# Leaked secrets scan (/security--secrets-scan)

/security--secrets-scan is a Claude Code skill in the Code section. Scans your code, config files and recent git history for API keys, tokens, passwords and private keys, and explains how to remediate each.

- Web version: https://skills.sgomez.dev/en/s/security--secrets-scan
- Section: [Code](https://skills.sgomez.dev/en/code.md)
- Author: Santiago Gómez de la Torre
- License: MIT
- Source: https://github.com/sgomez-dev/claude-skills/blob/main/skills/security/secrets-scan.md
- Updated 26 Mar 2026

## How to ask for it

- `/security--secrets-scan scan the repo for leaked API keys`
- `/security--secrets-scan check for exposed credentials before pushing to GitHub`
- `/security--secrets-scan scan the whole project for forgotten tokens`

## Install

macOS · Linux:

```
curl -fsSL https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.sh | bash
```

Windows:

```
irm https://raw.githubusercontent.com/sgomez-dev/claude-skills/main/install.ps1 | iex
```

Claude Code plugin:

```
/plugin marketplace add sgomez-dev/claude-skills
/plugin install security-skills@claude-skills-collection
```

## Permissions

- Reads: `**/*`, `.git/**`
- Writes: —
- Runs: `git log`
- Network: No
- Destructive: No

## Author's description

Scan codebase for leaked secrets, API keys, tokens, and credentials

## Pairs well with

- [Pre-deployment checklist (/devops--deploy-check)](https://skills.sgomez.dev/en/s/devops--deploy-check.md): Runs a checklist before you ship, covering code quality, security, database and configuration, to catch problems before release.
- [Dependency vulnerability check (/security--dependency-vuln)](https://skills.sgomez.dev/en/s/security--dependency-vuln.md): Runs your package manager's audit and lists each vulnerable dependency with its CVE, severity, fixed version and a remediation plan.
- [Performance audit (/performance--perf-audit)](https://skills.sgomez.dev/en/s/performance--perf-audit.md): Audits your backend and frontend code for bottlenecks and lists each finding with its location, estimated impact and a specific fix.
- [Test coverage gaps (/testing--test-coverage)](https://skills.sgomez.dev/en/s/testing--test-coverage.md): Finds which code your tests don't cover, ranks the gaps by risk and generates tests for the highest-priority ones.
- [OWASP security audit (/security--security-audit)](https://skills.sgomez.dev/en/s/security--security-audit.md): Audits your codebase against the OWASP Top 10 and returns each finding with severity, file and line, a description and a fix.
- [Login and permissions review (/security--auth-review)](https://skills.sgomez.dev/en/s/security--auth-review.md): Reviews your app's login, sessions, tokens and access rules and returns severity-rated findings, each with a specific fix.
- Recipe: [/pipeline--pre-deploy](https://github.com/sgomez-dev/claude-skills/blob/main/pipelines/pre-deploy.yaml): Pre-Deploy
- Recipe: [/pipeline--security-hardening](https://github.com/sgomez-dev/claude-skills/blob/main/pipelines/security-hardening.yaml): Security Hardening

- [How we review this](https://skills.sgomez.dev/en/methodology.md)
