Prevent secret leakage across git history, package artifacts, logs, and docs. Use when editing workflows, packaging configuration, environment files, or release automation.
Scanned 9/12/2026
Install to Claude Code
npx -y skills add aibot88/sec_skill_store --skill secret-exposure-prevention --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Secret Exposure Prevention?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/aibot88-secret-exposure-prevention)More formats (shields.io, HTML) on the badges page.
---
name: secret-exposure-prevention
description: Prevent secret leakage across git history, package artifacts, logs, and docs. Use when editing workflows, packaging configuration, environment files, or release automation.
---
# Secret Exposure Prevention
## When to use
- On changes involving `.env`, publish scripts, workflow files, and package include/exclude rules.
- Before packaging/publishing distributable artifacts.
- After any secret-handling incident or near-miss.
## Procedure
1. Identify secret-bearing file patterns in repo and tooling context.
2. Verify packaging exclude rules (`.vscodeignore`, `.npmignore`, artifact manifests).
3. Verify prevention controls (pre-commit scanning, CI scanning, secret scanning backstops).
4. Validate that examples and docs use placeholders, never live tokens.
5. Propose targeted guardrails with minimal operational overhead.
## Output format
- `risk_status`: low|medium|high
- `exposure_surfaces`: git|artifact|logs|docs
- `missing_controls`: specific missing guardrails
- `recommended_controls`: prevention-first controls in priority order
- `evidence`: files, workflows, and policies reviewed
## Standards
- Prevention first, detection second.
- Never accept shipping secret-bearing files in distributable artifacts.
- Keep false-positive handling explicit and auditable.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!
Playbook for creating and editing uCoz landing pages via MCP tools (`templates_tool`, `ftp_tool`, `modules_tool`). Use for tasks such as: "build a landing page", "update the homepage as a landing page", "create a promo page on the homepage", "add a lead form / menu / SEO to the homepage". Homepage: `page_list`, `page_get`; first publish — `page_update` with full `page_tmpl`; HTML edits after generation — `patch_template` (module_id=2, template_id=1), not `update_template`. Activate the mail f...
Interact with the Paperclip control plane API to manage tasks, coordinate with other agents, and follow company governance. Use when you need to check assignments, update task status, delegate work, post comments, set up or manage routines (recurring scheduled tasks), or call any Paperclip API endpoint. Do NOT use for the actual domain work itself (writing code, research, etc.) — only for Paperclip coordination.
Instantly.ai cold email outreach API - manage campaigns, leads, accounts, and analytics. Use for cold email automation, lead management, campaign creation/monitoring, and email account warmup.
Digital Audio Workstation usage, music composition, interactive music systems, and game audio implementation for immersive soundscapes.
Compress natural language memory files (CLAUDE.md, todos, preferences) into caveman format to save input tokens. Preserves all technical substance, code, URLs, and structure. Compressed version overwrites the original file. Human-readable backup saved as FILE.original.md. Trigger: /caveman-compress FILEPATH or "compress memory file"