Sponsor Suno AI Music arrow_forward
Plugin

Secret Scanner

Scan codebase for exposed secrets, API keys, passwords, and sensitive credentials

Type
Plugin
GitHub stars
2.8k
License
MIT
Repo last updated
Sep 27, 2026
Version
1.24.0
Author
Jeremy Longshore

What Secret Scanner is

Secret Scanner is a plugin published in the jeremylongshore/tons-of-skills-marketplace repository on GitHub, which has about 2.8k stars. The repository describes itself as: “Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com.”

A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.

Installing Secret Scanner adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.

How to install Secret Scanner

Claude Code

  1. Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace
  2. Install the plugin: claude plugin install secret-scanner@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
  3. Restart the session if the new skills or commands don't appear straight away.

Claude Cowork

  1. Open Customize → Plugins and choose Add marketplace.
  2. Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub).
  3. Find Secret Scanner in the list, click Install, then connect any connectors it needs from its Connectors tab.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from plugins/security/secret-scanner/.claude-plugin/plugin.json, shared under the repository's MIT license. Read the full file on GitHub.

Scan codebase for exposed secrets, API keys, passwords, and sensitive credentials with pattern matching and entropy analysis.

Features

  • Multi-Platform API Keys - AWS, GCP, Azure, Stripe, GitHub, etc.
  • Pattern Matching - Known secret formats
  • Entropy Analysis - Detect random strings that may be secrets
  • Git History Scanning - Find secrets in commit history
  • Comprehensive Reporting - File locations and remediation steps
  • Pre-commit Integration - Prevent secret commits

Installation

/plugin install secret-scanner@claude-code-plugins-plus

Usage

# Scan current directory
/scan-secrets

# Or use shortcut
/secrets

What It Detects

API Keys & Tokens

  • AWS Access Keys
  • Google API Keys
  • Azure Storage Keys
  • Stripe API Keys
  • GitHub Personal Access Tokens
  • Slack Tokens
  • Twilio API Keys
  • SendGrid API Keys
  • Mailgun API Keys

Credentials

  • Database passwords
  • SMTP credentials
  • FTP credentials
  • SSH private keys
  • PGP private keys

Tokens

  • OAuth tokens
  • JWT tokens
  • Session tokens
  • Bearer tokens

High-Entropy Strings

  • Base64-encoded secrets
  • Hexadecimal keys
  • Random-looking strings (>4.5 entropy)

Example Report

SECRET SCAN REPORT
==================
Scan Date: 2025-10-11
Secrets Found: 4

CRITICAL SECRETS
----------------

1. AWS Access Key Exposed
   File: src/config/aws.js:12
   Pattern: AKIA[0-9A-Z]{16}
   Value: AKIA****************WXYZ (masked)

   Immediate Actions:
   1. Revoke this key in AWS IAM Console
   2. Generate new access key
   3. Store in environment variable or AWS Secrets Manager
   4. Remove from git history:
…

Remediation Guide

For Exposed API Keys

# 1. Revoke the exposed key immediately
# (Use provider's console/CLI)

# 2. Remove from current files
# Replace with environment variable
export API_KEY="new-key-here"

# 3. Remove from git history
git filter-repo --path config/keys.js --invert-paths

# 4. Add to .gitignore
echo "config/keys.js" >> .gitignore

For Configuration Files

# Create template file
cp .env .env.example
# Remove sensitive values from .env.example

# Add .env to .gitignore
echo ".env" >> .gitignore

# Document required variables
cat > .env.example << EOF
# Required environment variables
API_KEY=your_api_key_here
DATABASE_URL=your_database_url_here
EOF

Best Practices

  1. Prevention
  • Use environment variables
  • Implement pre-commit hooks
  • Use secret management tools (Vault, AWS Secrets Manager)
  • Review code before committing
  1. Detection
  • Run scans regularly
  • Scan git history periodically
  • Monitor CI/CD logs
  • Enable secret scanning in GitHub/GitLab
  1. Response
  • Rotate exposed secrets immediately
  • Remove from git history
  • Update documentation
  • Notify security team
  1. Secret Management
  • Use HashiCorp Vault
  • Use cloud provider secret managers
  • Use encrypted configuration
  • Implement proper access controls

Pre-commit Hook

Add to .git/hooks/pre-commit:

#!/bin/bash
if /plugin secret-scanner | grep -q "CRITICAL"; then
    echo "ERROR: Secrets detected! Commit blocked."
    exit 1
fi

Requirements

  • Read access to codebase
  • Read access to git history
  • Write access for remediation scripts

License

MIT License - See LICENSE file for details

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Secret Scanner?

Secret Scanner is a plugin for Claude Code and Claude Cowork from the jeremylongshore/tons-of-skills-marketplace repository on GitHub. Scan codebase for exposed secrets, API keys, passwords, and sensitive credentials

How do I install Secret Scanner in Claude Code?

Add the repository as a plugin marketplace: claude plugin marketplace add jeremylongshore/tons-of-skills-marketplace Install the plugin: claude plugin install secret-scanner@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.

Can I use Secret Scanner in Claude Cowork?

Open Customize → Plugins and choose Add marketplace. Enter jeremylongshore/tons-of-skills-marketplace (the owner/repo shorthand works for GitHub). Find Secret Scanner in the list, click Install, then connect any connectors it needs from its Connectors tab.

Is Secret Scanner safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under MIT. This directory is independent and not affiliated with Anthropic or the resource's authors.