Agent skill

Secret Scan

by SpecterOps in SpecterOps/skills

Scan repositories and codebases for exposed secrets, credentials, and sensitive data.

Apache-2.0Auto-check passed

Install Secret Scan

skills CLI
$ npx skills add SpecterOps/skills --skill secret-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SpecterOps/skills secret-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SpecterOps/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/ops-appsec/skills/secret-scan .claude/skills/secret-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
secret-scan
GitHub stars
704
Token cost
~948 tokens
SKILL.md length
247 words
Files
4 (incl. assets)
Skills in repo
38
Repo updated
First seen
Licence
Apache-2.0

At a glance

Scan repositories and codebases for exposed secrets, credentials, and sensitive data.

  • Works in 3 steps: trufflehog (preferred) → gitleaks → manual grep-based fallback
  • GitHub repo/org/user scans
  • SKILL.md covers Input Parsing, Execution Policy, Tool Preference and Workflow, plus 4 more sections
  • Calls gh, gitleaks and git; reaches github.com

What it does

Secret Scan is an agent skill from SpecterOps/skills. Scan repositories and codebases for exposed secrets, credentials, and sensitive data. Use for GitHub repo/org/user scans, local code scans, and secret-discovery triage with optional command execution.

Its SKILL.md is about 950 tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including assets (for example `agents/openai.yaml`).

It works with GitHub. The repository describes itself as: A marketplace for LLM skills. The licence is Apache-2.0.

When your agent uses it

  • GitHub repo/org/user scans
  • Local code scans
  • Secret-discovery triage with optional command execution

Example prompts

  • “/secret-scan”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. trufflehog (preferred)
  2. gitleaks
  3. manual grep-based fallback

What it can do on your machine

Read from SKILL.md and the folder at commit e655f93. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gh
    • gitleaks
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Secret Scan loads about 948 tokens when it runs. Until then it costs about 53 tokens; SKILL.md has 247 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~53
When it runs · the whole SKILL.md, loaded when a task matches
~948

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from SpecterOps/skills at commit e655f93, republished under its Apache-2.0 licence (© SpecterOps). 247 words, ~948 tokens.

Download SKILL.mdSave it as .claude/skills/secret-scan/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
secret-scan
description
Scan repositories and codebases for exposed secrets, credentials, and sensitive data. Use for GitHub repo/org/user scans, local code scans, and secret-discovery triage with optional command execution.
metadata.author
GhostWorks

Secret Scan

Identify exposed secrets and sensitive material in approved targets.

Input Parsing

Accept input as: ACTION TARGET [MODE]

Actions:

  • repo <owner/repo>
  • org <org-name>
  • user <username>
  • dork <search phrase>
  • local <path>

Modes:

  • plan: recommendations + command set only
  • execute (default, preferred): run commands and report evidence

If mode is omitted, default to execute.

Examples:

  • $secret-scan repo owner/repo
  • $secret-scan org acme-corp execute
  • $secret-scan local ./src execute
  • $secret-scan dork "Acme Corp"

Execution Policy

  • Always generate a plan first.
  • In execute mode, run routine in-scope command batches autonomously.
  • Request approval only for OPSEC-dangerous command batches.
  • Only scan authorized targets provided by the user.
  • Capture exact commands and key output evidence in the report.

Tool Preference

  1. trufflehog (preferred)
  2. gitleaks
  3. manual grep-based fallback

Check availability:

bash
which trufflehog
which gitleaks
which gh

Workflow

  1. Create output directory:
    • mkdir -p recon/secret-scan/
  2. Build a target-specific command plan.
  3. In execute mode:
    • run routine in-scope commands autonomously,
    • request approval only for OPSEC-dangerous steps,
    • collect outputs and triage.
  4. Produce findings with severity and confidence labels.
  5. Save report to:
    • recon/secret-scan/<target-slug>-report.md

