CtrlK
BlogDocsLog inGet started
Tessl Logo

secrets-audit

Find leaked secrets in source code, Git history, build artifacts, and infrastructure — and audit the secrets-management posture preventing future leaks. Use when the user mentions 'secrets audit,' 'secret scanning,' 'leaked credentials,' 'API key in code,' 'gitleaks,' 'trufflehog,' 'git history scan,' 'secrets management,' 'vault audit,' 'rotation policy,' 'AWS Secrets Manager,' 'HashiCorp Vault,' 'Doppler,' '1Password Secrets Automation,' 'sealed-secrets,' 'External Secrets Operator,' or needs to find or prevent credential exposure.

72

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

88%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sequenced skill body with executable commands, validation-gated triage, and destructive-operation safeguards. The relative weak spots are mild framing prose and a monolithic single-file structure with no progressive disclosure into bundle files.

Suggestions

Trim the editorial framing sentences (e.g., "the part people forget", the "Most secret leaks aren't 'we forgot to redact'..." opener) to tighten conciseness without losing operational value.

Consider moving the provider-key-prefix grep library and/or the build-artifact leakage list into a references/ file referenced from SKILL.md, so the body stays a lean overview and progressive disclosure can reach the top anchor.

DimensionReasoningScore

Conciseness

The body is information-dense and assumes Claude's knowledge (no explaining what a secret or git is), with every section delivering operational value; a few framing sentences ("the part people forget", "Most secret leaks aren't 'we forgot to redact'...") are light padding that could be trimmed, keeping it just below the lean anchor.

4 / 5

Actionability

It provides copy-paste-ready, executable grep patterns, git history/trufflehog/gitleaks/bfg commands, docker history checks, and provider verification calls (aws sts get-caller-identity, stripe balance retrieve) that cover the common cases concretely.

5 / 5

Workflow Clarity

The 7-step triage workflow has explicit validation checkpoints ("Verify it's live — ... don't assume", rotate-before-revoke, rotate first then history-rewrite), and the destructive history-rewrite operation is gated by an explicit coordination/confirmation requirement, satisfying the destructive-operation validation cap.

5 / 5

Progressive Disclosure

Content is organized into clear Part 1 / Part 2 / Output Format / Boundaries / References sections with well-signaled inline cross-references to sibling skills; with no bundled reference files present the operational detail is appropriately inline, leaving only minor organization gaps versus a fully split structure.

4 / 5

Total

18

/

20

Passed

Description

91%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, trigger-rich description that clearly states what the skill does and when to use it, with comprehensive natural keywords. The only soft spot is slight overlap with adjacent security-audit skills on a few provider/manager terms.

DimensionReasoningScore

Specificity

"Find leaked secrets in source code, Git history, build artifacts, and infrastructure" and "audit the secrets-management posture" name concrete actions across four surfaces, but the skill is really two macro-verbs (find, audit) expanded over locations rather than a long list of distinct actions, so it sits just below the comprehensive anchor.

4 / 5

Completeness

It explicitly answers both "what" (find leaked secrets across four surfaces and audit secrets-management posture) and "when" ("Use when the user mentions ... or needs to find or prevent credential exposure") with concrete trigger phrases.

5 / 5

Trigger Term Quality

The "Use when" clause enumerates a comprehensive set of natural terms users would say, including tool names (gitleaks, trufflehog), provider names (AWS Secrets Manager, HashiCorp Vault, Doppler, 1Password Secrets Automation, sealed-secrets, External Secrets Operator), and synonyms (secrets audit, secret scanning, leaked credentials, API key in code, git history scan).

5 / 5

Distinctiveness Conflict Risk

The secrets/credential-exposure niche is clear and the tool- and provider-specific triggers are distinct, but several terms (HashiCorp Vault, AWS Secrets Manager, External Secrets Operator) overlap with the cross-referenced iam-audit and dependency-audit skills, leaving minor conflict risk.

4 / 5

Total

18

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

allowed_tools_field

'allowed-tools' contains unusual tool name(s)

Warning

Total

15

/

16

Passed

Repository
briiirussell/cybersecurity-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.