secrets-scan
Detect hardcoded credentials, API keys, tokens, and secrets in source code and configuration files. Use when reviewing code for leaked secrets before commit/merge, auditing a repository for credential exposure, or setting up secret detection.
How do I install this agent skill?
npx skills add https://github.com/owasp/secure-agent-playbook --skill secrets-scanIs this agent skill safe to install?
- Gen Agent Trust Hubpass
This skill is a defensive security tool designed to identify hardcoded secrets and credentials in source code. It follows security best practices by recommending redaction of discovered secrets and utilizing established scanning utilities.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
What does this agent skill do?
Secrets Scan
Detect hardcoded secrets by following the full procedure in plays/secrets-scan.md.
Steps
-
Run Automated Scanner — Use available tools in preference order:
trufflehog filesystem --directory=<path> --json(recommended)trufflehog git file://<repo> --json(includes git history)gitleaks detect --source=<path> --report-format=jsondetect-secrets scan <path> --all-files- If no scanner available, proceed with manual pattern analysis.
-
Manual Pattern Analysis — Search for high-confidence patterns:
- AWS keys (
AKIA...), OpenAI (sk-...), Anthropic (sk-ant-...), GitHub (ghp_...), Slack (xoxb-...), Stripe (sk_live_...), SendGrid (SG.) - Connection strings with embedded passwords (
://user:pass@host) - Private keys (PEM headers), JWT secrets, database credentials
- High-risk files:
.env,docker-compose*.yml,*.tfvars,terraform.tfstate,kubeconfig,.npmrc,.pypirc
- AWS keys (
-
Contextual Analysis — For each detection: Is it real (not a placeholder/test fixture)? Is it active? What's the blast radius (service, permissions, prod vs dev, exposure duration)?
-
Check Preventive Controls — Verify:
.gitignorecovers sensitive files, pre-commit hooks for secret scanning, CI pipeline scanning, secrets management documentation.
Important: Never include actual secret values in findings. Show redacted versions only (e.g., AKIA****EXAMPLE). Active production secrets require immediate rotation.
Output
Scan summary, findings using templates/finding.md, preventive controls checklist, and immediate rotation actions if needed.
OWASP References
- A07:2021: Identification and Authentication Failures
- CWE-798: Use of Hard-coded Credentials
- CWE-312: Cleartext Storage of Sensitive Information
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/owasp/secure-agent-playbook/secrets-scan">View secrets-scan on skillZs</a>