Agent skill

GitHub Secret Hunting

by uphiago in uphiago/recon-skills

Find leaked API keys, tokens, and credentials in public GitHub repositories.

MITAuto-check: warningsSecurity

Install GitHub Secret Hunting

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add uphiago/recon-skills --skill github-secret-hunting -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install uphiago/recon-skills github-secret-hunting --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/recon/github-secret-hunting .claude/skills/github-secret-hunting && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
github-secret-hunting
GitHub stars
1.3k
Token cost
~1.8k tokens
SKILL.md length
345 words
Files
1
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

Find leaked API keys, tokens, and credentials in public GitHub repositories.

  • Works in 7 steps: Targeted Dorking with GitDorker → TruffleHog Deep Scanning → Real-Time Monitoring with shhgit → …
  • Tasks that involve Secrets management
  • SKILL.md covers When to Use, Prerequisites, Quick Detection and Procedure, plus 3 more sections
  • Calls curl, python3 and jq; reaches api.github.com and github.com; needs GITHUB_TOKEN and DB_PASSWORD

What it does

GitHub Secret Hunting is an agent skill from uphiago/recon-skills. Find leaked API keys, tokens, and credentials in public GitHub repositories.

Its SKILL.md is about 1.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires curl, httpx, python3

It sits in Security, covering Secrets management. It works with GitHub. The repository describes itself as: Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh. The licence is MIT.

When your agent uses it

  • Tasks that involve Secrets management

Example prompts

  • “/github-secret-hunting”

Requirements

  • Python 3
  • Docker
  • A credential in GITHUB_TOKEN
  • A credential in GITLAB_TOKEN
  • Compatibility (from SKILL.md): Requires curl, httpx, python3

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Targeted Dorking with GitDorker
  2. TruffleHog Deep Scanning
  3. Real-Time Monitoring with shhgit
  4. File Type and Extension Search
  5. Hardcoded Credential Verification
  6. GitLab Private Instances
  7. Metadata Extraction from Public Documents

What it can do on your machine

Read from SKILL.md and the folder at commit 1260244. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • python3
    • jq
    • git
    • docker
    • gitleaks

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.github.com
    • github.com
    • api.openai.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN
    • DB_PASSWORD
    • GITLAB_TOKEN
    • AWS_ACCESS_KEY_ID

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires curl, httpx, python3

    From compatibility in the SKILL.md frontmatter.

Context cost

GitHub Secret Hunting loads about 1.8k tokens when it runs. Until then it costs about 25 tokens; SKILL.md has 345 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~25
When it runs · the whole SKILL.md, loaded when a task matches
~1.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:113
    filename:config.json api_key" "filename:id_rsa" \
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:114
    "filename:.npmrc" "extension:pem BEGIN RSA" \
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:175
    l leaks.** Focus on `.env`, `.config`, `.npmrc`, and CI/CD workflow files.
  • NoteMentions a .env fileSKILL.md:193
    eak-hunt`** — Find exposed config files (.env, .git) on live web servers.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from uphiago/recon-skills at commit 1260244, republished under its MIT licence (© uphiago). 345 words, ~1,840 tokens.

Download SKILL.mdSave it as .claude/skills/github-secret-hunting/SKILL.md (or your agent's skills folder).
name
github-secret-hunting
description
Find leaked API keys, tokens, and credentials in public GitHub repositories.
compatibility
Requires curl, httpx, python3
version
1.1.0
revision_date
2026-07-25
license
MIT
platforms
linux
tags
recon, github, secret, API-key, token, dork, OSINT, trufflehog, credential
category
recon
related_skills
js-secrets-extraction, hardcoded-credential-hunt, source-leak-hunt

GitHub Secret Hunting

Scan public GitHub repositories for leaked API keys, tokens, passwords, and internal infrastructure details. Developers accidentally push secrets constantly — this skill uses targeted dorking, automated scanning tools, and real-time monitoring to find credentials before the developer notices and revokes them.

When to Use

  • Target has public repositories under an organization account.
  • JS bundle analysis reveals internal service names — search GitHub for related config files.
  • Need to find valid API keys for cloud services, payment gateways, or third-party integrations.
  • The target uses CI/CD systems that may leak tokens in build logs or workflow files.
  • Want real-time monitoring for new secret leaks from the target org.

