Back to skill

Security audit

Secrets Audit

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent secrets scanner, but it needs review because it can expose detected secrets in reports and can read outside the chosen folder through symlinks.

Install only if you are comfortable with a local scanner reading the full project you point it at. Avoid running it on untrusted repositories until symlink handling is fixed, treat its output files and CI logs as sensitive, and verify or pin any optional prevention tools before installing them.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Error
Location
scripts/scan_secrets.py:136
Finding

Symbolic Links Can Escape the Requested Scan Root

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/scan_secrets.py:198
Finding

Detected Credentials Are Exposed in Plaintext Reports

Content
View full analysis
60 else ''), 'context': context[:200], }) ``` ```python lines.append(f' Match: {finding["match"]}') ``` ```python if args.format == 'json': output = json.dumps({ 'project': project_path, 'files_scanned': files_scanned, 'files_skipped': files_skipped, 'elapsed_seconds': round(elapsed, 1), 'findings': unique_findings, 'summary': { 'high': len([f for f in unique_findings if f['severity'] == 'HIGH']), 'medium': len([f for f in unique_findings if f['severity'] == 'MEDIUM']), 'low': len([f for f in unique_findings if f['severity'] == 'LOW']), 'total': len(unique_findings), } }, indent=2) ``` ```python if args.output: with open(args.output, 'w', encoding='utf-8') as f: f.write(output) print(f'Report written to {args.output}') else: print(output) ``` ### Technical Analysis The scanner stores up to 60 characters of every detected value and up to 200 characters of surrounding source context. Text reports print the captured match, while JSON reports serialize the entire finding, including its context. Many credentials are shorter than 60 characters and are therefore disclosed in full. Even when the `match` field is truncated, the `context` field can contain the complete credential. If output is written to a file, the file is created using the process's default permissions and current `umask`, without explicitly requiring owner-only access. A secrets-detection tool should avoid reproducing the sensitive materi ...[truncated 1155 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
references/prevention-guide.md:10
Finding

