Secrets Leak Triage
$2.99OfficialUse when credentials may be exposed in code, config, logs, or git history: find them, judge real exposure, and drive rotation and cleanup.
securitysecuritysecretscredentialsgit-historyincident-responserotationยท by SkillingMain
What you get
- โ10-step procedure
- โ1 ready-to-run code block
- โ9-point quality checklist
- โ10 pitfalls to avoid
- โInstalls into 6 tools
- Version
- v1 โ
- Last updated
- today
- Length
- 9 min read
- Requires
- Best with a strong model (Claude Sonnet 4)
Works in: Claude Code, Codex, Cline, opencode, OpenClaw, Hermes ยท Handles multi-file projects
Preview
When to use
Invoke when a credential may be exposed, or when you must prove none is. Typical triggers:
- A scanner, pre-commit hook, CI gate, or provider alert fired on a possible credential.
- Before making a private repository public, transferring it, or sharing it with a third party.
- After an accidental commit or push of an env file, a config dump, or a notebook with output cells.
- A vendor or researcher reports an exposed key.
- Repository hygiene work: establish what is in the tree and in the history, and close the gap that let it in.
Use a different skill for general vulnerability review or third-party package risk.
Inputs to gather
- Remotes and visibility: every rem
โฆ
๐ Buy once ($2.99) to unlock the full playbook, download it, and install it in every tool you use.