Prerequisites

  • terminal with python3, curl, git.
  • GitHub Personal Access Token (only public_repo scope needed).
  • Tool dependencies: TruffleHog, GitDorker, gitleaks.

Quick Detection

bash
# Basic GitHub code search for sensitive patterns in target repos
echo "target.com" | while read domain; do
  curl --max-time 30 --connect-timeout 10 -s -H "Authorization: token $GITHUB_TOKEN" \
    "https://api.github.com/search/code?q=$domain+filename:.env" \
    | jq '.items[]?.html_url'
done

Procedure

Phase 1 — Targeted Dorking with GitDorker
bash
# Clone the dork collection and run against target
git clone https://github.com/Proviesec/github-dorks
python3 GitDorker.py \
  -tf $GITHUB_TOKEN \
  -q target.com \
  -d dorks/medium_dorks.txt \
  -o gitdorker_target.txt

# Also search by employee emails found in LinkedIn or metadata
python3 GitDorker.py \
  -tf $GITHUB_TOKEN \
  -q "john.doe@target.com" \
  -d dorks/medium_dorks.txt

# Custom dork: find env files
python3 GitDorker.py -tf $GITHUB_TOKEN \
  -q "org:target filename:.env DB_PASSWORD" -d dorks/medium_dorks.txt
Phase 2 — TruffleHog Deep Scanning
bash
# Scan a specific repo (finds secrets even in deleted commits)
trufflehog git https://github.com/target/repo --results=verified

# Scan entire GitHub org
trufflehog github --org=target --token=$GITHUB_TOKEN \
  --only-verified --threads=20 --json > trufflehog_org.json

# Docker variant
docker run --rm -it trufflesecurity/trufflehog:latest \
  github --only-verified --org=target

# Parse verified secrets
cat trufflehog_org.json | jq -r 'select(.Verified == true) | "\(.DetectorName): \(.RawV2)"'
Phase 3 — Real-Time Monitoring with shhgit
bash
# Monitor globally for secrets being pushed right now
shhgit --search-query \
  'path:*.env OR "DB_PASSWORD=" OR "AWS_ACCESS_KEY_ID=" OR "-----BEGIN RSA PRIVATE KEY-----"'

# Monitor specific org
shhgit --search-query \
  'target.com (path:*.env OR "DB_PASSWORD=" OR "api_key=")'
bash
# git-wild-hunt: find specific file types
python3 git-wild-hunt.py \
  -s "org:Target extension:json filename:creds language:JSON"
python3 git-wild-hunt.py \
  -s "org:Target extension:sql filename:backup"
python3 git-wild-hunt.py \
  -s "target.com gitlab_token"

# Manual search patterns via GitHub API
for pattern in "filename:.env DB_PASSWORD" "filename:credentials.json" \
               "filename:config.json api_key" "filename:id_rsa" \
               "filename:.npmrc" "extension:pem BEGIN RSA" \
               "filename:service-account.json"; do
  curl --max-time 30 --connect-timeout 10 -s -H "Authorization: token $GITHUB_TOKEN" \
    "https://api.github.com/search/code?q=target.com+$pattern" \
    | jq '.total_count, (.items[:3][].html_url)'
done
Phase 5 — Hardcoded Credential Verification
bash
# Pipeline: find → extract → verify
echo "target.com" | gau | grep -E '\.js$|\.json$|\.env$|\.config$' \
  | httpx -silent -mc 200 \
  | parallel -j 10 "curl --max-time 30 --connect-timeout 10 -s {} | grep -Eo \
    '(?:api[_-]?key|secret|token)[\"'\''']?\s*[:=]\s*[\"'\''']?([A-Za-z0-9_\-]{20,})' \
    | tee -a api_keys.txt"

# Verify found keys
for key in $(cat api_keys.txt | awk -F':' '{print $2}' | tr -d '"'\'' ' | sort -u); do
  # OpenAI
  curl --max-time 30 --connect-timeout 10 -s "https://api.openai.com/v1/models" -H "Authorization: Bearer $key" | jq '.data[].id' 2>/dev/null && echo "VALID OPENAI: $key"
  # GitHub
  curl --max-time 30 --connect-timeout 10 -s "https://api.github.com/user" -H "Authorization: token $key" | jq '.login' 2>/dev/null && echo "VALID GITHUB: $key"
done
Phase 6 — GitLab Private Instances
bash
# Discover self-hosted GitLab
# Check: gitlab.target.com, git.target.com, code.target.com
curl --max-time 30 --connect-timeout 10 -sk "https://gitlab.target.com/api/v4/projects?visibility=public"

