Skip to content
Back to skills

Secret Scan

ASecurity

> Detect exposed credentials, API keys, and sensitive data in the codebase.

  • 229 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added June 6, 2026
securitygobashawsgitapidatabase

Works with

  • api

Security analysis

A100/100

Scanned June 6, 2026

npx -y skills add Miosa-osa/canopy --skill secret-scan --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Secret Scan?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Secret Scan
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/miosa-osa-secret-scan/badge)](https://www.skillsdirectory.com/skills/miosa-osa-secret-scan)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
# /secret-scan

> Detect exposed credentials, API keys, and sensitive data in the codebase.

## Usage
```
/secret-scan [path] [--git-history] [--fix]
```

## What It Does
Scans the codebase (and optionally git history) for exposed secrets: AWS credentials, API keys, private keys, database connection strings, JWT tokens, and other sensitive data. Reports findings with exact file locations and remediation steps.

## Implementation
1. **Scan current files** -- regex patterns for common secret formats:
   - AWS: `AKIA[0-9A-Z]{16}`
   - Generic API key: `[a-zA-Z0-9]{32,}` in assignment context
   - Private keys: `-----BEGIN (RSA|EC|DSA) PRIVATE KEY-----`
   - Connection strings: `postgres://`, `mongodb://`, `redis://` with credentials
   - JWT: `eyJ[A-Za-z0-9-_]+\.eyJ[A-Za-z0-9-_]+\.[A-Za-z0-9-_]+`
2. **Scan git history** (if `--git-history`) -- check previous commits for secrets that were later removed.
3. **Check .gitignore** -- verify .env, credential files, and key files are ignored.
4. **Report** -- location, secret type, severity, and remediation.
5. **Fix** (if `--fix`) -- add entries to .gitignore, suggest secret rotation.

## Examples
```bash
# Scan current codebase
/secret-scan

# Include git history
/secret-scan --git-history

# Scan and auto-fix .gitignore
/secret-scan --fix

# Scan specific directory
/secret-scan config/
```

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…