Agent skill

JS Secrets Extraction

by uphiago in uphiago/recon-skills

Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

MITAuto-check passedBackend & APIs

Install JS Secrets Extraction

skills CLI
$ npx skills add uphiago/recon-skills --skill js-secrets-extraction -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install uphiago/recon-skills js-secrets-extraction --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/recon/js-secrets-extraction .claude/skills/js-secrets-extraction && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
js-secrets-extraction
GitHub stars
1.3k
Token cost
~2.6k tokens
SKILL.md length
408 words
Files
2 (incl. scripts)
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

  • Works in 3 steps: Source Map Exploitation → Deep JS Crawling → Per-File AI-Assisted Code Review
  • Tasks that involve Secrets management
  • SKILL.md covers When to Use, Why Analyze JS Bundles, Bundle Download and Analysis and Source Map Reconstruction, plus 8 more sections
  • Runs Python scripts from its folder; calls curl, python3 and firebase; reaches unminify.com and source-map-visualization.netlify.app; needs ANON_KEY and API_KEY

What it does

JS Secrets Extraction is an agent skill from uphiago/recon-skills. Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/scan_js.py`).

It sits in Backend & APIs, covering Secrets management and Authentication. It works with Supabase and Firebase. The repository describes itself as: Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh. The licence is MIT.

When your agent uses it

  • Tasks that involve Secrets management
  • Tasks that involve Authentication

Example prompts

  • “/js-secrets-extraction”

Requirements

  • Python 3
  • A credential in API_KEY
  • A credential in SUPABASE_ANON_KEY

Workflow steps

3 steps, taken from the step headings in SKILL.md.

  1. Source Map Exploitation
  2. Deep JS Crawling
  3. Per-File AI-Assisted Code Review

What it can do on your machine

Read from SKILL.md and the folder at commit 1260244. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • curl
    • python3
    • firebase
    • wget
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • unminify.com
    • source-map-visualization.netlify.app
    • identitytoolkit.googleapis.com
    • web.archive.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • ANON_KEY
    • API_KEY
    • SUPABASE_ANON_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

JS Secrets Extraction loads about 2.6k tokens when it runs. Until then it costs about 30 tokens; SKILL.md has 408 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~30
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from uphiago/recon-skills at commit 1260244, republished under its MIT licence (© uphiago). 408 words, ~2,622 tokens.

Download SKILL.mdSave it as .claude/skills/js-secrets-extraction/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
js-secrets-extraction
description
Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints
version
1.1.0
revision_date
2026-07-25
license
MIT
category
recon
tags
js, secrets, API-key, jwt, source-map, recon

JS Bundle & Source Map Analysis -- Secret Extraction

When to Use

  • ALWAYS after initial web enumeration
  • When you find modern SPA (React, Angular, Vue)
  • When target uses Firebase, Supabase, Auth0
  • Higher yield than directory scanning on many targets

Why Analyze JS Bundles

Modern JavaScript bundles (Webpack, Vite, esbuild) often contain:

  • Hardcoded API keys and tokens
  • Internal API URLs
  • Firebase, Auth0, Supabase configurations
  • Environment variables (VITE_*, REACT_APP_*, NEXT_PUBLIC_*)
  • Internal routes

Bundle Download and Analysis

bash
curl --max-time 30 --connect-timeout 10 -s "https://target.com" > index.html
grep -Eo 'src="[^"]*\.js"' index.html | cut -d'"' -f2 | while read js; do
  curl --max-time 30 --connect-timeout 10 -s "https://target.com$js" > "$(basename $js)"
done

# Search for secrets in bundles
grep -rEn "(apiKey|api_key|API_KEY|token|secret|password|clientId|client_id|auth0|firebase|supabase)[\"'\"]?[[:space:]]*[:=][[:space:]]*[\"'\'][^\"'\']{8,}" *.js

Source Map Reconstruction

bash
curl --max-time 30 --connect-timeout 10 -sI "https://target.com/assets/index-abc123.js.map"
curl --max-time 30 --connect-timeout 10 -sI "https://target.com/static/js/main.12345.js.map"

