Skip to content
Back to skills

Quickstart

CSecurity

Use this skill when the user wants to scan for leaked credentials, API keys, secrets in git repos, files, or CI/CD pipelines.

  • 54 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 6, 2026
toolsbashdockergitapici/cdsecurity

Works with

  • api

Security analysis

C71/100
  • criticalPipes output to a shell interpreter
  • mediumUses curl or wget to download content
  • criticalDownloads and executes remote scripts — classic supply chain attack

Pro shows the line behind each finding and how to fix it

Scanned September 6, 2026

npx -y skills add javimosch/supercli --skill quickstart --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Quickstart?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Quickstart
[![Security: C — Skills Directory](https://www.skillsdirectory.com/api/skills/javimosch-quickstart-a7b96ca6/badge)](https://www.skillsdirectory.com/skills/javimosch-quickstart-a7b96ca6)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: trufflehog
description: Use this skill when the user wants to scan for leaked credentials, API keys, secrets in git repos, files, or CI/CD pipelines.
---

# TruffleHog Plugin

Find and verify leaked credentials in git repositories, filesystems, Docker images, S3, GCS, and more.

## Commands

### Scanning
- `trufflehog git scan <repo-url>` — Scan a git repository
- `trufflehog filesystem scan <path>` — Scan files/directories
- `trufflehog docker scan <image>` — Scan a Docker image

### Output
- `trufflehog git <repo> --json` — JSON output for CI/CD
- `trufflehog filesystem <path> --json` — JSON output for automation

## Usage Examples

- Scan current directory: `trufflehog filesystem .`
- Scan git repo: `trufflehog git https://github.com/user/repo --json`
- Only verified: `trufflehog git <repo> --results verified`

## Installation

```bash
curl -sSfL https://raw.githubusercontent.com/trufflesecurity/trufflehog/main/scripts/install.sh | sh
```

## Examples

```bash
# Scan a repo for secrets
trufflehog git https://github.com/user/repo

# JSON output for CI/CD
trufflehog filesystem . --json --fail

# Scan Docker image
trufflehog docker --image nginx:latest

# Scan S3 bucket
trufflehog s3 --bucket my-bucket
```

## Key Features
- Detects 800+ secret types
- Active verification against APIs
- JSON output for CI/CD integration
- Scans git history (including deleted commits)
- Docker, S3, GCS, filesystem support

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…