What problem does it solve?
This Skill helps authorized security teams identify exposed credentials, API keys, private keys, sensitive files, and infrastructure clues without relying on ad hoc searches or unsafe validation practices.
Core Features & Use Cases
- Secret Pattern Scanning: Apply a prioritized catalog of 48 provider-specific and generic secret patterns across code, JavaScript, source maps, mobile strings, archives, and public content.
- Dork-Based Discovery: Search 70 web dorks and 13 GitHub code-search queries across file exposures, administrative panels, cloud services, backups, documentation, and vulnerability indicators.
- Read-Only Verification: Validate supported Postman, AWS, GitHub, Slack, Anthropic, OpenAI, npm, Atlassian, and Datadog credentials using read-only endpoints while recording scope, detectability, and timestamps.
- Use Case: During an authorized engagement, scan public repositories and web results for leaked cloud or SaaS credentials, classify matches by severity, preserve evidence, and hand validated-live credentials to the appropriate gated follow-up workflow.
Quick Start
Use the secrets-and-dorks skill to scan the authorized target domain and its public code repositories for exposed secrets, classify matches, and report only read-only validation results.