Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/smicolon/ai-kitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/commands/smicolon/ai-kit/infisical-scan)<a href="https://agentmods.dev/commands/smicolon/ai-kit/infisical-scan"><img src="https://agentmods.dev/badge/commands/smicolon/ai-kit/infisical-scan/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/commands/smicolon/ai-kit/infisical-scan"><img src="https://agentmods.dev/badge/commands/smicolon/ai-kit/infisical-scan.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00016 | $0.00886 |
| Opus 5 | $0.00008 | $0.00443 |
| Sonnet 5 | $0.00003 | $0.00177 |
| Haiku 4.5 | $0.00002 | $0.00089 |
Grade A, and why
infisical-scan scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 143 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Infisical Scan Command
Scan the codebase for exposed secrets, API keys, and hardcoded credentials.
Parse Arguments
Extract from user input:
- mode:
directory(default),git-history, orstaged
Workflow
Step 1: Check CLI Available
which infisical && infisical --version
Step 2: Choose Scan Mode
Ask the user which scan to run:
- Directory Scan - Scan all files in current directory
- Git History Scan - Scan git commit history for leaked secrets
- Staged Only - Scan only staged files (pre-commit check)
Step 3a: Directory Scan
# Scan current directory
infisical scan
# Scan specific path
infisical scan --path=./src
# Scan with verbose output
infisical scan -v
Step 3b: Git History Scan
# Scan all git history
infisical scan git-changes
# Scan recent changes only
infisical scan git-changes --staged
Step 3c: Staged Files Only
# Scan only staged files (ideal for pre-commit)
infisical scan git-changes --staged
Step 4: Analyze Results
Review scan output and categorize findings by severity:
- Critical: AWS keys, database connection strings, private keys, tokens with write access
- High: API keys, OAuth secrets, webhook secrets
- Medium: Internal URLs, non-production credentials
- Low: Example/placeholder values that look like secrets
Step 5: Remediate Findings
For each real secret found:
-
Move to Infisical:
infisical secrets set LEAKED_KEY=<actual-value> --env=dev -
Remove from code and replace with environment variable:
# Before (hardcoded) api_key = "sk_live_abc123" # After (from environment) api_key = os.environ["API_KEY"] -
Rotate the credential - any secret found in git history should be considered compromised:
- Regenerate the key/token in the provider's dashboard
- Update the new value in Infisical
- Revoke the old credential
-
Verify cleanup:
infisical scan
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 6d ago First seen · 143 lines · 16 tokens per session scan A d2a00abc75b3
infisical-scan is a command published in the GitHub repository smicolon/ai-kit (6 stars, last pushed 6d ago), licensed MIT. It adds 16 tokens to every session and 886 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other commands, from other repositories
commit-push-pr
An automated Git workflow that checks a project, synchronizes documentation, commits changes, and can create or merge a GitHub pull request. A pull request is a request for teammates to review and add changes to a shared codebase.
auto
An automated coding workflow runs a software task from planning through code changes, checks, and a pull request. A pull request is a proposed change for review before it is merged into the main codebase.
sync
A command that pulls the latest code from the main Git branch and updates the project's key planning and instruction documents to match it.
pull
A quick command that downloads the latest commits from the main Git branch into the current project.
worktree-cleanup
A command for removing a Git worktree, which is a separate working folder linked to the same repository, after its pull request is merged.
quick-commit
A quick Git command for committing and pushing a small code change. Git is the tool that records code versions and sends them to a shared repository.