Semgrep Secret Scan

Run Semgrep Secrets scanning to detect leaked credentials, API keys, passwords, and access tokens in source code. Use this skill whenever the user asks to scan for secrets, detect leaked credentials, find API keys in code, run secret detection, check for hardcoded passwords, or mentions "semgrep secrets", "secret scan", "credential scan", "key leak", or "token exposure". Also trigger when the user wants to scan Git history for leaked secrets, validate whether detected secrets are still active, or audit a repository for sensitive data exposure. This skill connects to the Semgrep AppSec Platform cloud instance for enhanced detection with semantic analysis, entropy analysis, and HTTP validation of discovered secrets.

vchirrav-eng Updated

File contents

vchirrav-eng/product-security-ai-skills/tree/main/secret-scan-semgrep commit 05f3a89cdb

Frequently asked questions

npx skillmds@latest add vchirrav-eng/semgrep-secret-scan