# If HTTP 200, use for reconstruction:
# https://unminify.com
# https://source-map-visualization.netlify.app

Real-world case: Enterprise Angular SPA admin, 2 JS bundles (250KB each) exposed:

  • Internal API URL (apiv3.empresa.com.br)
  • Firebase API key (AIzaSy...2GXA)
  • Encryption keys (AD5oDjsJaTJOzLe1Llj9mz)
  • Cloudinary upload endpoint

Port-Specific URL Analysis

Modern deployments often serve the main SPA on port 443 and admin/API on separate ports (8080, 8081, 8084). Always check JS bundles on ALL discovered ports:

bash
# Check source maps on every open port
for port in 443 8080 8081 8084; do
  curl --max-time 30 --connect-timeout 10 -sI "https://target.com:$port/static/js/main.*.js.map" 2>/dev/null
  curl --max-time 30 --connect-timeout 10 -sI "https://target.com:$port/assets/index-*.js.map" 2>/dev/null
done

Source maps on administrative or alternate-port applications may expose a different route and configuration set from the public SPA. Analyze each authorized application independently.

Admin Portal JS Analysis Pattern

When you find an admin portal on a separate port, the JS bundle often contains different secrets than the main site:

python
base = "https://target.com:8080"  # Admin portal
js = requests.get(f"{base}/static/js/main.*.js").text

# 1. Extract ALL API URLs
api_urls = re.findall(r'https?://[^\"\'[[:space:]]\\n,)>\\]]+', js)
# 2. Find base API URL (the backend this admin talks to)
# 3. Look for hardcoded credentials, API keys, auth patterns
# 4. Extract route paths for the admin app
routes = re.findall(r'[\"\'](/[a-zA-Z0-9_/.-]*(?:admin|chat|bot|message|user|auth|login|token|config|setting|dashboard|hospital|pharmacy|drug|payment)[a-zA-Z0-9_/.-]*)[\"\']', js, re.IGNORECASE)

Source Map Content Analysis (1,200+ Files)

When source maps are available, analyze the sourcesContent array for hardcoded secrets:

python
import json, re
data = json.loads(open("bundle.js.map").read())
all_source = " ".join(data.get("sourcesContent", []))

# Search for credentials in the original source
patterns = {
    "password": r'[\"\']([^\"\']*(?:password|passwd|pwd)[^\"\']*)[\"\']\s*[:=]\s*[\"\']([^\"\']+)[\"\']',
    "token": r'[\"\']([^\"\']*(?:token|jwt|api_key|apikey|secret)[^\"\']*)[\"\']\s*[:=]\s*[\"\']([^\"\']+)[\"\']',
}
for name, pat in patterns.items():
    matches = re.findall(pat, all_source, re.IGNORECASE)
    if matches:
        print(f"[{name}] {matches[:5]}")
  • Cloudinary upload endpoint

Secret Regex Patterns Catalog

python
import re

patterns = {
    "Firebase API Key": r'apiKey:\s*[\"\']([^\"\']{30,})',
    "AWS Key": r'(?:AKIA|ASIA)[A-Z0-9]{16}',
    "Google API Key": r'AIza[0-9A-Za-z\\-_]{35}',
    "JWT": r'eyJ[A-Za-z0-9_\\-]{20,}\.[A-Za-z0-9_\\-]{20,}\.[A-Za-z0-9_\\-]{10,}',
    "Mercado Pago": r'APP_USR-[a-f0-9]{8,}',
    "Stripe": r'(?:sk_live|pk_live)_[A-Za-z0-9]{24,}',
    "Auth0 Domain": r'(?:domain|auth0_domain):\s*[\"\']([^\"\']+\.auth0\.com)',
    "Auth0 Client ID": r'(?:client_id|clientId|AUTH0_CLIENT_ID):\s*[\"\']([^\"\']{20,})',
    "Supabase URL": r'(?:supabaseUrl|SUPABASE_URL):\s*[\"\'](https://[^\"\']+\.supabase\.co)',
    "Supabase Key": r'(?:supabaseKey|anonKey|SUPABASE_ANON_KEY):\s*[\"\'](eyJ[A-Za-z0-9_\\-]+\.[A-Za-z0-9_\\-]+\.[A-Za-z0-9_\\-]+)',
    "Heroku": r'[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}',
    "Generic Secret": r'(?:secret|password|token|key):\s*[\"\']([^\"\']{8,})',
}

