skylv-smart-secrets-scannerIntelligent secrets detection and prevention — scan code, configs, and git history for exposed API keys, passwords, tokens, and credentials
Install via ClawdBot CLI:
clawdbot install sky-lv/skylv-smart-secrets-scannerGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Hardcoded API key or token pattern found in skill definition
AKIAIOSFODNN...Audited May 10, 2026 · audit v1.0
Generated May 21, 2026
Integrate the scanner into CI/CD pipelines (e.g., GitHub Actions, Jenkins) to block deployments when critical secrets are detected in code or configuration files. This prevents accidental exposure of API keys or tokens during automated builds and releases.
Use the git-scan capability to audit repositories for secrets that were committed and later removed. This is crucial for incident response when a suspected leak has occurred, allowing teams to identify all affected files and rotate credentials before attackers exploit them.
Install the pre-commit hook across developer machines to automatically scan code for secrets before commits are finalized. This prevents sensitive data from ever entering the repository, reducing remediation costs and improving security posture from the start.
Schedule regular scans of codebases and configuration repositories to ensure no hardcoded credentials exist. This supports compliance requirements by demonstrating proactive credential management and reducing the risk of data breaches.
Run scans on sample codebases or during security workshops to show developers common places where secrets are exposed (e.g., .env files, logs). The scanner’s auto-remediation suggestions educate teams on proper secret management practices.
Offer a free tier that scans up to a certain number of files or repositories, with paid tiers for unlimited scans, advanced patterns (e.g., custom regex), and integration with CI/CD tools. Revenue comes from monthly subscriptions.
Provide a fee-based service where the scanner is used to audit a client’s entire codebase and git history, producing a detailed report. This appeals to companies needing a one-off security assessment before a launch or after a breach.
License the scanner as a plugin or add-on for existing DevSecOps platforms (e.g., GitHub Marketplace, GitLab, Jenkins). Revenue comes from per-seat licensing or a percentage of sales through the platform.
💬 Integration Tip
Start with a simple `node scanner.js scan ./` in your project root, then automate via CI/CD by adding a step that runs the scanner and fails the build on critical findings.
Scored May 21, 2026
Security-first skill vetting for AI agents. Use before installing any skill from ClawdHub, GitHub, or other sources. Checks for red flags, permission scope,...
全面排查企业的经营风险情况,适用于供应商准入尽调、贷前风险筛查、合作伙伴背景调查等场景,全方位预警潜在经营风险,辅助决策者规避合作隐患。
Security scanner for AI agent skills. 9 built-in detection signatures. Identifies secrets, unsafe execution patterns, and prompt injection. Sub-50ms results.
Wallet anti-theft guard. One-click scan for high-risk wallet approvals to protect user assets. Use when a user asks for a wallet security check, wallet healt...
Comprehensive security audit for an agent's full skill stack. Chains scanner, differ, trust-verifier, and health-monitor into a single assessment with priori...
Audit and score OpenClaw AgentSkills against structural compliance, quality standards, and OpenClaw-specific architecture patterns. Produces a 0-100 score wi...