Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add niels-emmer/myace --skill secrets-scan-checklistgit clone --depth 1 https://github.com/niels-emmer/myaceWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/niels-emmer/myace/secrets-scan-checklist)<a href="https://agentmods.dev/skills/niels-emmer/myace/secrets-scan-checklist"><img src="https://agentmods.dev/badge/skills/niels-emmer/myace/secrets-scan-checklist/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/niels-emmer/myace/secrets-scan-checklist"><img src="https://agentmods.dev/badge/skills/niels-emmer/myace/secrets-scan-checklist.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00036 | $0.00939 |
| Opus 5 | $0.00018 | $0.00469 |
| Sonnet 5 | $0.00007 | $0.00188 |
| Haiku 4.5 | $0.00004 | $0.00094 |
Grade A, and why
Secrets Scan Checklist scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 47 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Purpose
Give a reviewer a fast pattern-matching pass for credential-shaped strings, so secrets get caught by recognizable shape rather than relying on remembering to look for them. Pair this with the Secrets Are Always A Hard Fail rule — this skill is about finding the secret; that rule governs what happens next.
When to use it
At the start of every review, before looking at anything else — a live credential outranks every other finding in urgency, so it's worth checking first rather than stumbling into it halfway through. Also run it against commit history when a repository's history hasn't been checked before, not just the current diff — a secret removed in a later commit is still exposed in history.
Shapes to recognize
- Cloud/provider API keys — long fixed-prefix strings such as vendor keys that start with a recognizable literal prefix followed by 20+ alphanumeric characters. Don't rely on memorizing every vendor's exact prefix; the pattern (short literal prefix + long high-entropy suffix) is the signal.
- Generic tokens/secrets — high-entropy strings (mixed case, digits, length 32+) assigned to a variable or field named
token,secret,key,password,credential,auth, or similar, especially in config,.env-style files, or hardcoded as a default value. - Connection strings — URLs with a scheme like
postgres://,mysql://,mongodb://,redis://,amqp://that embed a username and password in the authority component (scheme://user:password@host/...). - Private key blocks — anything containing
-----BEGIN ... PRIVATE KEY-----(RSA, EC, OpenSSH, PGP), or.pem/.pfx/.p12file content pasted inline. - JWTs and session tokens — three base64url segments separated by dots (
eyJ...........), especially if hardcoded rather than generated at runtime. - Webhook/signing secrets — values assigned to names like
webhook_secret,signing_key,hmac_keysitting next to the verification code that's supposed to use them.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 47 lines · 36 tokens per session scan A 79af11164322
Secrets Scan Checklist is a skill published in the GitHub repository niels-emmer/myace (1 stars, last pushed 4d ago), licensed MIT. It adds 36 tokens to every session and 939 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
html-draft
Use when user wants a standalone HTML diagram in flat engineering blueprint style — architecture diagrams, system flows, technical spec sheets, component maps. Generates one HTML file using Tailwind v4 (browser CDN) for layout and D3 v7 (CDN) for SVG diagrams. User-invoked only — do NOT auto-trigger. Triggers on…
idea
Use when capturing ONE new idea the user voices and wants recorded — "save this idea", "I have an idea", "log this idea", "/idea", "idea: ...". Creates a provenance-tracked folder (one folder per idea) in your ideas repo, dedups against an index, optionally mirrors to a GitHub Project view filtered by label:idea. NOT…
pm-feedback
A feedback-analysis aid that turns spreadsheet data, CSV files, pasted text, or review screenshots into organized product insights. It groups themes, identifies sentiment, examines trends and sources, calculates NPS, and extracts user types.
weekly-planning
A planning workflow that turns a completed weekly review and existing backlog into prioritized outcomes for one ISO calendar week.
gh-issues
Use when creating, searching, updating, or managing GitHub issues via CLI. Triggers: "issue", "create issue", "gh issue", "task tracking", "context", "handoff", "resume task", "session context", "save progress", "active tasks", "in-progress", "my tasks", "open issues". Covers: gh commands, bulk operations, JSON/jq…
pm-brainstorm
A structured brainstorming session for exploring a specific product problem or opportunity and narrowing the results to ideas worth pursuing.