Batch Bundle Download + Grep

python
import requests, re, json

base = "https://target.com"
html = requests.get(base).text

# Extract all JS URLs
js_urls = re.findall(r'src="([^"]*\.js)"', html)
for js_url in js_urls:
    if js_url.startswith("/"):
        js_url = base + js_url
    content = requests.get(js_url).text
    for name, pattern in patterns.items():
        matches = re.findall(pattern, content)
        for m in matches:
            if isinstance(m, tuple):
                m = m[0]
            if len(m) > 6:
                print(f"[{name}] {m[:80]}")

Pitfalls

IssueSolution
Bundles too largeUse grep -Eo with specific patterns
Minified code (1 char names)Use source maps for reconstruction
False positive matchesValidate keys by testing API endpoint
Rate limitingAdd delays between bundle downloads

Show full SKILL.md (161 more words)Show less

Backend URL Discovery

JS bundles frequently leak production backend URLs, enabling direct API attacks bypassing CDN/WAF:

bash
# Platform-specific backend URL patterns
grep -Eo 'https?://[a-zA-Z0-9.\-]+\.(fly\.dev|azurewebsites\.net|onrender\.com|vercel\.app|netlify\.app)[^"'\'' ]{0,40}' /tmp/*.js
grep -Eo 'https?://[a-zA-Z0-9.\-]+\.(supabase\.co|r2\.dev|blob\.vercel-storage\.com)[^"'\'' ]{0,40}' /tmp/*.js

# Edge function URLs
grep -Eo 'functions/v1/[a-zA-Z0-9_\-]+' /tmp/*.js

# Internal API paths
grep -Eo '["\x60]/api/v1/[a-zA-Z0-9_\-/]+["\x60]' /tmp/*.js
Real Field Patterns
PatternPlatformExampleSecret?
*.fly.devFly.ioht-prod-backend.fly.dev✅ Backend URL
*.azurewebsites.netAzureconsigpro-api-prod-...✅ Backend URL
*.onrender.comRenderclickcity-api.onrender.com✅ Backend URL
*.supabase.coSupabasejxhvjufqtabpeieyhkgk.supabase.co✅ Anon key is public; backend URL is intel
*.r2.devCloudflare R2pub-xxx.r2.dev✅ Storage URL
functions/v1/*Supabase Edgeprovision-openrouter-key✅ Endpoint name
dpl_*Vercel DPLdpl_BCoyPsxxYLZ...❌ NOT a secret — public deploy ID

Verification

bash
# Test Firebase API key
curl --max-time 30 --connect-timeout 10 -s "https://identitytoolkit.googleapis.com/v1/accounts:signUp?key=AIza..."
# Test Supabase anon key
curl --max-time 30 --connect-timeout 10 -s "https://PROJECT.supabase.co/rest/v1/users?limit=1" -H "apikey: ANON_KEY" -H "Authorization: Bearer ANON_KEY"
Phase 5 — Source Map Exploitation

Recover full pre-compiled source code when .js.map files are left in production:

bash
# Find .map files via Wayback Machine
curl --max-time 30 --connect-timeout 10 -s "https://web.archive.org/cdx/search/cdx?url=*.target.com/*&collapse=urlkey&output=text&fl=original&filter=original:.*\.js\.map$" \
  | sort -u > map_urls.txt

# Download and extract source
wget https://target.com/static/app.js.map
node -e "
const map = require('./app.js.map');
map.sources.forEach((src, i) => {
  const fs = require('fs');
  fs.writeFileSync(src.split('/').pop(), map.sourcesContent[i]);
});
print('Extracted ' + map.sources.length + ' source files');
"

# Quick check: does a JS file have an available map?
curl --max-time 30 --connect-timeout 10 -skI "https://target.com/static/app.js.map" | grep "200\|Content-Type"
Phase 6 — Deep JS Crawling

