credential-scannerScans files, repos, and directories for leaked secrets — API keys, tokens, passwords, connection strings, private keys, and credentials. Detects 40+ secret p...
Install via ClawdBot CLI:
clawdbot install nirwandogra/credential-scannerGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://hooks\.slack\.com/services/T[A-Z0-9]+/B[A-Z0-9]+/[A-Za-z0-9]+Uses known external API (expected, informational)
slack.comAudited Apr 16, 2026 · audit v1.0
Generated Mar 21, 2026
Development teams can integrate this skill into their CI/CD pipelines or pre-commit hooks to automatically scan code changes for leaked secrets before they are committed to version control. This prevents accidental exposure of credentials in repositories, reducing security risks and compliance violations.
During cloud migration projects, organizations can use this skill to scan legacy codebases and configuration files for hardcoded credentials related to on-premises systems or new cloud providers. This ensures that no sensitive keys are transferred unintentionally, enhancing security posture.
Companies can employ this skill to audit code from third-party vendors or open-source dependencies for exposed secrets before integration. This helps identify potential security flaws in external software, mitigating supply chain attacks and protecting intellectual property.
Organizations in regulated industries like finance or healthcare can use this skill to perform periodic scans of their codebases to ensure compliance with data protection standards such as GDPR or HIPAA. It detects unauthorized storage of credentials, aiding in audit trails and risk management.
Offer a basic version of the skill for free to individual developers and small teams, with premium features like advanced reporting, API integrations, and team management available through subscription plans. This model drives adoption and generates recurring revenue from enterprises.
License the skill as part of a larger security suite for enterprises, integrating it with existing DevOps tools and SIEM systems. Provide dedicated support, customization, and compliance certifications to attract large organizations with complex security needs.
Offer consulting services where security experts use the skill to conduct audits, provide remediation guidance, and set up automated scanning workflows for clients. This model adds value through personalized support and ongoing security monitoring.
💬 Integration Tip
Integrate this skill into CI/CD pipelines using simple bash commands or as a pre-commit hook to automate secret detection and prevent leaks early in the development cycle.
Scored Jun 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...