What problem does it solve?
This Skill reduces the risk of credential leaks by producing a structured, evidence-based review of secrets detection, exposure paths, rotation, and vault integration aligned to OWASP and NIST guidance.
Core Features & Use Cases
- Structured secrets management assessment that maps findings to OWASP Secrets Management and NIST SP 800-57 Part 1 Rev 5, including severity and remediation.
- Detection coverage review for secret scanning tooling and configuration (e.g., Gitleaks, TruffleHog, detect-secrets) with guidance to avoid placeholder-driven false positives.
- Exposure and lifecycle checks for .env handling, Docker/IaC miswiring, git history scanning, centralized secrets managers, and agent/JIT credential patterns.
Quick Start
Run a secrets management review against the target repository by asking the AI to perform an OWASP/NIST-aligned assessment focusing on detection patterns, .env and vault integration, rotation automation, and git history risks for the provided path.