Crawl JS files recursively for embedded URLs, APIs, and IPs:

bash
# lazyegg — crawls JS files for links, APIs, IPs
python3 lazyegg.py https://target.com
python3 lazyegg.py https://target.com/js/auth.js

# Combine with waybackurls for deep coverage
waybackurls target.com \
  | grep '\.js$' \
  | awk -F '?' '{print $1}' \
  | sort -u \
  | xargs -I{} bash -c 'python3 lazyegg.py "{}" --js_urls --domains --ips' \
  > lazyegg_output.txt

# subjs — extract JS URLs from any URL list
cat all_urls.txt | subjs | tee js_files_full.txt
Phase 7 — Per-File AI-Assisted Code Review

JS bundles are source code — even minified. A disciplined per-file (per-chunk) review finds what autonomous agents miss:

bash
# 1. Download all JS chunks
curl --max-time 30 --connect-timeout 10 -sk "https://target.com" | grep -Eo 'src="[^"]+\.js[^"]*"' | \
  cut -d'"' -f2 | while read js; do
    curl --max-time 30 --connect-timeout 10 -sk "$js" -o "chunks/$(basename $js)"
  done

# 2. Per-chunk pattern review for dangerous sinks
for chunk in chunks/*.js; do
  echo "=== $chunk ==="
  # eval / new Function (arbitrary code execution)
  grep -Eon 'eval\s*\(|new\s+Function\s*\(' "$chunk"
  # Hardcoded API keys/secrets
  grep -Eon '(?:api[_-]?key|secret|token|password|bearer)\s*[:=]\s*["\x27][^"\x27]{8,}' "$chunk"
  # postMessage without origin check
  grep -Eon 'postMessage\s*\(' "$chunk"
  # Prototype pollution patterns
  grep -Eon '__proto__|constructor\.prototype' "$chunk"
  # Debug/test code in production
  grep -Eoin 'debug|test|staging|localhost' "$chunk"
  # Client-trusted flags
  grep -Eon '(?:isAdmin|isVip|isPremium|isModerator|role)\s*[=:]\s*true' "$chunk"
done > ai_review_findings.txt

# 3. Review findings — each is a CANDIDATE, not confirmed
grep -c "===" ai_review_findings.txt  # files reviewed
grep -c ":" ai_review_findings.txt     # candidate findings

Key insight: autonomous agents told "find bugs" in a whole codebase burn budget and miss things. A guaranteed per-file pass with fixed output structure produces repeatable hits. Each finding still needs manual PoC verification.

© uphiago, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in recon/js-secrets-extraction of uphiago/recon-skills.

  • SKILL.md
  • scripts/scan_js.py

Open the folder on GitHubat commit 1260244

Compare with similar skills

JS Secrets Extraction next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

JS Secrets Extraction compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
JS Secrets Extraction this skilluphiago/recon-skills1.3k—~2.6kAutomated safety check: PassMIT
Workosusenotra/notra255—~6.2kAutomated safety check: PassAGPL-3.0
API Security Designvinayaklatthe/microsoft-security-skills175—~2.2kAutomated safety check: PassMIT
Supabase Development and Debuggingsupabase/agent-skills2.7k3 repos~3.6kAutomated safety check: PassMIT
Security Reviewjewbetcha/opentrace11617 repos~3.1kAutomated safety check: NotesMIT
Better Auth Best Practiceslatitude-dev/latitude-llm4.7k7 repos~1.6kAutomated safety check: PassMIT

Similar skills

  • Workos

    usenotra/notra

    A skill your agent uses when the user asks for a WorkOS docs URL, term, or dashboard field (Sign-in endpoint, initiateloginuri, Redirect URI, WORKOS env vars), or is implementing, debugging, or…

    255 GitHub stars~6.2k tokensUpdated today
    Backend & APIsAuto-check passed
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Backend & APIsAuto-check passed
  • Official

    General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.

    2.7k GitHub starsUsed in 3 repos~3.6k tokens
    Backend & APIsAuto-check passed
  • Security Review

    jewbetcha/opentrace

    A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.