Installation Guidance Uses Unpinned Executable Dependencies

Content
View full analysis
Remediation
View remediation
``` 2. Verify the selected release or commit using a documented checksum or cryptographic signature before installation. 3. Pin `pre-commit` to a reviewed version: ```bash python3 -m pip install 'pre-commit==' ``` 4. For reproducible installations, provide a requirements file containing exact versions and hashes and install it with `--require-hashes`. 5. Recommend installation in an isolated virtual environment rather than the global Python environment. 6. Avoid instructing users to execute build or installation scripts directly from a newly cloned mutable branch. 7. Periodically review and update pinned versions through a controlled dependency-update process. ]]>
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (20)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 3)May include surrounding context.

md
---
name: secrets-audit
description: Scan projects and codebases for exposed secrets, API keys, tokens, passwords, and sensitive credentials. Detects hardcoded secrets in source code, config files, environment files, and git history. Use when asked to audit a project for secrets, check for exposed credentials, scan for API keys, find hardcoded passwords, review security of a codebase, check for leaked tokens, audit .env files, or verify no secrets are committed. Triggers on "secrets audit", "scan for secrets", "find exposed keys", "check for credentials", "security scan", "leaked secrets", "hardcoded passwords", "API key exposure", "credential check".
---

# Secrets Audit

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/prevention-guide.md (reported line 71)May include surrounding context.

md
---
name: secrets-audit
description: Scan projects and codebases for exposed secrets, API keys, tokens, passwords, and sensitive credentials. Detects hardcoded secrets in source code, config files, environment files, and git history. Use when asked to audit a project for secrets, check for exposed credentials, scan for API keys, find hardcoded passwords, review security of a codebase, check for leaked tokens, audit .env files, or verify no secrets are committed. Triggers on "secrets audit", "scan for secrets", "find exposed keys", "check for credentials", "security scan", "leaked secrets", "hardcoded passwords", "API key exposure", "credential check".
---

# Secrets Audit

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/scan_secrets.py (reported line 95)May include surrounding context.

python
---
name: secrets-audit
description: Scan projects and codebases for exposed secrets, API keys, tokens, passwords, and sensitive credentials. Detects hardcoded secrets in source code, config files, environment files, and git history. Use when asked to audit a project for secrets, check for exposed credentials, scan for API keys, find hardcoded passwords, review security of a codebase, check for leaked tokens, audit .env files, or verify no secrets are committed. Triggers on "secrets audit", "scan for secrets", "find exposed keys", "check for credentials", "security scan", "leaked secrets", "hardcoded passwords", "API key exposure", "credential check".
---

# Secrets Audit

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 14)May include surrounding context.

md
python3 scripts/scan_secrets.py /path/to/project

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 17)May include surrounding context.

md
python3 scripts/scan_secrets.py /path/to/project

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 20)May include surrounding context.

md
python3 scripts/scan_secrets.py /path/to/project

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 23)May include surrounding context.

md
python3 scripts/scan_secrets.py /path/to/project

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 91)May include surrounding context.

md
python3 scripts/scan_secrets.py /path/to/project

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/prevention-guide.md (reported line 72)May include surrounding context.

text
# Environment files
.env
.env.local
.env.*.local
.env.production
.env.staging

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/prevention-guide.md (reported line 74)May include surrounding context.

md
.env
.env.local
.env.*.local
.env.production
.env.staging

# Key files

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/prevention-guide.md (reported line 86)May include surrounding context.

*.jks

Credentials

credentials.json service-account*.json *-credentials.json

text

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · references/prevention-guide.md (reported line 88)May include surrounding context.

*.jks

Credentials

credentials.json service-account*.json *-credentials.json

text

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/scan_secrets.py (reported line 57)May include surrounding context.

python
('Stripe Publishable Key', r'pk_live_[0-9a-zA-Z]{24,}', 'MEDIUM', 'Stripe live publishable key'),

    # GitHub
    ('GitHub Token', r'gh[pousr]_[A-Za-z0-9_]{36,}', 'HIGH', 'GitHub personal access token'),
    ('GitHub OAuth', r'gho_[A-Za-z0-9]{36}', 'HIGH', 'GitHub OAuth token'),

    # Generic tokens/keys

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/scan_secrets.py (reported line 219)May include surrounding context.

python
deleted_files = [f for f in result.stdout.split('\n') if f.strip()]

        # Check for sensitive deleted files
        sensitive_patterns = ['.env', 'credentials', 'secret', '.pem', '.key', 'id_rsa']
        for f in deleted_files:
            for pattern in sensitive_patterns:
                if pattern in f.lower():

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
87% confidence
Finding

The skill instructs use of file access and shell execution (python3 scripts/scan_secrets.py, directory walking, git history scanning) but does not declare any explicit tool scope or permission boundaries. That creates unnecessary ambiguity about what the agent may read or execute, increasing the risk of overbroad filesystem access or command execution against unintended paths.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The trigger list includes broad phrases like security scan, check for credentials, and review security of a codebase, which can cause this skill to activate for general security requests outside narrow secret scanning. Overbroad activation is dangerous because the skill has shell and filesystem-oriented behavior, so it may be invoked in contexts where users did not intend a repo-wide scan or git-history inspection.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/scan_secrets.py (reported line 212)May include surrounding context.

python
"""Scan git history for previously committed secrets."""
    findings = []
    try:
        result = subprocess.run(
            ['git', '-C', project_path, 'log', '--diff-filter=D', '--name-only', '--pretty=format:'],
            capture_output=True, text=True, timeout=30
        )

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/scan_secrets.py (reported line 235)May include surrounding context.

python
break

        # Check commit messages for secret-related keywords
        result = subprocess.run(
            ['git', '-C', project_path, 'log', '--oneline', '-50', '--all'],
            capture_output=True, text=True, timeout=30
        )

File System Enumeration

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Code scans file system directories looking for sensitive files. This could be reconnaissance for credential theft.

Content

Scanner excerpt · scripts/scan_secrets.py (reported line 327)May include surrounding context.

python
files_scanned = 0
    files_skipped = 0

    # Walk the directory tree
    for root, dirs, files in os.walk(project_path):
        # Skip directories in-place
        dirs[:] = [d for d in dirs if d not in SKIP_DIRS]

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
83% confidence
Finding

This code performs a file write via the --output path, which is a safety-relevant operation under the rule. Although the script's overall purpose is scanning, the argparse help only describes output path selection and the nearby code provides no prior warning, confirmation, or comment disclosing that user-specified files will be created or overwritten.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.