Command Patterns

repo
bash
# Preferred
trufflehog github --repo=https://github.com/<owner/repo> --only-verified --json

# Alternative
git clone --mirror https://github.com/<owner/repo> /tmp/secret-scan-target
gitleaks detect --source /tmp/secret-scan-target --report-format json --report-path recon/secret-scan/gitleaks.json
org
bash
gh repo list <org> --public --limit 200 --json name,url,pushedAt
trufflehog github --org=<org> --only-verified --json
user
bash
gh repo list <user> --public --limit 100 --json name,url,pushedAt
dork
bash
gh search code "<query>" --limit 20 --json repository,path,textMatches
local
bash
trufflehog filesystem <path> --json
# or
gitleaks detect --source <path> --report-format json --report-path recon/secret-scan/gitleaks-local.json
manual fallback patterns
bash
grep -RInE 'AKIA[0-9A-Z]{16}|BEGIN [A-Z ]*PRIVATE KEY|api[_-]?key|token|password\\s*[:=]' <path>
grep -RInE 'mongodb(\\+srv)?://|postgres(ql)?://|mysql://|redis://|amqp://' <path>

Triage Rules

  • Confirm whether value appears live/real vs placeholder/test string.
  • Prioritize:
    1. active credentials and tokens,
    2. private keys/certs,
    3. database connection strings,
    4. internal endpoints and sensitive config.
  • Avoid publishing raw secret values in final report unless explicitly required; use redaction where possible.

Output Format

markdown
# Secret Scan Report ? <target>
## Action: <repo|org|user|dork|local>
## Mode: <plan|execute>

## Executive Summary
- High-level findings and risk.

## Commands
- exact command
- execution status

## Findings
- secret type
- location (file/path/repo + line)
- confidence
- impact
- recommended response (rotate/revoke/remove/history rewrite)

## Next Steps
1. immediate containment
2. cleanup and hardening
3. verification rerun

Quality Rules

  • Keep findings evidence-based and reproducible.
  • Separate confirmed secrets from unverified candidates.
  • Include exact commands and output snippets for all executed steps.

© SpecterOps, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (assets) in plugins/ops-appsec/skills/secret-scan of SpecterOps/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/icon.png
  • assets/icon.svg

Open the folder on GitHubat commit e655f93

Compare with similar skills

Secret Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Secret Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Secret Scan this skillSpecterOps/skills704—~948Automated safety check: PassApache-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Diagnosing Superpowers Sessionsobra/superpowers297k3 repos~1.7kAutomated safety check: PassMIT
Greplooponyx-dot-app/onyx32k4 repos~3.3kAutomated safety check: PassMIT
GitHub Deep Researchbytedance/deer-flow84k4 repos~1.3kAutomated safety check: PassMIT
Update V8 Versionopeninterpreter/openinterpreter69k2 repos~845Automated safety check: PassApache-2.0

Similar skills

  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Investigates a session where Superpowers went wrong, reads the transcripts on disk and produces an evidence-cited report, optionally prepared as a bug report for the maintainers.

    297k GitHub starsUsed in 3 repos~1.7k tokens
    Agent WorkflowsAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed
  • GitHub Deep Research

    bytedance/deer-flow

    Researches a GitHub repository over four rounds using the GitHub API and web search, then writes a structured markdown report with timeline, metrics and Mermaid diagrams.

    84k GitHub starsUsed in 4 repos~1.3k tokens
    Research & ScienceAuto-check passed
  • Update V8 Version

    openinterpreter/openinterpreter

    Bumps the pinned v8 and rusty_v8 versions in Codex, validates the release-candidate path with the v8-canary check, and traces failures to upstream build changes.

    69k GitHub starsUsed in 2 repos~845 tokens
    DevOps & CloudAuto-check passed
  • Last30days

    mvanhorn/last30days-skill

    Research what people actually say about any topic in the last 30 days.

