Secret Scanner
Scan codebase for exposed secrets, API keys, passwords, and sensitive credentials
- Type
- Plugin
- Repository
- jeremylongshore/tons-of-skills-marketplace
- GitHub stars
- 2.8k
- License
- MIT
- Repo last updated
- Sep 27, 2026
- Version
- 1.24.0
- Author
- Jeremy Longshore
What Secret Scanner is
Secret Scanner is a plugin published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Secret Scanner adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Secret Scanner
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace
- Install the plugin: claude plugin install secret-scanner@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub).
- Find Secret Scanner in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/security/secret-scanner/.claude-plugin/plugin.json, shared under the repository's MIT license. Read the full file on GitHub.
Scan codebase for exposed secrets, API keys, passwords, and sensitive credentials with pattern matching and entropy analysis.
Features
- Multi-Platform API Keys - AWS, GCP, Azure, Stripe, GitHub, etc.
- Pattern Matching - Known secret formats
- Entropy Analysis - Detect random strings that may be secrets
- Git History Scanning - Find secrets in commit history
- Comprehensive Reporting - File locations and remediation steps
- Pre-commit Integration - Prevent secret commits
Installation
/plugin install secret-scanner@claude-code-plugins-plusUsage
# Scan current directory
/scan-secrets
# Or use shortcut
/secretsWhat It Detects
API Keys & Tokens
- AWS Access Keys
- Google API Keys
- Azure Storage Keys
- Stripe API Keys
- GitHub Personal Access Tokens
- Slack Tokens
- Twilio API Keys
- SendGrid API Keys
- Mailgun API Keys
Credentials
- Database passwords
- SMTP credentials
- FTP credentials
- SSH private keys
- PGP private keys
Tokens
- OAuth tokens
- JWT tokens
- Session tokens
- Bearer tokens
High-Entropy Strings
- Base64-encoded secrets
- Hexadecimal keys
- Random-looking strings (>4.5 entropy)
Example Report
SECRET SCAN REPORT
==================
Scan Date: 2025-10-11
Secrets Found: 4
CRITICAL SECRETS
----------------
1. AWS Access Key Exposed
File: src/config/aws.js:12
Pattern: AKIA[0-9A-Z]{16}
Value: AKIA****************WXYZ (masked)
Immediate Actions:
1. Revoke this key in AWS IAM Console
2. Generate new access key
3. Store in environment variable or AWS Secrets Manager
4. Remove from git history:
…Remediation Guide
For Exposed API Keys
# 1. Revoke the exposed key immediately
# (Use provider's console/CLI)
# 2. Remove from current files
# Replace with environment variable
export API_KEY="new-key-here"
# 3. Remove from git history
git filter-repo --path config/keys.js --invert-paths
# 4. Add to .gitignore
echo "config/keys.js" >> .gitignoreFor Configuration Files
# Create template file
cp .env .env.example
# Remove sensitive values from .env.example
# Add .env to .gitignore
echo ".env" >> .gitignore
# Document required variables
cat > .env.example << EOF
# Required environment variables
API_KEY=your_api_key_here
DATABASE_URL=your_database_url_here
EOFBest Practices
- Prevention
- Use environment variables
- Implement pre-commit hooks
- Use secret management tools (Vault, AWS Secrets Manager)
- Review code before committing
- Detection
- Run scans regularly
- Scan git history periodically
- Monitor CI/CD logs
- Enable secret scanning in GitHub/GitLab
- Response
- Rotate exposed secrets immediately
- Remove from git history
- Update documentation
- Notify security team
- Secret Management
- Use HashiCorp Vault
- Use cloud provider secret managers
- Use encrypted configuration
- Implement proper access controls
Pre-commit Hook
Add to .git/hooks/pre-commit:
#!/bin/bash
if /plugin secret-scanner | grep -q "CRITICAL"; then
echo "ERROR: Secrets detected! Commit blocked."
exit 1
fiRequirements
- Read access to codebase
- Read access to git history
- Write access for remediation scripts
License
MIT License - See LICENSE file for details
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Secret Scanner?
Secret Scanner is a plugin for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. Scan codebase for exposed secrets, API keys, passwords, and sensitive credentials
How do I install Secret Scanner in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace Install the plugin: claude plugin install secret-scanner@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Secret Scanner in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub). Find Secret Scanner in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Secret Scanner safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Advisor Use this agent when the User asks for health, fitness, nutrition, or longevity guidance tailored to adults 50+, or when they describe physical symptoms, fatigue, lab results, metabolic markers, joint pain, or sleep issues — even without explicitly asking for health advice. Subagent · jeremylongshore/tons-of-skills-marketplace
- Adobe Pack Operate Adobe Firefly, Photoshop v2, PDF Services, I/O Events, App Builder, and enterprise access through 30 evidence-backed skills with safe auth, data, spend, deployment, and recovery boundaries. Plugin · jeremylongshore/tons-of-skills-marketplace
- Agent Context Manager Automatically detects and loads AGENTS.md files to provide agent-specific instructions alongside CLAUDE.md. Enables specialized agent behaviors without manual intervention. Plugin · jeremylongshore/tons-of-skills-marketplace
- Ai Agent Create Create a new specialized AI agent with custom tools, handoff rules, and Slash Command · jeremylongshore/tons-of-skills-marketplace
- Secrets Manager Integrator Integrate with secrets managers (Vault, AWS Secrets Manager, etc) Plugin · jeremylongshore/tons-of-skills-marketplace
- Secops Team Security Operations Team — 10 agents: Red, Blue, Hunt, Patch, Chain, Sast, Siem, Resp, Zero, Phish Plugin · jeremylongshore/tons-of-skills-marketplace
- Security Audit Reporter Generate comprehensive security audit reports Plugin · jeremylongshore/tons-of-skills-marketplace
- Search To Slack Enhances web_search Skill by posting formatted research digests to Slack channels Plugin · jeremylongshore/tons-of-skills-marketplace