Sicurezza GitHub
ccplugins/awesome-claude-code-plugins
Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot.
Triage, redact, clean up, and resolve OpenClaw GitHub Secret Scanning alerts in issues or PRs.
$ npx skills add openclaw/openclaw --skill openclaw-secret-scanning-maintainer -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install openclaw/openclaw openclaw-secret-scanning-maintainer --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/openclaw-secret-scanning-maintainer .claude/skills/openclaw-secret-scanning-maintainer && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "openclaw-secret-scanning-maintainer" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/openclaw-secret-scanning-maintainer into .claude/skills/openclaw-secret-scanning-maintainer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openclaw-secret-scanning-maintainer", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/openclaw/openclaw/tree/main/.agents/skills/openclaw-secret-scanning-maintainerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add openclaw/openclaw --skill openclaw-secret-scanning-maintainer -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install openclaw/openclaw openclaw-secret-scanning-maintainer --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.agents/skills/openclaw-secret-scanning-maintainer .agents/skills/openclaw-secret-scanning-maintainer && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "openclaw-secret-scanning-maintainer" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/openclaw-secret-scanning-maintainer into .agents/skills/openclaw-secret-scanning-maintainer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openclaw-secret-scanning-maintainer", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openclaw/openclaw --skill openclaw-secret-scanning-maintainer -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install openclaw/openclaw openclaw-secret-scanning-maintainer --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.agents/skills/openclaw-secret-scanning-maintainer .cursor/skills/openclaw-secret-scanning-maintainer && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "openclaw-secret-scanning-maintainer" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/openclaw-secret-scanning-maintainer into .cursor/skills/openclaw-secret-scanning-maintainer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openclaw-secret-scanning-maintainer", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/openclaw/openclaw.git --path .agents/skills/openclaw-secret-scanning-maintainer--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add openclaw/openclaw --skill openclaw-secret-scanning-maintainer -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install openclaw/openclaw openclaw-secret-scanning-maintainer --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.agents/skills/openclaw-secret-scanning-maintainer .gemini/skills/openclaw-secret-scanning-maintainer && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "openclaw-secret-scanning-maintainer" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/openclaw-secret-scanning-maintainer into .gemini/skills/openclaw-secret-scanning-maintainer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openclaw-secret-scanning-maintainer", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install openclaw/openclaw openclaw-secret-scanning-maintainerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add openclaw/openclaw --skill openclaw-secret-scanning-maintainer -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .github/skills && cp -r skills-src/.agents/skills/openclaw-secret-scanning-maintainer .github/skills/openclaw-secret-scanning-maintainer && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "openclaw-secret-scanning-maintainer" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/openclaw-secret-scanning-maintainer into .github/skills/openclaw-secret-scanning-maintainer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openclaw-secret-scanning-maintainer", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add openclaw/openclaw --skill openclaw-secret-scanning-maintainer -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install openclaw/openclaw openclaw-secret-scanning-maintainer --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/openclaw/openclaw.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.agents/skills/openclaw-secret-scanning-maintainer .opencode/skills/openclaw-secret-scanning-maintainer && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "openclaw-secret-scanning-maintainer" agent skill from https://github.com/openclaw/openclaw/tree/main/.agents/skills/openclaw-secret-scanning-maintainer into .opencode/skills/openclaw-secret-scanning-maintainer/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "openclaw-secret-scanning-maintainer", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
openclaw-secret-scanning-maintainerTriage, redact, clean up, and resolve OpenClaw GitHub Secret Scanning alerts in issues or PRs.
Openclaw Secret Scanning Maintainer is an agent skill from openclaw/openclaw. Triage, redact, clean up, and resolve OpenClaw GitHub Secret Scanning alerts in issues or PRs.
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts.
It sits in DevOps & Cloud, covering Secrets management. It works with GitHub. The repository describes itself as: The AI that really does things. Any OS. Any Platform. The lobster way. 🦞. The licence is MIT.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 5843d60. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (JavaScript), which the agent can run.