# With a found token
curl --max-time 30 --connect-timeout 10 --header "PRIVATE-TOKEN: $GITLAB_TOKEN" \
  "https://gitlab.target.com/api/v4/user"
curl --max-time 30 --connect-timeout 10 --header "PRIVATE-TOKEN: $GITLAB_TOKEN" \
  "https://gitlab.target.com/api/v4/projects?membership=true&simple=true"

# Deep scan for secrets across accessible repos
gitleaks detect \
  --source https://gitlab.target.com \
  --access-token $GITLAB_TOKEN -v
Phase 7 — Metadata Extraction from Public Documents
bash
# metafinder: downloads public documents and extracts metadata
# Reveals usernames, software versions, internal file paths, email patterns
metafinder -d "target.com" -l 10 -go -bi -ba -o metadata_target.txt
metafinder -d "dev.target.com" -l 10 -go -bi -ba -o metadata_dev.txt

# Manual: check PDF metadata
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/document.pdf" -o doc.pdf
exiftool doc.pdf | grep -i "author\|creator\|producer"

Pitfalls

  • Most search results are documentation and examples, not real leaks. Focus on .env, .config, .npmrc, and CI/CD workflow files.
  • Rate limiting on GitHub API is strict. Use multiple tokens or rotate IPs.
  • Verified secrets may already be revoked. Always verify before reporting.
  • Self-hosted GitLab instances may block external scanning. Test connectivity first.
  • Never use found credentials for unauthorized access. Verify minimally, document, and report.

Verification

  1. TruffleHog or GitDorker identifies a potential secret with context.
  2. Verify the secret by making a minimal API call (e.g., GET /user for GitHub tokens).
  3. Confirm the secret was committed recently (check commit date) — stale secrets are lower priority.
  4. Check if the repo is public and the secret grants meaningful access (admin vs read-only).
  5. Document the exact file path, commit hash, and line number for the report.
  • js-secrets-extraction — Find API keys and endpoints in JavaScript bundles that may lead to GitHub repos.
  • hardcoded-credential-hunt — Detect hardcoded passwords in HTML, JS, and API responses.
  • source-leak-hunt — Find exposed config files (.env, .git) on live web servers.

© uphiago, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in recon/github-secret-hunting of uphiago/recon-skills.

Open the folder on GitHubat commit 1260244

Compare with similar skills

GitHub Secret Hunting next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

GitHub Secret Hunting compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
GitHub Secret Hunting this skilluphiago/recon-skills1.3k—~1.8kAutomated safety check: WarnMIT
Security SecretsIgorWarzocha/Opencode-Workflows122—~1.2kAutomated safety check: NotesNone
Triaging Security Findingsbitwarden/ai-plugins154—~2.2kAutomated safety check: PassCustom licence
Triage Codeqlnetdata/netdata81k—~1.8kAutomated safety check: NotesGPL-3.0
Secure GitHub Actionsvechain/x-app-template450—~1.2kAutomated safety check: PassMIT
Implementing GitHub Advanced Security For Code Scanningmukul975/Anthropic-Cybersecurity-Skills34k—~2.3kAutomated safety check: PassApache-2.0

Similar skills

  • Security Secrets

    IgorWarzocha/Opencode-Workflows

    Review secret detection patterns and scanning workflows. An agent skill from IgorWarzocha/Opencode-Workflows.

    122 GitHub stars~1.2k tokensUpdated 8 mo ago
    SecurityAuto-check: notes
  • Triaging Security Findings

    bitwarden/ai-plugins

    Official

    This skill should be used when the user asks to "triage security findings", "fix an Aikido finding", "review Aikido issues", "dismiss a false positive", "check SAST/IaC alerts", or needs to work…

    154 GitHub stars~2.2k tokensUpdated today
    SecurityAuto-check passed
  • Triage Codeql

    netdata/netdata

    Inspect, review or triage GitHub Code Scanning alerts, including CodeQL findings; apply verified dismissals when authorized.

