mcpbeat Sign in

Detecting Secrets Agent Skill

This skill should be used when the user asks to "find hardcoded secrets", "audit for credential leaks", "check for API keys in code", "review secret scanning alerts", "rotate a leaked secret", or needs to detect hardcoded credentials, review secret handling patterns, or remediate exposed secrets.

2k tokens
context cost
the whole folder, loaded on every use
1
files
instructions only
0
copies elsewhere
how many repositories repackaged it
129
stars on the repo
on the repository, not the skill itself

Install

one command, takes just this skill from the repository
npx skills add https://github.com/bitwarden/ai-plugins --skill detecting-secrets

The instruction itself

16 sections, as written by the author

Secret Patterns

Look for these categories of hardcoded secrets in code:

High-Confidence Patterns

| Type | Example Patterns |

| ------------------ | ----------------------------------------------------------------------------------------------------------------------- |

| API Keys | AKIA[0-9A-Z]{16} (AWS), AIza[0-9A-Za-z_-]{35} (Google), strings assigned to variables named *apiKey*, *api_key* |

| Connection Strings | Server=...;Password=..., mongodb://user:pass@host, postgres://user:pass@host |

| Private Keys | -----BEGIN RSA PRIVATE KEY-----, -----BEGIN OPENSSH PRIVATE KEY----- |

| Tokens | ghp_[A-Za-z0-9]{36} (GitHub PAT), xoxb- (Slack bot), sk- (OpenAI) |

| Passwords | Values assigned to variables named *password*, *passwd*, *secret*, *credential* |

| Certificates | PFX/P12 files with embedded passwords, PEM files with private keys |

Lower-Confidence Patterns (Require Context)

  • Base64-encoded strings in configuration (may be encrypted or may be cleartext secrets)
  • JWT tokens (may be test tokens or production tokens)
  • Hex strings of 32+ characters (may be encryption keys or hashes)
  • URLs with embedded credentials (https://user:pass@host)

Context-Aware Detection

Distinguish real secrets from false positives. Not every pattern match indicates an actual secret — consider context:

Test Fixtures and Mock Data

// NOT a real secret — test fixture with obvious fake value
var testApiKey = "test-api-key-not-real-12345";
var mockPassword = "P@ssword123"; // Used only in unit tests

// REAL secret — production-looking value in non-test code
var apiKey = "sk-proj-abc123def456ghi789jkl012mno345pqr678stu901vwx";

Decision criteria:

  • Is it in a test directory (/test/, /tests/, /*.Test/)?
  • Does the value contain obvious placeholder text ("test", "fake", "mock", "example", "placeholder")?
  • Is the value used in assertions or mock setups?

Example and Placeholder Values

// NOT a real secret — documented example
{
  "apiKey": "YOUR_API_KEY_HERE"
}

// REAL secret — actual value in config
{
  "apiKey": "sk-proj-abc123def456ghi789jkl012mno345pqr678stu901vwx"
}

Encrypted or Hashed Values

  • Hashed passwords (bcrypt $2b$, argon2 $argon2id$) are NOT secrets — they're properly stored
  • Encrypted values with proper key management are NOT secrets in the same way
  • But the encryption KEY itself, if hardcoded, IS a secret

Common Hiding Spots

Search these locations when auditing for secrets:

| Location | What to Look For |

| --------------------------------------------------- | ---------------------------------------------------------- |

| appsettings.json / appsettings.Development.json | Connection strings, API keys, service credentials |

| .env / .env.local | Environment variable definitions with real values |

| web.config / app.config | Machine keys, connection strings |

| docker-compose.yml / Dockerfile | ENV directives with credentials, build args with secrets |

| CI/CD files (.github/workflows/*.yml) | Inline secrets instead of ${{ secrets.* }} references |

| Test seed scripts / migration files | Database passwords, service account credentials |

| Comments and TODO notes | "Temporary" credentials left in comments |

| Default parameter values | function connect(password = "admin123") |

| Constants files | Centralized credential definitions |

GitHub Secret Scanning Integration

# List all secret scanning alerts
gh api /repos/{owner}/{repo}/secret-scanning/alerts --jq '.[] | {number, state, secret_type, secret_type_display_name, created_at, push_protection_bypassed}'

# Get details for a specific alert
gh api /repos/{owner}/{repo}/secret-scanning/alerts/{alert_number}

# List alerts that bypassed push protection
gh api "/repos/{owner}/{repo}/secret-scanning/alerts?state=open" --jq '.[] | select(.push_protection_bypassed == true)'

Push protection prevents commits containing detected secrets from being pushed. When someone bypasses push protection, the alert is flagged — review these with extra scrutiny.