Shell commands in SKILL.md call:
nodeFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
support.github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Openclaw Secret Scanning Maintainer loads about 2.5k tokens when it runs. Until then it costs about 33 tokens; SKILL.md has 948 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from openclaw/openclaw at commit 5843d60, republished under its MIT licence (© openclaw). 948 words, ~2,500 tokens.
.claude/skills/openclaw-secret-scanning-maintainer/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Maintainer-only. This skill requires repo admin / maintainer permissions to edit or delete other users' comments and resolve secret scanning alerts.
Use this skill when processing alerts from https://github.com/openclaw/openclaw/security/secret-scanning.
Language rule: All notification comments and replacement comments MUST be written in English.
All mechanical operations (API calls, temp file management, security enforcements) are handled by:
$REPO_ROOT/.agents/skills/openclaw-secret-scanning-maintainer/scripts/secret-scanning.mjsThe script enforces:
hide_secret=true on all alert fetches (no plaintext secrets in stdout)mktemp with random UUIDs for all temp files-F body=@file for all body uploads (no inline shell quoting).secret or .body to stdoutSupports single or multiple alerts. For multiple alerts, process in ascending order.
For each alert:
fetch-alert + fetch-content to get metadata and bodyredact-body-if-needed for issue/PR body; skip for comments (delete directly)delete-comment + recreate-comment for comments; cannot purge body historynotify posts the right template per location type, unless the current issue/PR body is already redactedresolve closes the alertsummary prints formatted results# List all open alerts
node secret-scanning.mjs list-open
# Fetch specific alert metadata + locations
node secret-scanning.mjs fetch-alert <NUMBER>
# Fetch content for each location (saves body to temp file)
node secret-scanning.mjs fetch-content '<location-json>'The fetch-content output includes:
body_file: path to temp file with full body contentauthor: who posted itissue_number / pr_number: where it isedit_history_count: number of existing editstype: location type for routingdiscussion_comment, it also includes comment_node_id, discussion_node_id, and reply_to_node_id when the original comment was a reply.| type | Flow |
|---|---|
issue_comment | Comment: delete+recreate |
pull_request_comment | Comment: delete+recreate |
pull_request_review_comment | Comment: delete+recreate |
discussion_comment | Discussion comment: delete+recreate (GraphQL) |
issue_body | Body: redact in place |
pull_request_body | Body: redact in place |
commit | Notify only |
| other | Skip and report |
The agent reads the body file from fetch-content output and:
[REDACTED <secret_type>] — no partial values, no prefix/suffixThis is the only step that requires semantic understanding. Everything else is mechanical.
For issue_body and pull_request_body: if the current body has already been redacted by the author and no plaintext credential remains, do not post a public notification comment. Resolve the alert with a maintainer-only resolution comment such as:
node secret-scanning.mjs resolve <ALERT_NUMBER> revoked "Current issue/PR body is already redacted; no public notification posted."This avoids creating a fresh public pointer to historical sensitive content.
Do NOT redact. Skip directly to Step 4 (delete + recreate). PATCHing before DELETE creates an unnecessary edit history revision.
node secret-scanning.mjs redact-body-if-needed <issue|pr> <NUMBER> <current-body-file> <redacted-body-file> <result-file>Use the body_file from fetch-content as <current-body-file>. The command writes notify_required to <result-file> and only PATCHes the body when the redacted file differs from the current body.
For issue/PR comments:
# Delete original (all edit history gone)
node secret-scanning.mjs delete-comment <COMMENT_ID>
# Recreate with redacted content
node secret-scanning.mjs recreate-comment <ISSUE_NUMBER> <body-file>For discussion comments (uses GraphQL):
# Delete original
node secret-scanning.mjs delete-discussion-comment <COMMENT_NODE_ID>
# Recreate with redacted content
node secret-scanning.mjs recreate-discussion-comment <DISCUSSION_NODE_ID> <body-file> [REPLY_TO_NODE_ID]The fetch-content output for discussion_comment includes comment_node_id and discussion_node_id for these commands. When the original discussion comment was a reply, it also includes reply_to_node_id; pass that optional third argument so the redacted replacement stays in the original thread.
