Secret Scanner
A dependency-free engine that finds committed credentials by combining high-signal vendor regex rules (AWS, GitHub, GCP, Stripe, OpenAI, Anthropic, Slack, …) with Shannon-entropy gating to catch generic secrets while keeping false positives low.
When to use this skill
- "Are there any secrets / API keys committed in this repo?"
- "Scan this folder before I open-source it."
- Pre-commit / pre-push credential checks.
- Investigating a suspected leak.
How to run it
The engine has no third-party dependencies — just Python 3.9+.
# Human-readable report (default)
python skills/secret-scanner/engine.py .
# Machine-readable JSON (pipe into other tooling)
python skills/secret-scanner/engine.py . --json
# Tune entropy sensitivity (lower = more findings)
python skills/secret-scanner/engine.py src/ --min-entropy 3.0
# Include test directories (skipped by default)
python skills/secret-scanner/engine.py . --include-tests
Exit codes: 0 clean · 1 findings present · 2 usage error.
This makes it drop-in for CI: a non-zero exit fails the build.
How to interpret results
Each finding reports severity, rule_id, path:line:column, a redacted
preview of the value (never the full secret), and the measured entropy.
Severity guide:
- critical — live credential material (private keys, cloud secret keys, provider tokens). Rotate immediately.
- high — access key IDs, third-party API keys.
- medium — generic
password=/secret=assignments. - low — JWTs and other context-dependent values; verify before acting.
Recommended workflow for Claude
- Run the scanner with
--jsonand parse the findings. - For each finding, open the file at the reported line to confirm it is a real secret and not a placeholder/test fixture.
- Report confirmed leaks grouped by severity, and advise the user to rotate the credential (committing a fix does not un-leak git history).
- If the secret is in git history, recommend
git filter-repo/ BFG and credential rotation — deleting the line is not enough.
False positives
The engine already filters obvious placeholders (example, <your-key>,
xxxx, changeme, ${ENV}, etc.) and gates generic rules behind entropy.
If a finding is a known dummy value, treat it as noise. To re-check with
stricter entropy, raise --min-entropy.
Notes
- Binary files,
node_modules,.git, virtualenvs and oversized files are skipped automatically. - The scanner never prints full secret values — only redacted previews.