Secrets Scanner

SkillMonitoring & ops

Hunt for leaked credentials - hardcoded API keys, tokens, private keys, passwords and connection strings in code, config, logs and git history. Use for /unmask, pre-commit secret sweeps, or "did we leak a key?" questions.

Use Secrets Scanner in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add Secrets Scanner and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the Secrets Scanner skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Secrets ScannerStart free

What this skill tells your AI

The instructions your AI receives, as published by navinspire-ia/navin in navin/skills/secrets-scanner/SKILL.md and read by Ahel’s review.

Overview

Find secrets that should never be in the repository, ranked by how exploitable the leak is. A committed live production key is critical; a placeholder in an example file is informational. Every finding cites file, line, and the secret type (never echo the full secret value - show a masked prefix only).

What to detect

ClassSignals
Cloud keysAKIA… (AWS), AIza… (Google), Azure connection strings, GCP service-account JSON
TokensGitHub ghp_/gho_, Slack xox…, Stripe sk_live_, JWT secrets, bearer tokens
Private keys`-----BEGIN (RSA
Passwordspassword=, passwd, basic-auth in URLs, DB connection strings with creds
Generichigh-entropy strings assigned to secret/token/apikey/key names

Workflow

  1. Call security_scan(kind=secrets) first for structured baseline findings.
  2. Scan the working tree deeply: source, config, .env*, CI files, Dockerfiles, notebooks, and infra manifests.
  3. Then scan git history (git log -p, git rev-list) - a secret removed in a later commit is still exposed and must be rotated.
  4. Prefer real tooling when present (gitleaks, trufflehog, detect-secrets); use pattern sweeps for what they miss.
  5. Triage false positives: test fixtures, obvious placeholders (xxx, changeme, example), and public keys are not leaks - mark them Info.
  6. For each real finding, mask the value (sk_live_51H… → sk_live_51H•••), and give the response: rotate the credential, remove from history if committed, and move to a secret manager / env var.
  7. Recommend prevention: .gitignore rules, pre-commit secret scanning, and a secrets baseline.

Anti-patterns

  • Printing the full secret in the report (mask it)
  • Flagging placeholders and test fixtures as critical leaks
  • Assuming deletion from the current tree is enough (history still leaks; rotation is mandatory)
  • Rotating or editing anything without an explicit request

Signals

GitHub stars
36
Forks
4
Last commit
Oct 2026
Advanced
Item type
skill
Key
secrets-scanner-navinspire-ia
Source
github.com/navinspire-ia/navin