The recreated comment should follow this format:
> **Note:** The original comment by @<AUTHOR> has been removed due to secret leakage. Below is the redacted version of the original content.
---
<redacted original content>Editing creates an edit history revision with the pre-edit plaintext. This cannot be cleared via API.
Do not advise authors publicly to delete/recreate issues or close/reopen PRs. That can draw attention to historical content. Keep purge guidance maintainer-only.
Output to maintainer terminal only (never in public comments):
⚠️ Issue/PR body edit history still contains plaintext secrets.
Contact GitHub Support to purge: https://support.github.com/contact
Request purge of issue/PR #{NUMBER} userContentEdits.CRITICAL: Do NOT mention edit history or the "edited" button in any public comment or resolution_comment.
Cannot clean. Notify author to delete branch or force-push (for unmerged PRs).
node secret-scanning.mjs notify <TARGET> <AUTHOR> <LOCATION_TYPE> <SECRET_TYPES> [REPLY_TO_NODE_ID|BODY_REDACTION_RESULT_FILE]<TARGET> is the issue/PR number.discussion_comment, <TARGET> is the discussion_node_id returned by fetch-content.discussion_comment locations, pass the optional reply_to_node_id from fetch-content so the notification stays in the same thread.issue_body and pull_request_body, pass the <result-file> from redact-body-if-needed. The script skips notification when notify_required is false and refuses body notifications without this file.Secret types are comma-separated: "Discord Bot Token,Feishu App Secret"
The script picks the right template:
For issue_body and pull_request_body, only notify when the current body still contained plaintext and maintainers redacted it. If the user already redacted the current body, skip this step and resolve silently.
node secret-scanning.mjs resolve <ALERT_NUMBER>
# or with custom resolution:
node secret-scanning.mjs resolve <ALERT_NUMBER> revoked "Custom comment"Resolution is revoked by default. As maintainers we cannot control whether users rotate — our responsibility is to remove current plaintext exposure and notify only when public notification is useful. The revoked means "this secret should be considered leaked", not "I confirmed it was revoked".
After processing, create a JSON results file and pass it to the summary command:
node secret-scanning.mjs summary /tmp/results.jsonThe script outputs a block delimited by ---BEGIN SUMMARY--- and ---END SUMMARY---. You MUST output the content between these markers verbatim to the user. Do NOT rephrase, reformat, abbreviate, or create your own summary. The script already includes full URLs for every alert and location.
The JSON format:
[
{
"number": 72,
"secret_type": "Discord Bot Token",
"location_label": "Issue #63101 comment",
"location_url": "https://github.com/openclaw/openclaw/issues/63101#issuecomment-xxx",
"actions": "Deleted+Recreated+Notified",
"history_cleared": true
}
]For unsupported types, add "skipped": true, "unsupported_type": "<type>".
© openclaw, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (scripts) in .agents/skills/openclaw-secret-scanning-maintainer of openclaw/openclaw.
Open the folder on GitHubat commit 5843d60
Openclaw Secret Scanning Maintainer next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Openclaw Secret Scanning Maintainer this skillopenclaw/openclaw | 392k | — | ~2.5k | Automated safety check: Pass | MIT | |
| Sicurezza GitHubccplugins/awesome-claude-code-plugins | 970 | — | ~486 | Automated safety check: Notes | Apache-2.0 | |
| Secure GitHub Actionsvechain/x-app-template | 450 | — | ~1.2k | Automated safety check: Pass | MIT | |
| Private Secret Scanningjamditis/claude-skills-journalism | 416 | — | ~1.8k | Automated safety check: Pass | MIT | |
| Deploy To Hostinghostinger/api-mcp-server | 160 | — | ~2.7k | Automated safety check: Notes | MIT | |
| Secrets Managementdavila7/claude-code-templates | 33k | 12 repos | ~2k | Automated safety check: Pass | MIT |
ccplugins/awesome-claude-code-plugins
Aggiunge alle repository GitHub dei siti workflow di sicurezza automatici - scansione dipendenze vulnerabili, ricerca di segreti/chiavi nel codice, analisi statica CodeQL e Dependabot.
