secrets-and-dorks

Detect exposed credentials and sensitive infrastructure indicators in public attack-surface data.

4|Updated Apr 29, 2026
One-click install
npx skills add https://github.com/Ap6pack/outrider-recon --skill secrets-and-dorks
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: secrets-and-dorks
Source: https://github.com/Ap6pack/outrider-recon/tree/main/skills/secrets-and-dorks
Command: npx skills add https://github.com/Ap6pack/outrider-recon --skill secrets-and-dorks

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

This Skill helps authorized security teams identify exposed credentials, API keys, private keys, sensitive files, and infrastructure clues without relying on ad hoc searches or unsafe validation practices.

Core Features & Use Cases

  • Secret Pattern Scanning: Apply a prioritized catalog of 48 provider-specific and generic secret patterns across code, JavaScript, source maps, mobile strings, archives, and public content.
  • Dork-Based Discovery: Search 70 web dorks and 13 GitHub code-search queries across file exposures, administrative panels, cloud services, backups, documentation, and vulnerability indicators.
  • Read-Only Verification: Validate supported Postman, AWS, GitHub, Slack, Anthropic, OpenAI, npm, Atlassian, and Datadog credentials using read-only endpoints while recording scope, detectability, and timestamps.
  • Use Case: During an authorized engagement, scan public repositories and web results for leaked cloud or SaaS credentials, classify matches by severity, preserve evidence, and hand validated-live credentials to the appropriate gated follow-up workflow.

Quick Start

Use the secrets-and-dorks skill to scan the authorized target domain and its public code repositories for exposed secrets, classify matches, and report only read-only validation results.

Frequently Asked Questions about secrets-and-dorks

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find exposed API keys and secrets in public GitHub code?

You can find exposed API keys in GitHub code by applying 13 specific GitHub code-search queries and 48 prioritized secret patterns across repositories. This identifies cloud credentials and sensitive infrastructure indicators during authorized security reconnaissance.

What is read-only validation for leaked credentials?

Read-only validation for leaked credentials is the process of verifying exposed keys using non-destructive endpoints. This Skill validates supported AWS, GitHub, Slack, OpenAI, and other credentials while recording scope, detectability, and timestamps without modifying data.

How do I use web dorks to scan an attack surface for sensitive files?

You can scan an attack surface for sensitive files by applying 70 web dorks across file exposures, administrative panels, cloud services, and backups. This reveals exposed documentation and vulnerability indicators in authorized public web search results.

Can I detect secrets in JavaScript, source maps, and mobile strings?

Yes, you can detect secrets in JavaScript, source maps, and mobile strings. The scanning applies 48 provider-specific and generic secret patterns across these formats, alongside archives and public documentation, to identify exposed credentials.

Does secret scanning work on Wayback captures and Postman workspaces?

Yes, secret scanning works on Wayback captures and Postman workspaces. The process detects exposed credentials and sensitive files in these sources, applying read-only verification to supported Postman credentials during authorized public attack-surface reconnaissance.

What is the best way to classify and handle validated-live credentials?

The best way to handle validated-live credentials is through severity classification, evidence tracking, and policy-gated handoff. After scanning and read-only validation, matches are classified by severity and passed to appropriate gated follow-up workflows.