    116 GitHub starsUsed in 17 repos~3.1k tokens
    SecurityAuto-check: notes
  • Better Auth Best Practices

    latitude-dev/latitude-llm

    Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.

    4.7k GitHub starsUsed in 7 repos~1.6k tokens
    Backend & APIsAuto-check passed
  • Supabase

    curvenote/curvenote

    A skill your agent uses when doing ANY task involving Supabase.

    169 GitHub starsUsed in 5 repos~2.2k tokens
    Backend & APIsAuto-check passed

More from uphiago/recon-skills

All 23 skills in this repo
  • Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.

    1.3k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed
  • Error Log Mining

    uphiago/recon-skills

    Mine errorlog for creds, paths, SQL when leak hunt finds. An agent skill from uphiago/recon-skills.

    1.3k GitHub stars~3.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Recon Playbook

    uphiago/recon-skills

    A skill your agent uses when starting or restructuring an authorized external web and API assessment.

    1.3k GitHub stars~1.9k tokensUpdated 1 mo ago
    Auto-check passed
  • Web Enumeration

    uphiago/recon-skills

    Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect

    1.3k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check: notes
  • 401 403 Bypass Techniques

    uphiago/recon-skills

    A skill your agent uses when protected HTTP routes return 401 or 403.

    1.3k GitHub stars~3.1k tokensUpdated 1 mo ago
    Auto-check passed
  • Asn Infrastructure Mapping

    uphiago/recon-skills

    Map organization IP infrastructure via ASN, CIDR, TLD expansion, and reverse DNS.

    1.3k GitHub stars~1.6k tokensUpdated 1 mo ago
    Auto-check passed

Questions about JS Secrets Extraction

What does JS Secrets Extraction do?

Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints. JS Secrets Extraction is an agent skill from uphiago/recon-skills.

When should I use JS Secrets Extraction?

JS Secrets Extraction fits situations like: tasks that involve Secrets management; tasks that involve Authentication.

How do I install JS Secrets Extraction in Claude Code?

Run `npx skills add uphiago/recon-skills --skill js-secrets-extraction -a claude-code`. Or copy the skill folder (recon/js-secrets-extraction in uphiago/recon-skills) into .claude/skills/js-secrets-extraction in your project. Claude Code loads it when a task matches its description.

How do I install JS Secrets Extraction in Codex?

Run `npx skills add uphiago/recon-skills --skill js-secrets-extraction -a codex`. Or copy the skill folder (recon/js-secrets-extraction in uphiago/recon-skills) into .agents/skills/js-secrets-extraction in your project. Codex loads it when a task matches its description.

Can I use JS Secrets Extraction in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add uphiago/recon-skills --skill js-secrets-extraction -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/js-secrets-extraction, .gemini/skills/js-secrets-extraction, .github/skills/js-secrets-extraction and .opencode/skills/js-secrets-extraction in your project.

What does JS Secrets Extraction need to run?

Going by SKILL.md and its folder, JS Secrets Extraction needs Python for the scripts in its folder, the command-line tools its instructions call (curl, python3, firebase, wget and node) and credentials named ANON_KEY, API_KEY and SUPABASE_ANON_KEY. Our summary lists: Python 3; A credential in API_KEY; A credential in SUPABASE_ANON_KEY.

Does JS Secrets Extraction access the network?

SKILL.md names 4 domains. In commands or code: unminify.com, source-map-visualization.netlify.app, identitytoolkit.googleapis.com and web.archive.org; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is JS Secrets Extraction safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does JS Secrets Extraction use?

JS Secrets Extraction is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does JS Secrets Extraction use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to JS Secrets Extraction?

Skills that share tags, products or a category with JS Secrets Extraction: Workos (usenotra/notra, 255 stars), API Security Design (vinayaklatthe/microsoft-security-skills, 175 stars), Supabase Development and Debugging (supabase/agent-skills, 2.7k stars) and Security Review (jewbetcha/opentrace, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains JS Secrets Extraction?

uphiago (a GitHub user) maintains it in uphiago/recon-skills, which has 1,294 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 1, 2026.

Source: uphiago/recon-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.