    81k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes
  • Secure GitHub Actions

    vechain/x-app-template

    Secure GitHub Actions workflows against supply-chain, privilege, and shell-injection risks.

    450 GitHub stars~1.2k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Implementing GitHub Advanced Security For Code Scanning

    mukul975/Anthropic-Cybersecurity-Skills

    Configures GitHub Advanced Security (code scanning with CodeQL, secret scanning, dependency review, and Dependabot alerts) to perform automated static analysis and vulnerability detection across…

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Network Security Setup

    Microck/ordinary-claude-skills

    Configure Claude Code sandbox network isolation with trusted domains, custom access policies, and environment variables

    401 GitHub starsUsed in 1 repo~2.7k tokens
    DevOps & CloudAuto-check: notes

More from uphiago/recon-skills

All 23 skills in this repo
  • Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.

    1.3k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Error Log Mining

    uphiago/recon-skills

    Mine errorlog for creds, paths, SQL when leak hunt finds. An agent skill from uphiago/recon-skills.

    1.3k GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • JS Secrets Extraction

    uphiago/recon-skills

    Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

    1.3k GitHub stars~2.6k tokensUpdated 1 mo ago
    Auto-check passed
  • Recon Playbook

    uphiago/recon-skills

    A skill your agent uses when starting or restructuring an authorized external web and API assessment.

    1.3k GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Web Enumeration

    uphiago/recon-skills

    Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect

    1.3k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check: notes
  • 401 403 Bypass Techniques

    uphiago/recon-skills

    A skill your agent uses when protected HTTP routes return 401 or 403.

    1.3k GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about GitHub Secret Hunting

What does GitHub Secret Hunting do?

Find leaked API keys, tokens, and credentials in public GitHub repositories. GitHub Secret Hunting is an agent skill from uphiago/recon-skills. Find leaked API keys, tokens, and credentials in public GitHub repositories.

When should I use GitHub Secret Hunting?

GitHub Secret Hunting fits situations like: tasks that involve Secrets management.

How do I install GitHub Secret Hunting in Claude Code?

Run `npx skills add uphiago/recon-skills --skill github-secret-hunting -a claude-code`. Or copy the skill folder (recon/github-secret-hunting in uphiago/recon-skills) into .claude/skills/github-secret-hunting in your project. Claude Code loads it when a task matches its description.

How do I install GitHub Secret Hunting in Codex?

Run `npx skills add uphiago/recon-skills --skill github-secret-hunting -a codex`. Or copy the skill folder (recon/github-secret-hunting in uphiago/recon-skills) into .agents/skills/github-secret-hunting in your project. Codex loads it when a task matches its description.

Can I use GitHub Secret Hunting in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add uphiago/recon-skills --skill github-secret-hunting -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/github-secret-hunting, .gemini/skills/github-secret-hunting, .github/skills/github-secret-hunting and .opencode/skills/github-secret-hunting in your project.

What does GitHub Secret Hunting need to run?

Going by SKILL.md and its folder, GitHub Secret Hunting needs the command-line tools its instructions call (curl, python3, jq, git, docker and gitleaks) and credentials named GITHUB_TOKEN, DB_PASSWORD, GITLAB_TOKEN and AWS_ACCESS_KEY_ID. Our summary lists: Python 3; Docker; A credential in GITHUB_TOKEN; A credential in GITLAB_TOKEN. Compatibility (from SKILL.md): Requires curl, httpx, python3.

Does GitHub Secret Hunting access the network?

SKILL.md names 3 domains. In commands or code: api.github.com, github.com and api.openai.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is GitHub Secret Hunting safe to install?

Our automated static check of SKILL.md flagged 3 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does GitHub Secret Hunting use?

GitHub Secret Hunting is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does GitHub Secret Hunting use?

About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to GitHub Secret Hunting?

Skills that share tags, products or a category with GitHub Secret Hunting: Security Secrets (IgorWarzocha/Opencode-Workflows, 122 stars), Triaging Security Findings (bitwarden/ai-plugins, 154 stars), Triage Codeql (netdata/netdata, 81k stars) and Secure GitHub Actions (vechain/x-app-template, 450 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains GitHub Secret Hunting?

uphiago (a GitHub user) maintains it in uphiago/recon-skills, which has 1,294 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 1, 2026.

Source: uphiago/recon-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.