doro-git-secrets-scannerGit 安全扫描器 - 检查提交中的敏感信息泄露(API keys、密码、token)
Install via ClawdBot CLI:
clawdbot install a2mus/doro-git-secrets-scannerGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Calls external URL not in known-safe list
https://github.com/gitleaks/gitleaks/releasesAudited Apr 17, 2026 · audit v1.0
Generated Mar 21, 2026
DevOps teams use this skill to integrate secret scanning into CI/CD pipelines, automatically checking every push and pull request for exposed credentials. It helps prevent accidental leaks before code reaches production, ensuring compliance with security policies and reducing breach risks.
Banks and fintech companies employ the scanner to audit git repositories for sensitive data like API keys and passwords, meeting regulatory requirements such as GDPR or PCI DSS. Regular scans help identify and remediate leaks, protecting customer financial information and avoiding hefty fines.
Healthcare organizations use the skill to scan for PHI or access tokens in version control, safeguarding patient data under HIPAA regulations. It enables proactive detection of secrets in codebases, minimizing data breach incidents and ensuring secure development practices.
E-commerce platforms leverage the scanner to monitor for payment gateway keys and database credentials in git commits, preventing fraud and data theft. By automating scans, they maintain secure checkout processes and protect user transaction data from exploitation.
Startups adopt this skill during early development to catch secrets like API tokens before public releases, avoiding costly security oversights. It provides a lightweight, automated way to enforce security best practices without extensive resources.
Offer a free basic scanning version with limited features, then charge for advanced capabilities like custom rule sets, priority support, and detailed analytics. This model attracts small teams and scales with enterprise needs, generating revenue through subscription tiers.
Bundle the scanner into a larger security platform targeting corporations, providing features such as centralized reporting, compliance dashboards, and integration with existing tools. Revenue comes from annual licenses and professional services for deployment and training.
Provide expert services to help organizations implement and customize the scanner, including security audits, remediation support, and developer workshops. This model leverages the tool to drive high-margin consulting engagements and ongoing maintenance contracts.
💬 Integration Tip
Start by adding a simple pre-commit hook with Gitleaks to catch secrets early, then gradually integrate into CI/CD pipelines for automated scans on every code change.
Scored Jun 19, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
GEO Audit — AI Search Visibility Checker for ChatGPT, Perplexity, Claude & Gemini. 29-point GEO readiness checklist: robots.txt AI crawler access, Index...
Audit and analyze Solidity smart contracts for security vulnerabilities. Use when reviewing, auditing, or analyzing smart contracts, Solidity code, DeFi prot...