Secleak Check
Workflow
- Confirm cwd and repo root.
- For a scan request, run the bundled script from this skill, not a target-repo script.
- For a setup request, add repo-local guardrails from
references/guardrails.md. - Quote exact failing tool output, but never print raw secret values.
- If the bundled script is unavailable, use the manual fallback commands below.
Bundled command
Resolve scripts/secleak-check.sh relative to this SKILL.md.
Common installed path:
/Users/kregenrek/.agents/skills/secleak-check/scripts/secleak-check.sh
Manual fallback
betterleaks git --no-banner --redact=100 .
trivy fs --scanners vuln,secret,misconfig --exit-code 1 .
Prefer .betterleaks.toml when present. If only .gitleaks.toml exists, pass --config .gitleaks.toml; BetterLeaks supports it for compatibility.
Reporting
betterleaksfindings are blockers until verified false-positive or remediated.- For historical leaks, report file, line, commit, rule, and fingerprint only.
trivydependency vulnerabilities should be summarized by severity and top fixed versions.- Misconfig findings inside
node_modulesare dependency artifact noise unless that file is built or shipped by the repo.
Guardrail setup
When asked to harden a repo against secret leaks:
- Inventory existing
.betterleaks.toml,.gitleaks.toml, secret-scan workflows, Dependabot, and hook tooling. - Add
.forbidden-paths.regexand a staged-file hook. - Add
.betterleaks.tomlwith path-based filters only for fixtures. - Add repo-local
scripts/secleak-check.shonly when the repo wants a first-class local script. - Add CI secret scanning and Dependabot when GitHub Actions are in scope.
- Update
.gitignorefor runtime dirs, env files, credentials, keys, and infra state.
Templates live in references/guardrails.md; small examples live in references/examples.md.