Trufflehog

Comprehensive guide for using TruffleHog (open-source) to detect, classify, and verify leaked secrets and credentials. Use this skill whenever the user wants to scan for secrets, credentials, API keys, tokens, or passwords in git repos, GitHub/GitLab orgs, Docker images, S3/GCS buckets, filesystems, CI systems, or any other data source. Also invoke this skill when the user asks about setting up pre-commit hooks for secret detection, integrating secret scanning into CI/CD pipelines (GitHub Actions, GitLab CI, etc.), reducing false positives from secret scanners, writing custom regex detectors, understanding TruffleHog's verification model, or auditing repositories for credential leaks. Trigger on any mention of: trufflehog, secret scanning, credential detection, leaked keys, API key detection, pre-commit secret hooks, or scanning git history for secrets.

kpatryk c6fd05e 3 files · 27.2 KB Updated

File contents

kpatryk/skills/tree/main/skills/trufflehog commit c6fd05ea27

Frequently asked questions

npx skillmds@latest add kpatryk/trufflehog