secret-management-attack

Map leaked credentials across code, containers, cloud, and CI/CD pipelines.

60|14|Updated Apr 27, 2026
One-click install
npx skills add https://github.com/brucesongs/kali-claw --skill secret-management-attack
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: secret-management-attack
Source: https://github.com/brucesongs/kali-claw/tree/main/skills/secret-management-attack
Command: npx skills add https://github.com/brucesongs/kali-claw --skill secret-management-attack

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill consolidates discovery, SAST auditing, and secrets-management exploitation into a comprehensive, playbook-driven approach for locating and assessing credential leakage across repos, images, cloud, and CI/CD pipelines.

Core Features & Use Cases

  • Discovery & scanning of git history, filesystem, containers, APKs, and web assets to surface hardcoded secrets and tokens.
  • SAST & secret-management playbooks for vaults, cloud secret managers, CI secrets, and Kubernetes secrets, including OPSEC-aware verification and blast-radius mapping.
  • End-to-end lifecycle from scope definition through pivoting across platforms to a masked, evidence-driven report.

Quick Start

Run a targeted secret-hunting engagement across a test repo to surface hardcoded credentials and assess their blast radius.

Frequently Asked Questions about secret-management-attack

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find leaked credentials across git history and containers?

Secret management exploitation involves testing vaults, cloud secret managers, and Kubernetes secrets for exposed credentials. This Skill provides SAST and secret-management playbooks to verify leaked tokens and map their blast radius with OPSEC controls.

Can I assess Kubernetes secrets and CI/CD pipeline tokens for blast radius?

Yes, you can assess Kubernetes secrets and CI/CD pipeline tokens for blast radius. This Skill maps credential leakage across clusters and pipelines, verifying exposed tokens to determine their impact and pivoting potential across platforms.

What is the best way to scan APKs and web assets for hardcoded secrets?

The best way to scan APKs and web assets for hardcoded secrets is a targeted discovery process that inspects compiled applications and live web surfaces. This Skill consolidates discovery and SAST auditing to surface exposed credentials in those formats.

How do I generate a masked, rotation-ready report after finding leaked cloud secrets?

To generate a masked, rotation-ready report after finding leaked cloud secrets, you need an evidence-driven lifecycle from scope definition to reporting. This Skill produces masked reports detailing cloud secret exploitation and blast-radius mapping.

Does credential discovery work with mounted images and git histories simultaneously?

Credential discovery works with mounted images and git histories simultaneously by applying a unified scanning playbook across repos and containers. This Skill guides end-to-end assessment to surface hardcoded tokens across both surfaces with OPSEC controls.