TacoSkill LAB
TacoSkill LAB
HomeSkillHubCreatePlaygroundSkillKit
© 2026 TacoSkill LAB
AboutPrivacyTerms
  1. Home
  2. /
  3. SkillHub
  4. /
  5. scanning-for-secrets
Improve

scanning-for-secrets

4.3

by majiayu000

108Favorites
77Upvotes
0Downvotes

Detect exposed secrets, API keys, and credentials in code. Use when auditing for secret leaks. Trigger with 'scan for secrets', 'find exposed keys', or 'check credentials'.

secretscredentialssecurity-audit

4.3

Rating

0

Installs

Security

Category

Quick Review

The skill provides a clear overview and well-structured documentation for secret scanning functionality. The description adequately covers what the skill does and when to use it. However, taskKnowledge is weak - the skill references a 'secret-scanner plugin' but provides no concrete implementation details, specific commands, regex patterns, or actual scanning tools (e.g., truffleHog, gitleaks, detect-secrets). The Instructions section is generic security guidance rather than actionable secret-scanning steps. Structure is good with logical sections and clear examples. Novelty is moderate - while secret scanning is valuable, the skill lacks sophisticated implementation that would meaningfully reduce token usage beyond what a CLI agent could accomplish with standard tools. To improve, add concrete bash commands, specific pattern libraries, and actual tool integrations rather than conceptual references to a non-existent plugin.

LLM Signals

Description coverage6
Task knowledge4
Structure7
Novelty5

GitHub Signals

49
7
1
1
Last commit 0 days ago

Publisher

majiayu000

majiayu000

Skill Author

Related Skills

security-reviewersecure-code-guardianrepomix-safe-mixer

Loading SKILL.md…

Try onlineView on GitHub

Publisher

majiayu000 avatar
majiayu000

Skill Author

Related Skills

security-reviewer

Jeffallan

6.4

secure-code-guardian

Jeffallan

6.4

repomix-safe-mixer

daymade

7.4

apktool

BrownFineSecurity

6.9
Try online