Workos
usenotra/notra
A skill your agent uses when the user asks for a WorkOS docs URL, term, or dashboard field (Sign-in endpoint, initiateloginuri, Redirect URI, WORKOS env vars), or is implementing, debugging, or…
Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints
$ npx skills add uphiago/recon-skills --skill js-secrets-extraction -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install uphiago/recon-skills js-secrets-extraction --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/recon/js-secrets-extraction .claude/skills/js-secrets-extraction && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "js-secrets-extraction" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/js-secrets-extraction into .claude/skills/js-secrets-extraction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "js-secrets-extraction", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/uphiago/recon-skills/tree/main/recon/js-secrets-extractionType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add uphiago/recon-skills --skill js-secrets-extraction -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install uphiago/recon-skills js-secrets-extraction --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/recon/js-secrets-extraction .agents/skills/js-secrets-extraction && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "js-secrets-extraction" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/js-secrets-extraction into .agents/skills/js-secrets-extraction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "js-secrets-extraction", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add uphiago/recon-skills --skill js-secrets-extraction -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install uphiago/recon-skills js-secrets-extraction --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/recon/js-secrets-extraction .cursor/skills/js-secrets-extraction && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "js-secrets-extraction" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/js-secrets-extraction into .cursor/skills/js-secrets-extraction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "js-secrets-extraction", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/uphiago/recon-skills.git --path recon/js-secrets-extraction--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add uphiago/recon-skills --skill js-secrets-extraction -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install uphiago/recon-skills js-secrets-extraction --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/recon/js-secrets-extraction .gemini/skills/js-secrets-extraction && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "js-secrets-extraction" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/js-secrets-extraction into .gemini/skills/js-secrets-extraction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "js-secrets-extraction", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install uphiago/recon-skills js-secrets-extractionInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add uphiago/recon-skills --skill js-secrets-extraction -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/recon/js-secrets-extraction .github/skills/js-secrets-extraction && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "js-secrets-extraction" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/js-secrets-extraction into .github/skills/js-secrets-extraction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "js-secrets-extraction", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add uphiago/recon-skills --skill js-secrets-extraction -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install uphiago/recon-skills js-secrets-extraction --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/uphiago/recon-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/recon/js-secrets-extraction .opencode/skills/js-secrets-extraction && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "js-secrets-extraction" agent skill from https://github.com/uphiago/recon-skills/tree/main/recon/js-secrets-extraction into .opencode/skills/js-secrets-extraction/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "js-secrets-extraction", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
js-secrets-extractionAnalyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints
JS Secrets Extraction is an agent skill from uphiago/recon-skills. Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/scan_js.py`).
It sits in Backend & APIs, covering Secrets management and Authentication. It works with Supabase and Firebase. The repository describes itself as: Recon & pentest skill pack. CORS, XSS, SQLi, SSRF, RCE, WordPress, MCP, cloud, subdomain takeover, and more. Field-tested. MIT. Full write-up at hiago.sh. The licence is MIT.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 1260244. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python), which the agent can run.
Shell commands in SKILL.md call:
curlpython3firebasewgetnodeFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
unminify.comsource-map-visualization.netlify.appidentitytoolkit.googleapis.comweb.archive.orgFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
ANON_KEYAPI_KEYSUPABASE_ANON_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
JS Secrets Extraction loads about 2.6k tokens when it runs. Until then it costs about 30 tokens; SKILL.md has 408 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from uphiago/recon-skills at commit 1260244, republished under its MIT licence (© uphiago). 408 words, ~2,622 tokens.
.claude/skills/js-secrets-extraction/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Modern JavaScript bundles (Webpack, Vite, esbuild) often contain:
curl --max-time 30 --connect-timeout 10 -s "https://target.com" > index.html
grep -Eo 'src="[^"]*\.js"' index.html | cut -d'"' -f2 | while read js; do
curl --max-time 30 --connect-timeout 10 -s "https://target.com$js" > "$(basename $js)"
done
# Search for secrets in bundles
grep -rEn "(apiKey|api_key|API_KEY|token|secret|password|clientId|client_id|auth0|firebase|supabase)[\"'\"]?[[:space:]]*[:=][[:space:]]*[\"'\'][^\"'\']{8,}" *.jscurl --max-time 30 --connect-timeout 10 -sI "https://target.com/assets/index-abc123.js.map"
curl --max-time 30 --connect-timeout 10 -sI "https://target.com/static/js/main.12345.js.map"
# If HTTP 200, use for reconstruction:
# https://unminify.com
# https://source-map-visualization.netlify.appReal-world case: Enterprise Angular SPA admin, 2 JS bundles (250KB each) exposed:
Modern deployments often serve the main SPA on port 443 and admin/API on separate ports (8080, 8081, 8084). Always check JS bundles on ALL discovered ports:
# Check source maps on every open port
for port in 443 8080 8081 8084; do
curl --max-time 30 --connect-timeout 10 -sI "https://target.com:$port/static/js/main.*.js.map" 2>/dev/null
curl --max-time 30 --connect-timeout 10 -sI "https://target.com:$port/assets/index-*.js.map" 2>/dev/null
doneSource maps on administrative or alternate-port applications may expose a different route and configuration set from the public SPA. Analyze each authorized application independently.
