vibe-sanitizerUse this skill when an agent needs to scan a Git repository for secrets, credentials, or machine-specific file paths, then sanitize safe findings in place or...
Install via ClawdBot CLI:
clawdbot install macoloye/vibe-sanitizerGrade Fair — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval(Audited Apr 17, 2026 · audit v1.0
Generated Oct 5, 2026
A developer is about to commit changes to a personal project and wants to ensure no API keys or credentials leak into the repository history. They run the skill's working-tree scan to identify any secrets, then use in-place sanitization on fixable findings before committing.
A team has rapidly built a prototype with AI-assisted coding and wants to share it on GitHub. They scan the tracked files for machine-specific paths and embedded credentials, then export a sanitized copy for public release.
A DevOps engineer integrates the skill into a CI pipeline to audit staged changes before deployment. The scan flags any bearer tokens or AWS keys, preventing accidental exposure in production environments.
A freelance developer is preparing to hand off a codebase to a client and needs to remove local workspace paths and temporary credentials. They use the tracked scope audit and create a sanitized export to deliver a clean repository.
An open source maintainer receives a pull request and wants to verify it doesn't introduce secrets or leak contributor machine paths. They run a commit audit on the PR's SHA and summarize findings without exposing raw values.
The core CLI remains free and open source, while advanced detectors (e.g., custom regex patterns, enterprise-grade secret types) and team dashboards are offered as a paid add-on. This drives adoption through developer trust and upsells security-conscious organizations.
Offer a hosted service that continuously scans repositories for secrets, integrates with GitHub/GitLab, and provides alerting and remediation workflows. Customers pay based on the number of repositories or seats monitored.
Provide expert consulting to help teams integrate secret scanning into their SDLC, along with training workshops on secure coding practices. Revenue comes from one-time engagements and ongoing retainer contracts.
💬 Integration Tip
Run the bundled CLI from `{{skill_dir}}/src` and always start with a `scan` before using `sanitize` or `export`; never auto-rewrite review-required findings without explicit user approval.
Scored Oct 5, 2026
1Password Connect API skill. Use when working with 1Password Connect for activity, vaults, heartbeat. Covers 15 endpoints.
Complete guide for using pass, the standard Unix password manager. Use this skill whenever the user asks about pass, password-store, managing passwords from...
Set up and use 1Password CLI (op). Use when installing the CLI, enabling desktop app integration, signing in (single or multi-account), or reading/injecting/...
Rotate and update secrets in environment files, generate Vault commands, and manage secret rotation workflows.
Headless plugin for 1Password secrets using service accounts, resolving op:// references, reading/writing secrets, and listing vault items via JS SDK.
Secure credential exchange with auto-expiry for Pilot Protocol agents. Use this skill when: 1. You need to share API keys, tokens, or credentials securely be...