Skip to content
Search prompts, tools, agents…

Secrets scan review

Looks through code and config for exposed secrets and explains how to rotate and prevent them. Use before committing or open-sourcing.

Free Intermediate 0 views 0 copies 0 downloads
Download skill

Skill file

SKILL.md
---
name: secrets-scan-review
description: "Looks through code and config for exposed secrets and explains how to rotate and prevent them. Use before committing or open-sourcing."
---

# Secrets scan review

A secret that reached git history must be treated as leaked.

## How to work

1. Search for keys, tokens, passwords, private keys and connection strings in code, config and history.
2. For each find, say what it is and whether it looks real or an example.
3. Explain the rotation: revoke, create a new one, update the place that uses it.
4. Suggest prevention: environment variables, a secret manager, a pre-commit scanner, .gitignore.

## Rules

- Never print a full secret in your answer: show the first and last four characters.
- Assume leaked until rotated.

## Output

A table: file, kind, severity, action; then the prevention checklist.

How to use it

  1. Download the skill.
  2. Put its folder (with SKILL.md inside) in .claude/skills/secrets-scan-review/ for just this project, or in ~/.claude/skills/ for every project.
  3. Restart your tool and ask for what the skill does. It loads on its own when it fits.

Try it

Check this repo for secrets before we make it public.

Looks through code and config for exposed secrets and explains how to rotate and prevent them. Use before committing or open-sourcing.

Join the conversation

Your email address will not be published. Required fields are marked *