Agent skill
secrets-guardian
Protect repositories from accidental secret commits. Essential when working with AI agents. Use when: setting up new project, adding pre-commit hooks, scanning for secrets, fixing leaked credentials. Triggers: "настрой защиту секретов", "setup secrets", "check secrets", "scan secrets", "проверь секреты", "pre-commit", "gitleaks". PROACTIVELY suggest when creating new projects or when .pre-commit-config.yaml is missing.
Install this agent skill to your Project
npx add-skill https://github.com/timequity/plugins/tree/main/vibe-coder/skills/secrets-guardian
SKILL.md
Secrets Guardian
Multi-layered protection against accidental secret commits. Critical for AI-assisted development where agents may not recognize sensitive data.
Quick Setup
For new projects, run this setup:
# 1. Check if pre-commit is installed
which pre-commit || pip install pre-commit
# 2. Copy pre-commit config from assets
# See assets/pre-commit-config.yaml
# 3. Create secrets baseline
echo '{"version": "1.5.0", "results": {}}' > .secrets.baseline
# 4. Install hooks
pre-commit install
pre-commit install --hook-type pre-push
# 5. Verify .gitignore has secret patterns
# See assets/gitignore-secrets
Commands
Setup Protection
When user says "настрой защиту секретов" or "setup secrets protection":
- Check existing setup:
ls -la .pre-commit-config.yaml .secrets.baseline .gitignore 2>/dev/null
-
If .pre-commit-config.yaml missing:
- Copy from
assets/pre-commit-config.yaml - Or add secret scanning hooks to existing config
- Copy from
-
Check .gitignore for secret patterns:
grep -E "\.env|\.key|API_KEY|secret" .gitignore
- If missing, append patterns from
assets/gitignore-secrets
- Create .secrets.baseline:
echo '{"version": "1.5.0", "results": {}}' > .secrets.baseline
- Install hooks:
pre-commit install
pre-commit install --hook-type pre-push
- Ask about CI/CD:
- "Добавить GitHub Actions workflow для проверки секретов в CI?"
- If yes, copy
assets/security-workflow.yamlto.github/workflows/
Scan for Secrets
When user says "проверь секреты" or "check secrets":
# Quick scan with gitleaks
gitleaks detect --no-git -v
# Detailed scan with detect-secrets
detect-secrets scan --all-files
Report findings and suggest fixes.
Fix Leaked Secret
When secret is detected:
-
Identify the secret type (API key, password, private key, etc.)
-
Suggest remediation:
- Move to
.envfile (ensure it's in .gitignore) - Use environment variable:
os.environ.get("API_KEY") - For false positives: update
.secrets.baseline
- Move to
-
If already committed:
- Rotate the credential immediately
- Consider git history cleanup (if not pushed)
- Warn about exposed secrets in git history
Update Baseline
For false positives, update the baseline:
detect-secrets scan --baseline .secrets.baseline
Proactive Checks
IMPORTANT: When working in any project, check for secret protection:
# Quick check
if [ ! -f .pre-commit-config.yaml ]; then
echo "WARNING: No pre-commit config found"
fi
If missing, ask user: "В проекте нет защиты от утечки секретов. Настроить?"
Reference Files
- Setup Guide - Detailed installation steps
- Tools Reference - gitleaks, detect-secrets, etc.
Asset Files
Copy these to project as needed:
assets/pre-commit-config.yaml- Pre-commit hooks configurationassets/gitignore-secrets- Patterns to add to .gitignoreassets/security-workflow.yaml- GitHub Actions CI workflow
Recommended Agent Skills
Expand your agent's capabilities with these related and highly-rated skills.
claude-code-course
Learn Claude Code in 5 hands-on lessons. From basics to building applications. Use when: user wants to learn Claude Code, asks "how do I...", or is new. Triggers: "learn", "teach me", "how does this work", "I'm new", "course".
foundations
Claude Code basics for new users. Covers essential concepts and commands. Use when: user is new to Claude Code or routed here by learning-path assessment.
advanced
Claude Code mastery for power users. Build agents, MCP servers, publish plugins. Use when: user wants to create agents, build integrations, or publish plugins.
lessons
Lesson content for Claude Code Course. Use when: loading lesson content. Internal skill - contains lesson files.
intermediate
Claude Code customization for comfortable users. Covers skills, commands, MCP, hooks. Use when: user knows basics and wants to customize Claude Code.
course-help
Help and navigation for Claude Code Course. Use when: user asks about the course, lessons, or progress. Triggers: "help", "course help", "what lessons", "my progress".
Didn't find tool you were looking for?