Getting it into your agent
There is no command for this one: it runs only inside a plugin, and the catalogue could not identify which plugin ships it. The source is linked below.
Wrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/bestdeejay-design/agent-skills/secret-scanner)<a href="https://agentmods.dev/skills/bestdeejay-design/agent-skills/secret-scanner"><img src="https://agentmods.dev/badge/skills/bestdeejay-design/agent-skills/secret-scanner/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/bestdeejay-design/agent-skills/secret-scanner"><img src="https://agentmods.dev/badge/skills/bestdeejay-design/agent-skills/secret-scanner.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00084 | $0.01602 |
| Opus 5 | $0.00042 | $0.00801 |
| Sonnet 5 | $0.00017 | $0.00320 |
| Haiku 4.5 | $0.00008 | $0.00160 |
Grade A, and why
secret-scanner scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 141 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Secret Scanner — leaked credential detection
Load this skill when you need to scan a codebase, directory, or git repo for leaked secrets/tokens/keys (before publishing a repo, before a release, or during security review).
The scanner is static and offline by design: patterns come from the gitleaks v8.30.3 default config, the canonical open-source secret-detection rule set, and detection uses the same Shannon-entropy gating semantics as gitleaks. No network calls are made — a format match is reported as potential, not verified.
The scanner script
scripts/secret_scanner.py — pure Python 3 stdlib (no dependencies).
| Source | Command |
|---|---|
| File | python3 secret_scanner.py --path path/to/file |
| Directory (recursive) | python3 secret_scanner.py --path path/to/dir |
| Git repo (tracked files) | secret_scanner.py --git /path/to/repo |
| stdin (blob) | `cat file |
Detected pattern families (19 rules)
Critical: AWS Access Key ID (AKIA/ASIA/ABIA/A3T…) & secret key,
GitHub PAT classic/fine-grained/refresh tokens, OpenAI (sk-*T3BlbkFJ*),
Anthropic (sk-ant-api03-…AA), Stripe (sk_live_/rk_live_),
Google API key (AIza…), private keys (PEM/OpenSSH/PGP blocks).
High: Slack app/bot/user tokens and webhooks, Perplexity (pplx-…).
Medium: JWT, generic keyword-anchored API keys.
False-positive suppression (allowlists)
- Placeholders:
$VAR,${VAR},{{ }},%VAR%,true/false/null,****,EXAMPLE,xxxx,your-,placeholder,TODO— never reported - Noise paths:
node_modules/,vendor/,.git/, lockfiles (package-lock.json,go.sum,poetry.lock, …), minified JS, binaries, images, fonts - Entropy gate: every entropy-sensitive rule skips values whose Shannon entropy ≤ rule minimum (gitleaks semantics)
Capabilities
--json/--markdown/ text (default) report formats--redact N— mask secrets in output (keeps first N chars; CI-safe)--max-mb N— skip huge files (default 10 MB)--exit-code— exit 1 when findings present (CI gate), else 0
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 141 lines · 84 tokens per session scan A 5569f8a6e565
secret-scanner is a skill published in the GitHub repository bestdeejay-design/agent-skills (5 stars, last pushed 3d ago), licensed MIT. It adds 84 tokens to every session and 1,602 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
workflow
Use when a task is too large for turn-by-turn orchestration and should run through the big-task workflow lane: system-wide changes, large migrations, repo-wide audits, high-confidence verification, or tasks explicitly asking to run a workflow. Claude Code uses native dynamic workflows; Codex, OpenCode, and Grok use…
skill-compiler
Automatic solved-to-skill compiler — detects novel task completions and autonomously drafts new SKILL.md files. Stolen from Hermes Agent's learning loop (NousResearch, 2026-05-11).
context-compactor
9-section context compression with analysis scratchpad. Adapted from Claude Code's /compact system (2026-03-31).
daemon-loop
Autonomous recurring agent tasks — converts workflows into persistent background daemons that run on intervals. Stolen from Boris Cherny's Claude Code /loop pattern (2026-03-31).
trade-journal-analyzer
Unified post-trade analytics: journal pattern extraction + drawdown classification. Absorbs: drawdown-classifier.
Deep Research Loop
Multi-step web research, compilation, and synthesis workflow. Scrapes multiple sources, cross-references claims, and produces a structured research brief.