Secret Scan

Catch hardcoded secrets, keys, and tokens before they get committed. Use before any commit and on any file with credentials.

archive228 c172074 725 B Updated

File contents

Secret Scan

Grep the diff for: api[_-]?key, secret, token, password, BEGIN PRIVATE KEY, AKIA[0-9A-Z]{16}, sk-, ghp_, bearer values, and long base64/hex blobs. For each hit: is it a real secret or a placeholder? Real secrets:

  1. Must move to env / a secrets manager — never the repo.
  2. If already committed, it is COMPROMISED. Rotate it, don't just delete the line.
  3. Add the pattern to .gitignore / a pre-commit secret scanner. Output: file:line of every real secret + the rotation step. A deleted secret in git history is still leaked.

archive228/loopkit/tree/main/skills/secret-scan commit c172074ded

Frequently asked questions

npx skillmds@latest add archive228/secret-scan