secret-scan
Installation
SKILL.md
Secret Scan
Core Question
Does the current diff, staged set, or repository context contain secret-like material that must not be exposed, committed, or pushed?
When To Use
Use this skill when:
- staged, unstaged, untracked, release, changelog, or tag content may contain credentials
- preflight detects sensitive-looking files or values
- a confidential file may have been committed
- the user asks whether secrets are present
- a secret may already have been committed or pushed
When Not To Use
Do not use this skill when: