Secrets detection
SkillFiles & storageFind leaked secrets in code, git history, and CI. Load on "secrets", "leaked key", a repo/ git history in scope, exposed .git, CI config review, or public-repo OSINT. Signals: API keys, tokens, .env files, private keys, cloud creds, hardcoded passwords.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Secrets detection skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/code-review/code-review-secrets-detection/SKILL.md and read by ahel’s review.
When it applies
Any source you can read: an in-scope repo, an exposed .git/ on a web server, public GitHub
repos of the org, or CI/CD config. Live secrets are direct, high-impact findings.
Why it works
Secrets get committed and then "removed" — but git keeps history, so they persist in old commits, branches, and stashes. Config/CI files and client bundles also embed keys that ship to users.
Method
- Scan history, not just HEAD:
trufflehog git file://. --only-verifiedorgitleaks detect --source . -v— these walk every commit and (trufflehog) verify keys live. - Exposed .git on a target:
git-dumper http://target/.git/ out/then scan the recovered repo. - Org-wide OSINT: GitHub dorks /
trufflehog github --org=<org>for public leaks (in scope only). - Client-side & config: grep JS bundles, mobile apps,
.env, Dockerfiles, k8s manifests, CI YAML for keys and tokens. - Validate & scope impact: confirm the key works with a read-only call (e.g.
aws sts get-caller-identity) — a live, privileged key is the report; a dead one is informational.
Gotchas
- Report verified/live secrets; example/placeholder keys inflate severity and get closed as N/A.
- Rotate-awareness: note it may be live now; don't exfiltrate data with it — prove access, stop.
- Deleted-from-HEAD ≠ gone — always scan full history.
Verify success
A secret that authenticates successfully (minimal proof), with where it lives (commit/file) — don't paste the secret value into reports, reference its location.
References
trufflehog & gitleaks docs; GitHub secret-scanning; OWASP secrets management.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
code-review-secrets-detection- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · thedaviddias
The pick for JavaScriptmodern-javascript-patterns
Skill · wshobson
The pick for JavaScriptaudit-dependencies
Skill · stbenjam
The pick for Dependenciesreview-dependencies
Skill · tobihagemann
The pick for Dependenciessecrets-exposure-review
Skill · naodeng
The pick for Secretssecrets-with-git-crypt
Skill · derailed-dash
The pick for Secrets