When you find an admin portal on a separate port, the JS bundle often contains different secrets than the main site:
base = "https://target.com:8080" # Admin portal
js = requests.get(f"{base}/static/js/main.*.js").text
# 1. Extract ALL API URLs
api_urls = re.findall(r'https?://[^\"\'[[:space:]]\\n,)>\\]]+', js)
# 2. Find base API URL (the backend this admin talks to)
# 3. Look for hardcoded credentials, API keys, auth patterns
# 4. Extract route paths for the admin app
routes = re.findall(r'[\"\'](/[a-zA-Z0-9_/.-]*(?:admin|chat|bot|message|user|auth|login|token|config|setting|dashboard|hospital|pharmacy|drug|payment)[a-zA-Z0-9_/.-]*)[\"\']', js, re.IGNORECASE)When source maps are available, analyze the sourcesContent array for hardcoded secrets:
import json, re
data = json.loads(open("bundle.js.map").read())
all_source = " ".join(data.get("sourcesContent", []))
# Search for credentials in the original source
patterns = {
"password": r'[\"\']([^\"\']*(?:password|passwd|pwd)[^\"\']*)[\"\']\s*[:=]\s*[\"\']([^\"\']+)[\"\']',
"token": r'[\"\']([^\"\']*(?:token|jwt|api_key|apikey|secret)[^\"\']*)[\"\']\s*[:=]\s*[\"\']([^\"\']+)[\"\']',
}
for name, pat in patterns.items():
matches = re.findall(pat, all_source, re.IGNORECASE)
if matches:
print(f"[{name}] {matches[:5]}")import re
patterns = {
"Firebase API Key": r'apiKey:\s*[\"\']([^\"\']{30,})',
"AWS Key": r'(?:AKIA|ASIA)[A-Z0-9]{16}',
"Google API Key": r'AIza[0-9A-Za-z\\-_]{35}',
"JWT": r'eyJ[A-Za-z0-9_\\-]{20,}\.[A-Za-z0-9_\\-]{20,}\.[A-Za-z0-9_\\-]{10,}',
"Mercado Pago": r'APP_USR-[a-f0-9]{8,}',
"Stripe": r'(?:sk_live|pk_live)_[A-Za-z0-9]{24,}',
"Auth0 Domain": r'(?:domain|auth0_domain):\s*[\"\']([^\"\']+\.auth0\.com)',
"Auth0 Client ID": r'(?:client_id|clientId|AUTH0_CLIENT_ID):\s*[\"\']([^\"\']{20,})',
"Supabase URL": r'(?:supabaseUrl|SUPABASE_URL):\s*[\"\'](https://[^\"\']+\.supabase\.co)',
"Supabase Key": r'(?:supabaseKey|anonKey|SUPABASE_ANON_KEY):\s*[\"\'](eyJ[A-Za-z0-9_\\-]+\.[A-Za-z0-9_\\-]+\.[A-Za-z0-9_\\-]+)',
"Heroku": r'[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}',
"Generic Secret": r'(?:secret|password|token|key):\s*[\"\']([^\"\']{8,})',
}import requests, re, json
base = "https://target.com"
html = requests.get(base).text
# Extract all JS URLs
js_urls = re.findall(r'src="([^"]*\.js)"', html)
for js_url in js_urls:
if js_url.startswith("/"):
js_url = base + js_url
content = requests.get(js_url).text
for name, pattern in patterns.items():
matches = re.findall(pattern, content)
for m in matches:
if isinstance(m, tuple):
m = m[0]
if len(m) > 6:
print(f"[{name}] {m[:80]}")| Issue | Solution |
|---|---|
| Bundles too large | Use grep -Eo with specific patterns |
| Minified code (1 char names) | Use source maps for reconstruction |
| False positive matches | Validate keys by testing API endpoint |
| Rate limiting | Add delays between bundle downloads |
JS bundles frequently leak production backend URLs, enabling direct API attacks bypassing CDN/WAF:
# Platform-specific backend URL patterns
grep -Eo 'https?://[a-zA-Z0-9.\-]+\.(fly\.dev|azurewebsites\.net|onrender\.com|vercel\.app|netlify\.app)[^"'\'' ]{0,40}' /tmp/*.js
grep -Eo 'https?://[a-zA-Z0-9.\-]+\.(supabase\.co|r2\.dev|blob\.vercel-storage\.com)[^"'\'' ]{0,40}' /tmp/*.js
# Edge function URLs
grep -Eo 'functions/v1/[a-zA-Z0-9_\-]+' /tmp/*.js
# Internal API paths
grep -Eo '["\x60]/api/v1/[a-zA-Z0-9_\-/]+["\x60]' /tmp/*.js| Pattern | Platform | Example | Secret? |
|---|---|---|---|
*.fly.dev | Fly.io | ht-prod-backend.fly.dev | ✅ Backend URL |
*.azurewebsites.net | Azure | consigpro-api-prod-... | ✅ Backend URL |
*.onrender.com | Render | clickcity-api.onrender.com | ✅ Backend URL |
*.supabase.co | Supabase | jxhvjufqtabpeieyhkgk.supabase.co | ✅ Anon key is public; backend URL is intel |
*.r2.dev | Cloudflare R2 | pub-xxx.r2.dev | ✅ Storage URL |
functions/v1/* | Supabase Edge | provision-openrouter-key | ✅ Endpoint name |
dpl_* | Vercel DPL | dpl_BCoyPsxxYLZ... | ❌ NOT a secret — public deploy ID |
# Test Firebase API key
curl --max-time 30 --connect-timeout 10 -s "https://identitytoolkit.googleapis.com/v1/accounts:signUp?key=AIza..."
# Test Supabase anon key
curl --max-time 30 --connect-timeout 10 -s "https://PROJECT.supabase.co/rest/v1/users?limit=1" -H "apikey: ANON_KEY" -H "Authorization: Bearer ANON_KEY"Recover full pre-compiled source code when .js.map files are left in production:
# Find .map files via Wayback Machine
curl --max-time 30 --connect-timeout 10 -s "https://web.archive.org/cdx/search/cdx?url=*.target.com/*&collapse=urlkey&output=text&fl=original&filter=original:.*\.js\.map$" \
| sort -u > map_urls.txt
# Download and extract source
wget https://target.com/static/app.js.map
node -e "
const map = require('./app.js.map');
map.sources.forEach((src, i) => {
const fs = require('fs');
fs.writeFileSync(src.split('/').pop(), map.sourcesContent[i]);
});
print('Extracted ' + map.sources.length + ' source files');
"
# Quick check: does a JS file have an available map?
curl --max-time 30 --connect-timeout 10 -skI "https://target.com/static/app.js.map" | grep "200\|Content-Type"Crawl JS files recursively for embedded URLs, APIs, and IPs:
# lazyegg — crawls JS files for links, APIs, IPs
python3 lazyegg.py https://target.com
python3 lazyegg.py https://target.com/js/auth.js
# Combine with waybackurls for deep coverage
waybackurls target.com \
| grep '\.js$' \
| awk -F '?' '{print $1}' \
| sort -u \
| xargs -I{} bash -c 'python3 lazyegg.py "{}" --js_urls --domains --ips' \
> lazyegg_output.txt
# subjs — extract JS URLs from any URL list
cat all_urls.txt | subjs | tee js_files_full.txtJS bundles are source code — even minified. A disciplined per-file (per-chunk) review finds what autonomous agents miss:
# 1. Download all JS chunks
curl --max-time 30 --connect-timeout 10 -sk "https://target.com" | grep -Eo 'src="[^"]+\.js[^"]*"' | \
cut -d'"' -f2 | while read js; do
curl --max-time 30 --connect-timeout 10 -sk "$js" -o "chunks/$(basename $js)"
done
# 2. Per-chunk pattern review for dangerous sinks
for chunk in chunks/*.js; do
echo "=== $chunk ==="
# eval / new Function (arbitrary code execution)
grep -Eon 'eval\s*\(|new\s+Function\s*\(' "$chunk"
# Hardcoded API keys/secrets
grep -Eon '(?:api[_-]?key|secret|token|password|bearer)\s*[:=]\s*["\x27][^"\x27]{8,}' "$chunk"
# postMessage without origin check
grep -Eon 'postMessage\s*\(' "$chunk"
# Prototype pollution patterns
grep -Eon '__proto__|constructor\.prototype' "$chunk"
# Debug/test code in production
grep -Eoin 'debug|test|staging|localhost' "$chunk"
# Client-trusted flags
grep -Eon '(?:isAdmin|isVip|isPremium|isModerator|role)\s*[=:]\s*true' "$chunk"
done > ai_review_findings.txt
# 3. Review findings — each is a CANDIDATE, not confirmed
grep -c "===" ai_review_findings.txt # files reviewed
grep -c ":" ai_review_findings.txt # candidate findingsKey insight: autonomous agents told "find bugs" in a whole codebase burn budget and miss things. A guaranteed per-file pass with fixed output structure produces repeatable hits. Each finding still needs manual PoC verification.
