scanning With Gitleaks compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Implementing Secret Scanning With Gitleaks this skillmukul975/Anthropic-Cybersecurity-Skills34k—~2.8kAutomated safety check: PassApache-2.0
Secrets GitleaksAgentSecOps/SecOpsAgentKit2202 repos~4.1kAutomated safety check: PassCustom licence
Private Secret Scanningjamditis/claude-skills-journalism416—~1.8kAutomated safety check: PassMIT
KubeSphere DevOps Credentialskubesphere/kubesphere17k—~4.2kAutomated safety check: PassCustom licence
Dotenvx Secretskortix-ai/suna20k—~4.4kAutomated safety check: NotesCustom licence
Leaked Secretsthedaviddias/Front-End-Checklist74k—~596Automated safety check: NotesMIT

Similar skills

  • Secrets Gitleaks

    AgentSecOps/SecOpsAgentKit

    Hardcoded secret detection and prevention in git repositories and codebases using Gitleaks.

    220 GitHub starsUsed in 2 repos~4.1k tokens
    DevOps & CloudAuto-check passed
  • Private Secret Scanning

    jamditis/claude-skills-journalism

    Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports.

    416 GitHub stars~1.8k tokensUpdated 6 days ago
    DevOps & CloudAuto-check passed
  • KubeSphere DevOps Credentials

    kubesphere/kubesphere

    Covers creating and managing KubeSphere DevOps credentials as typed Kubernetes Secrets that sync to Jenkins, including the API endpoints and a common pitfall.

    17k GitHub stars~4.2k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Dotenvx Secrets

    kortix-ai/suna

    How this repo manages API secrets and the four local-run environments (local/dev/staging/prod).

    20k GitHub stars~4.4k tokensUpdated today
    DevOps & CloudAuto-check: notes
  • Leaked Secrets

    thedaviddias/Front-End-Checklist

    A skill your agent uses when reviewing client-side JavaScript, HTML source, or git history for exposed credentials, API keys, or tokens.

    74k GitHub stars~596 tokensUpdated 4 days ago
    DevOps & CloudAuto-check: notes
  • Secrets Audit

    briiirussell/cybersecurity-skills

    Find leaked secrets in source code, Git history, build artifacts, and infrastructure — and audit the secrets-management posture preventing future leaks.

    413 GitHub stars~2.6k tokensUpdated 4 mo ago
    DevOps & CloudAuto-check: notes

More from mukul975/Anthropic-Cybersecurity-Skills

All 644 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Categories

Questions about Implementing Secret Scanning With Gitleaks

What does Implementing Secret Scanning With Gitleaks do?

This skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories. Implementing Secret Scanning With Gitleaks is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. This skill covers implementing Gitleaks for detecting and preventing hardcoded secrets in git repositories.

When should I use Implementing Secret Scanning With Gitleaks?

Implementing Secret Scanning With Gitleaks fits situations like: tasks that involve Secrets management.

How do I install Implementing Secret Scanning With Gitleaks in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-secret-scanning-with-gitleaks -a claude-code`. Or copy the skill folder (skills/implementing-secret-scanning-with-gitleaks in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/implementing-secret-scanning-with-gitleaks in your project. Claude Code loads it when a task matches its description.

How do I install Implementing Secret Scanning With Gitleaks in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-secret-scanning-with-gitleaks -a codex`. Or copy the skill folder (skills/implementing-secret-scanning-with-gitleaks in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/implementing-secret-scanning-with-gitleaks in your project. Codex loads it when a task matches its description.

Can I use Implementing Secret Scanning With Gitleaks in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill implementing-secret-scanning-with-gitleaks -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/implementing-secret-scanning-with-gitleaks, .gemini/skills/implementing-secret-scanning-with-gitleaks, .github/skills/implementing-secret-scanning-with-gitleaks and .opencode/skills/implementing-secret-scanning-with-gitleaks in your project.

What does Implementing Secret Scanning With Gitleaks need to run?

Going by SKILL.md and its folder, Implementing Secret Scanning With Gitleaks needs Python for the scripts in its folder, the command-line tools its instructions call (gitleaks, git, pip, brew and python3) and credentials named GITHUB_TOKEN, AWS_SECRET_ACCESS_KEY and REDACTED_AWS_KEY. Our summary lists: Python 3; Docker; A credential in AWS_SECRET_ACCESS_KEY; A credential in GITHUB_TOKEN.

Does Implementing Secret Scanning With Gitleaks access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Implementing Secret Scanning With Gitleaks safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Implementing Secret Scanning With Gitleaks use?

Implementing Secret Scanning With Gitleaks is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Implementing Secret Scanning With Gitleaks use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3k tokens, read only when the agent opens those files.

What are the alternatives to Implementing Secret Scanning With Gitleaks?

Skills that share tags, products or a category with Implementing Secret Scanning With Gitleaks: Secrets Gitleaks (AgentSecOps/SecOpsAgentKit, 220 stars), Private Secret Scanning (jamditis/claude-skills-journalism, 416 stars), KubeSphere DevOps Credentials (kubesphere/kubesphere, 17k stars) and Dotenvx Secrets (kortix-ai/suna, 20k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Implementing Secret Scanning With Gitleaks?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 34,116 GitHub stars. The repository holds 644 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.