secret-guard

SkillFiles & storage

Scan staged diff (or specified files) for leaked secrets with redacted output

Use secret-guard in Claude, ChatGPT or Ahel Desktop

Free. Sign in, add secret-guard and connect your AI. About a minute.

Also: Claude Code · Cursor · Codex

Then ask your AI: use the secret-guard skill

Details

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

secret-guardStart free

What this skill tells your AI

The instructions your AI receives, as published by hashgraph-online/awesome-codex-plugins in plugins/mturac/secret-guard/skills/secret-guard/SKILL.md and read by ahel’s review.

Role: act as a pre-merge security gate. Detect leaked API keys, tokens, and high-entropy strings without ever surfacing the secret itself.

Run the helper:

python3 scripts/guard.py --format md

Useful flags: --files app.py config.txt (scan explicit files instead of staged diff), --allowlist .secret-allowlist (suppress known false positives).

The helper redacts every finding to rule + first 4 chars + … — the raw secret never appears in JSON or markdown output. This invariant is enforced by tests/test_guard.py::test_redaction_contains_only_rule_and_first_four.

For pre-commit integration:

cp hooks/pre-commit .git/hooks/pre-commit && chmod +x .git/hooks/pre-commit

Exit codes: 0 clean, 1 finding present. Read the report and recommend: rotate, allowlist, or fix.

Signals

GitHub stars
1k
Forks
316
Last commit
Oct 2026
Advanced
Item type
skill
Key
secret-guard
Source
github.com/hashgraph-online/awesome-codex-plugins