secrets-scan

v2026.09.25

Detect hardcoded credentials, API keys, tokens, and secrets in source code and configuration files. Use when reviewing code for leaked secrets before commit/merge, auditing a repository for credential exposure, or setting up secret detection.

GitHub
安装命令
npx skhub add owasp/secrets-scan
Markdown
SKILL.md

Secrets Scan

Detect hardcoded secrets by following the full procedure in plays/secrets-scan.md.

Steps

  1. Run Automated Scanner — Use available tools in preference order:

    • trufflehog filesystem --directory=<path> --json (recommended)
    • trufflehog git file://<repo> --json (includes git history)
    • gitleaks detect --source=<path> --report-format=json
    • detect-secrets scan <path> --all-files
    • If no scanner available, proceed with manual pattern analysis.
  2. Manual Pattern Analysis — Search for high-confidence patterns:

    • AWS keys (AKIA...), OpenAI (sk-...), Anthropic (sk-ant-...), GitHub (ghp_...), Slack (xoxb-...), Stripe (sk_live_...), SendGrid (SG.)
    • Connection strings with embedded passwords (://user:pass@host)
    • Private keys (PEM headers), JWT secrets, database credentials
    • High-risk files: .env, docker-compose*.yml, *.tfvars, terraform.tfstate, kubeconfig, .npmrc, .pypirc
  3. Contextual Analysis — For each detection: Is it real (not a placeholder/test fixture)? Is it active? What's the blast radius (service, permissions, prod vs dev, exposure duration)?

  4. Check Preventive Controls — Verify: .gitignore covers sensitive files, pre-commit hooks for secret scanning, CI pipeline scanning, secrets management documentation.

Important: Never include actual secret values in findings. Show redacted versions only (e.g., AKIA****EXAMPLE). Active production secrets require immediate rotation.

Output

Scan summary, findings using templates/finding.md, preventive controls checklist, and immediate rotation actions if needed.

OWASP References

  • A07:2021: Identification and Authentication Failures
  • CWE-798: Use of Hard-coded Credentials
  • CWE-312: Cleartext Storage of Sensitive Information
发现
标签

此技能尚未发布标签。

版本
最新版本元数据

版本

v2026.09.25

发布时间

Sep 25, 2026

分类

未分类

许可证

NOASSERTION

源路径

plugins/code-security-skills/skills/secrets-scan

默认分支

main

最新提交

79fea6b

Tree SHA

6d787d7