vechain/x-app-template
Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.
jamditis/claude-skills-journalism
Local Gitleaks scans for staged changes, push ranges, and full history in private repos, with redacted reports.
hostinger/api-mcp-server
Deploy an existing project to a website on Hostinger web hosting (Shared, Cloud or Agency plans) and keep it deployed: picks the right deploy for static sites, Node.js apps (Next.js, Nuxt, Express…
davila7/claude-code-templates
Secure secrets management practices for CI/CD pipelines using Vault, AWS Secrets Manager, and other tools.
github/awesome-copilot
Guide for configuring and managing GitHub secret scanning, push protection, custom patterns, and secret alert remediation.
openclaw/openclaw
Summarize CodexBar local cost logs by model for Codex or Claude, including current or full breakdowns.
openclaw/openclaw
Maintain the canonical live OpenClaw main checkout, macOS LaunchAgent-managed Gateway, local macOS app, exact-head main CI, and recurring full release validation.
openclaw/openclaw
Feishu document read/write workflows. An agent skill from openclaw/openclaw.
openclaw/openclaw
Control tmux sessions/panes for interactive CLIs: list, capture output, send keys, paste text, monitor prompts.
openclaw/openclaw
Review, triage, repair, or land OpenClaw issues and pull requests with current-source evidence and the native maintainer workflow.
openclaw/openclaw
A skill your agent uses when controlling web pages with the OpenClaw browser tool, especially multi-step flows, login checks, tab management, or recovery from stale refs/timeouts.
Works with
Categories
Triage, redact, clean up, and resolve OpenClaw GitHub Secret Scanning alerts in issues or PRs. Openclaw Secret Scanning Maintainer is an agent skill from openclaw/openclaw. Triage, redact, clean up, and resolve OpenClaw GitHub Secret Scanning alerts in issues or PRs.
Openclaw Secret Scanning Maintainer fits situations like: tasks that involve Secrets management.
Run `npx skills add openclaw/openclaw --skill openclaw-secret-scanning-maintainer -a claude-code`. Or copy the skill folder (.agents/skills/openclaw-secret-scanning-maintainer in openclaw/openclaw) into .claude/skills/openclaw-secret-scanning-maintainer in your project. Claude Code loads it when a task matches its description.
Run `npx skills add openclaw/openclaw --skill openclaw-secret-scanning-maintainer -a codex`. Or copy the skill folder (.agents/skills/openclaw-secret-scanning-maintainer in openclaw/openclaw) into .agents/skills/openclaw-secret-scanning-maintainer in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add openclaw/openclaw --skill openclaw-secret-scanning-maintainer -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/openclaw-secret-scanning-maintainer, .gemini/skills/openclaw-secret-scanning-maintainer, .github/skills/openclaw-secret-scanning-maintainer and .opencode/skills/openclaw-secret-scanning-maintainer in your project.
Going by SKILL.md and its folder, Openclaw Secret Scanning Maintainer needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node). Our summary lists: Node.js.
SKILL.md names 1 domain. In commands or code: support.github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Openclaw Secret Scanning Maintainer is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Openclaw Secret Scanning Maintainer: Sicurezza GitHub (ccplugins/awesome-claude-code-plugins, 970 stars), Secure GitHub Actions (vechain/x-app-template, 450 stars), Private Secret Scanning (jamditis/claude-skills-journalism, 416 stars) and Deploy To Hosting (hostinger/api-mcp-server, 160 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
openclaw (a GitHub organization) maintains it in openclaw/openclaw, which has 391,658 GitHub stars. The repository holds 97 skills in this directory. The repository was last updated on October 11, 2026.
Source: openclaw/openclaw on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.