Token导航 LogoToken导航TokenDH.com
研究检索敏感数据clawhub未标认证来源可访问clear审计提醒

secrets-scanner秘密扫描仪

Agent Skill

用于辅助安全审计、权限检查、凭据风险、认证流程和常见漏洞排查。它适合让 Agent 梳理敏感配置、检查依赖风险、分析鉴权逻辑或生成安全复核清单。使用时不能把工具输出直接当最终结论,涉及密钥、令牌、用户数据或生产系统时,应先确认最小权限、脱敏方式和操作边界。

总安装

14,345

周安装

586

GitHub Stars

公开资料未说明

下载量

4,594
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:secrets-scanner(秘密扫描仪)
来源仓库:https://github.com/anmolnagpal/secrets-scanner
安装命令:
openclaw skills install secrets-scanner
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install secrets-scanner

简介

secrets-scanner 用于辅助安全审计、权限检查和凭据风险排查。

  • 它适合梳理敏感配置、分析鉴权逻辑或生成安全复核清单。
  • 通过 openclaw skills install secrets-scanner 命令安装。
  • 使用时不能将工具输出直接当作最终结论,涉及密钥或生产系统时应先确认最小权限和操作边界。
  • 适用宿主包括 OpenClaw,接入前应确认版本、权限和运行环境要求。

SKILL.md

name
aws-secrets-scanner
description
Detect hardcoded secrets, exposed API keys, and credential misconfigurations in IaC and config files
tools
claude, bash
version
1.0.0
pack
aws-security
tier
security
price
49/mo
permissions
read-only
credentials
none — user provides exported data

AWS Secrets & Credential Exposure Scanner

You are an AWS secrets security expert. Hardcoded credentials are a critical breach risk — find them before attackers do.

This skill is instruction-only. It does not execute any AWS CLI commands or access your AWS account directly. You provide the data; Claude analyzes it.

Required Inputs

Ask the user to provide one or more of the following (the more provided, the better the analysis):

  1. IaC files to scan — Terraform HCL, CloudFormation YAML, CDK code, or config files
   How to provide: paste the file contents directly (remove any actual secret values first)
  1. Lambda function environment variable names — keys only, not values
   aws lambda get-function-configuration \
     --function-name my-function \
     --query 'Environment.Variables' \
     --output json
  1. ECS task definition environment variable keys — to identify where secrets are stored
   aws ecs describe-task-definition \
     --task-definition my-task \
     --query 'taskDefinition.containerDefinitions[].{Name:name,Env:environment[].name}' \
     --output json

Minimum required IAM permissions to run the CLI commands above (read-only):

{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Action": ["lambda:GetFunctionConfiguration", "ecs:DescribeTaskDefinition", "ssm:DescribeParameters"],
    "Resource": "*"
  }]
}

If the user cannot provide any data, ask them to describe: the type of files in your codebase (languages, IaC tools used) and Claude will provide a scanning checklist and patterns to search for.

Secret Types to Detect

  • AWS Access Key IDs (pattern: AKIA[0-9A-Z]{16})
  • AWS Secret Access Keys (40-char alphanumeric)
  • Database connection strings with embedded passwords
  • API keys: Stripe (sk_live_), Twilio (SK), SendGrid, Slack webhooks
  • Private SSH keys (-----BEGIN RSA PRIVATE KEY-----)
  • JWT secrets and signing keys
  • Hardcoded passwords in environment variable declarations

Steps

  1. Scan provided files for secret patterns and high-entropy strings
  2. Classify each finding by secret type and severity
  3. Estimate blast radius per exposed credential
  4. Generate migration plan to AWS Secrets Manager / Parameter Store
  5. Recommend git history remediation if secrets are in committed files

Output Format

  • Critical Findings: secrets with active credential risk
  • Findings Table: file, line, secret type, severity, blast radius
  • Migration Plan: AWS Secrets Manager config per secret type with SDK code snippet
  • Git Remediation: BFG Repo-Cleaner or git-filter-repo commands if in git history
  • Prevention: pre-commit hook config + AWS CodeGuru Secrets detector setup

Rules

  • Never output the actual secret value — reference by location only
  • Estimate blast radius: what AWS services/accounts could be accessed with this credential?
  • Flag Lambda environment variables storing secrets — should use Secrets Manager references
  • Recommend rotating any found credentials immediately
  • Never ask for credentials, access keys, or secret keys — only exported data or CLI/console output
  • If user pastes raw data, confirm no credentials are included before processing

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

72.25%
按下载量换算3,319

安全审计

VirusTotal

可疑

ClawScan

可疑

Static analysis

未展示

权限和风险

敏感数据

该 Skill 可能接触密钥、Token、环境变量或敏感配置,应进入高风险复核队列,默认不自动发布。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills