Secret Exposure Prevention

Prevent secret leakage across git history, package artifacts, logs, and docs. Use when editing workflows, packaging configuration, environment files, or release automation.

aibot88 Updated 3 repo stars

File contents

Secret Exposure Prevention

When to use

  • On changes involving .env, publish scripts, workflow files, and package include/exclude rules.
  • Before packaging/publishing distributable artifacts.
  • After any secret-handling incident or near-miss.

Procedure

  1. Identify secret-bearing file patterns in repo and tooling context.
  2. Verify packaging exclude rules (.vscodeignore, .npmignore, artifact manifests).
  3. Verify prevention controls (pre-commit scanning, CI scanning, secret scanning backstops).
  4. Validate that examples and docs use placeholders, never live tokens.
  5. Propose targeted guardrails with minimal operational overhead.

Output format

  • risk_status: low|medium|high
  • exposure_surfaces: git|artifact|logs|docs
  • missing_controls: specific missing guardrails
  • recommended_controls: prevention-first controls in priority order
  • evidence: files, workflows, and policies reviewed

Standards

  • Prevention first, detection second.
  • Never accept shipping secret-bearing files in distributable artifacts.
  • Keep false-positive handling explicit and auditable.

aibot88/sec_skill_store/tree/main/skills/claudskills/secret-exposure-prevention commit aca0a060e7

Frequently asked questions

npx skillmds@latest add aibot88/secret-exposure-prevention