© uphiago, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (scripts) in recon/js-secrets-extraction of uphiago/recon-skills.
Open the folder on GitHubat commit 1260244
JS Secrets Extraction next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| JS Secrets Extraction this skilluphiago/recon-skills | 1.3k | — | ~2.6k | Automated safety check: Pass | MIT | |
| Workosusenotra/notra | 255 | — | ~6.2k | Automated safety check: Pass | AGPL-3.0 | |
| API Security Designvinayaklatthe/microsoft-security-skills | 175 | — | ~2.2k | Automated safety check: Pass | MIT | |
| Supabase Development and Debuggingsupabase/agent-skills | 2.7k | 3 repos | ~3.6k | Automated safety check: Pass | MIT | |
| Security Reviewjewbetcha/opentrace | 116 | 17 repos | ~3.1k | Automated safety check: Notes | MIT | |
| Better Auth Best Practiceslatitude-dev/latitude-llm | 4.7k | 7 repos | ~1.6k | Automated safety check: Pass | MIT |
usenotra/notra
A skill your agent uses when the user asks for a WorkOS docs URL, term, or dashboard field (Sign-in endpoint, initiateloginuri, Redirect URI, WORKOS env vars), or is implementing, debugging, or…
vinayaklatthe/microsoft-security-skills
Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…
supabase/agent-skills
General Supabase skill for database, auth, Edge Functions, Realtime and storage work, plus client libraries, migrations, security audits, debugging and reading logs.
jewbetcha/opentrace
A skill your agent uses when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features.
latitude-dev/latitude-llm
Configure Better Auth server and client, set up database adapters, manage sessions, add plugins, and handle environment variables.
curvenote/curvenote
A skill your agent uses when doing ANY task involving Supabase.
uphiago/recon-skills
Flags API endpoints whose data or actions look like they should need a login but currently don't, as part of authorized security testing.
uphiago/recon-skills
Mine errorlog for creds, paths, SQL when leak hunt finds. An agent skill from uphiago/recon-skills.
uphiago/recon-skills
A skill your agent uses when starting or restructuring an authorized external web and API assessment.
uphiago/recon-skills
Sensitive file scanning, path traversal bypass, vHost enum, .env extract, log mining, Varnish detect
uphiago/recon-skills
A skill your agent uses when protected HTTP routes return 401 or 403.
uphiago/recon-skills
Map organization IP infrastructure via ASN, CIDR, TLD expansion, and reverse DNS.
Categories
Analyze JS bundles and source maps for hardcoded secrets, API keys, JWTs, and internal endpoints. JS Secrets Extraction is an agent skill from uphiago/recon-skills.
JS Secrets Extraction fits situations like: tasks that involve Secrets management; tasks that involve Authentication.
Run `npx skills add uphiago/recon-skills --skill js-secrets-extraction -a claude-code`. Or copy the skill folder (recon/js-secrets-extraction in uphiago/recon-skills) into .claude/skills/js-secrets-extraction in your project. Claude Code loads it when a task matches its description.
Run `npx skills add uphiago/recon-skills --skill js-secrets-extraction -a codex`. Or copy the skill folder (recon/js-secrets-extraction in uphiago/recon-skills) into .agents/skills/js-secrets-extraction in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add uphiago/recon-skills --skill js-secrets-extraction -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/js-secrets-extraction, .gemini/skills/js-secrets-extraction, .github/skills/js-secrets-extraction and .opencode/skills/js-secrets-extraction in your project.
Going by SKILL.md and its folder, JS Secrets Extraction needs Python for the scripts in its folder, the command-line tools its instructions call (curl, python3, firebase, wget and node) and credentials named ANON_KEY, API_KEY and SUPABASE_ANON_KEY. Our summary lists: Python 3; A credential in API_KEY; A credential in SUPABASE_ANON_KEY.
SKILL.md names 4 domains. In commands or code: unminify.com, source-map-visualization.netlify.app, identitytoolkit.googleapis.com and web.archive.org; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
JS Secrets Extraction is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with JS Secrets Extraction: Workos (usenotra/notra, 255 stars), API Security Design (vinayaklatthe/microsoft-security-skills, 175 stars), Supabase Development and Debugging (supabase/agent-skills, 2.7k stars) and Security Review (jewbetcha/opentrace, 116 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
uphiago (a GitHub user) maintains it in uphiago/recon-skills, which has 1,294 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on September 1, 2026.
Source: uphiago/recon-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.