    64k GitHub stars~7.9k tokensUpdated today
    Research & ScienceAuto-check: notes

More from SpecterOps/skills

All 38 skills in this repo
  • Codex Activity Report

    SpecterOps/skills

    Generate a normalized UTC timeline and evidence-based narrative from Codex activity artifacts.

    704 GitHub stars~805 tokensUpdated 15 days ago
    Auto-check passed
  • Com Proxy Triage

    SpecterOps/skills

    A skill your agent uses when the user wants to triage Windows COM proxy/hijack candidates by capturing HKCU\Software\Classes\CLSID\{...}\InProcServer32 NAME NOT FOUND lookups for a process, mapping…

    704 GitHub stars~1.5k tokensUpdated 15 days ago
    Auto-check passed
  • Cwe Code Review

    SpecterOps/skills

    Perform CWE-grounded security code reviews and precise weakness mapping using a locally derived MITRE CWE corpus, relationship graphs, mapping notes, detection methods, mitigations, and schema…

    704 GitHub stars~2.4k tokensUpdated 15 days ago
    Auto-check passed
  • Ghostwriter Oplog

    SpecterOps/skills

    A skill your agent uses for Ghostwriter operation log entries from Codex, including config guidance, quick notes, evidence-backed entries, and guided oplog capture through the Ghostwriter MCP tools.

    704 GitHub stars~665 tokensUpdated 15 days ago
    Auto-check passed
  • Nmap Parse

    SpecterOps/skills

    Parse nmap scan output and generate actionable recon notes. An agent skill from SpecterOps/skills.

    704 GitHub stars~738 tokensUpdated 15 days ago
    Auto-check passed
  • Osint Recon

    SpecterOps/skills

    Perform OSINT and external reconnaissance for approved targets.

    704 GitHub stars~813 tokensUpdated 15 days ago
    Auto-check passed

Works with

Questions about Secret Scan

What does Secret Scan do?

Scan repositories and codebases for exposed secrets, credentials, and sensitive data. Secret Scan is an agent skill from SpecterOps/skills. Scan repositories and codebases for exposed secrets, credentials, and sensitive data.

When should I use Secret Scan?

Secret Scan fits situations like: GitHub repo/org/user scans; local code scans; secret-discovery triage with optional command execution.

How do I install Secret Scan in Claude Code?

Run `npx skills add SpecterOps/skills --skill secret-scan -a claude-code`. Or copy the skill folder (plugins/ops-appsec/skills/secret-scan in SpecterOps/skills) into .claude/skills/secret-scan in your project. Claude Code loads it when a task matches its description.

How do I install Secret Scan in Codex?

Run `npx skills add SpecterOps/skills --skill secret-scan -a codex`. Or copy the skill folder (plugins/ops-appsec/skills/secret-scan in SpecterOps/skills) into .agents/skills/secret-scan in your project. Codex loads it when a task matches its description.

Can I use Secret Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SpecterOps/skills --skill secret-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/secret-scan, .gemini/skills/secret-scan, .github/skills/secret-scan and .opencode/skills/secret-scan in your project.

What does Secret Scan need to run?

Going by SKILL.md and its folder, Secret Scan needs the command-line tools its instructions call (gh, gitleaks and git).

Does Secret Scan access the network?

SKILL.md names 1 domain. In commands or code: github.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Secret Scan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Secret Scan use?

Secret Scan is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Secret Scan use?

About 948 tokens (SKILL.md is roughly 3.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Secret Scan?

Skills that share tags, products or a category with Secret Scan: PR Babysitter (openinterpreter/openinterpreter, 69k stars), Diagnosing Superpowers Sessions (obra/superpowers, 297k stars), Greploop (onyx-dot-app/onyx, 32k stars) and GitHub Deep Research (bytedance/deer-flow, 84k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Secret Scan?

SpecterOps (a GitHub organization) maintains it in SpecterOps/skills, which has 704 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on September 23, 2026.

Source: SpecterOps/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.