Detect exposed secrets, API keys, credentials, and tokens in code. Use before commits, on file saves, or when security is mentioned. Prevents accidental secret exposure. Triggers on file changes, git commits, security checks, .env file modifications.
Detect and prevent exposed secrets, API keys, and credentials
// You type:
const stripeKey = 'sk_live_1234567890abcdef';
// Instant alert:
🚨 CRITICAL: Exposed Stripe API key!
🔧 Fix: const stripeKey = process.env.STRIPE_SECRET_KEY;
Blocks commits with exposed secrets:
git commit
# 🚨 Cannot commit - secrets detected!
# 1. Move to .env file
echo "API_KEY=your_key" > .env
# 2. Add to .gitignore
echo ".env" >> .gitignore
# 3. Use in code
const key = process.env.API_KEY;
See SKILL.md for full documentation.
npx skills add alirezarezvani/secret-scanner下载完整 Skill 目录,包含 SKILL.md 及所有相关文件
Search for places (restaurants, cafes, etc.) via Google Places API proxy on localhost.
Interact with GitHub using the `gh` CLI. Use `gh issue`, `gh pr`, `gh run`, and `gh api` for issues, PRs, CI runs, and advanced queries.
Create or update AgentSkills. Use when designing, structuring, or packaging skills with scripts, references, and assets.
Start voice calls via the OpenClaw voice-call plugin.
Notion API for creating and managing pages, databases, and blocks.
Gemini CLI for one-shot Q&A, summaries, and generation.
Category:developer