Secret Scanner
PassAudited by ClawScan on Feb 18, 2026.
Overview
The skill's code, instructions, and requirements are consistent with a local secret-scanning tool and do not request unrelated credentials or install external components.
This skill appears to be a local secret-scanning tool (no network calls or external installs are declared). Before running it, review the included secret_scanner.py yourself (or run it in a disposable/containerized environment) to confirm there are no unexpected network calls. Be aware the scanner will read your repository files and produce a report that may contain masked previews of secrets — if it finds real credentials, rotate them immediately and follow the remediation steps. Since the agent can invoke skills, only allow this skill access to directories you want scanned and avoid granting it blanket access to sensitive system paths.