Remediation Workflow

When a secret is found in code, follow this sequence:

1. Rotate Immediately

Assume any committed secret is compromised. Even if the repo is private, the secret may have been cached, logged, or accessed by CI/CD systems.

  • Revoke the existing credential
  • Generate a new credential
  • Update the credential wherever it's used (services, deployments)

2. Remove from Code

Replace the hardcoded secret with a secure reference:

// WRONG — hardcoded secret
var connectionString = "Server=prod.db;Password=s3cr3t!";

// CORRECT — environment variable
var connectionString = Environment.GetEnvironmentVariable("DB_CONNECTION_STRING");

// CORRECT — Azure Key Vault (Bitwarden's approach)
var connectionString = await keyVaultClient.GetSecretAsync("db-connection-string");

3. Remove from Git History (If Needed)

If the secret was committed to a public repo or a repo that will become public:

# Using git filter-repo (preferred over filter-branch)
git filter-repo --path-glob '*.json' --replace-text expressions.txt

# expressions.txt format:
# literal:the-secret-value==>REDACTED

Warning: Rewriting git history is destructive and affects all collaborators. Only do this when the secret was exposed in a public or soon-to-be-public repository.

4. Prevent Recurrence

  • Add patterns to .gitignore for files that should never be committed (.env, *.pfx, appsettings.Development.json)
  • Enable GitHub push protection for the repository
  • Use secret scanning custom patterns for organization-specific secret formats

Secure Alternatives

Bitwarden uses Azure Key Vault for secrets management, provisioned by the BRE team:

| Instead Of | Use |

| ------------------------------- | ---------------------------------------------- |

| Hardcoded connection strings | Azure Key Vault secrets |

| API keys in config files | Environment variables set at deployment |

| Certificates in source | Azure Key Vault certificates |

| Shared team credentials in code | Managed identities (Azure) |

| Secrets in CI/CD workflow files | GitHub Actions secrets (${{ secrets.NAME }}) |

For local development, use user-secrets or .env files that are .gitignored — never commit them.

Critical Rules

  • Assume any committed secret is compromised. Always rotate, even if the repo is private. No exceptions.
  • Never suppress secret scanning alerts without rotation. Dismissing an alert doesn't make the exposure go away.
  • Validation, not just detection. When a potential secret is found, verify it's real before raising an alarm. Check if it's a test value, placeholder, or encrypted content.
  • Check the full commit history. A secret removed in the latest commit may still exist in git history. Use git log -p -S "secret-pattern" to search history.
  • Bitwarden uses Azure Key Vault for secrets management. If a new secret needs to be stored, work with BRE to provision vault access for the repository.

Other skills for the same job

different authors, same section of the catalogue
Codebase Cleanup Deps Audit
by ComeOnOliver
×2

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.

10k tokens
Security Best Practices
by openai
vendor ×1

Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.

103k tokens
Better Auth
by mrgoonie
×1

Implement authentication and authorization with Better Auth - a framework-agnostic TypeScript authentication framework. Features include email/password authentication with verification, OAuth providers (Google, GitHub, Discord, etc.), two-factor authentication (TOTP, SMS), passkeys/WebAuthn support, session management, role-based access control (RBAC), rate limiting, and database adapters. Use when adding authentication to applications, implementing OAuth flows, setting up 2FA/MFA, managing user sessions, configuring authorization rules, or building secure authentication systems for web applications.

46k tokens scripts
Repomix
by mrgoonie
×1

Package entire code repositories into single AI-friendly files using Repomix. Capabilities include pack codebases with customizable include/exclude patterns, generate multiple output formats (XML, Markdown, plain text), preserve file structure and context, optimize for AI consumption with token counting, filter by file types and directories, add custom headers and summaries. Use when packaging codebases for AI analysis, creating repository snapshots for LLM context, analyzing third-party libraries, preparing for security audits, generating documentation context, or evaluating unfamiliar codebases.

27k tokens scripts
Dependency Management Deps Audit
by lingxling
×1

You are a dependency security expert specializing in vulnerability scanning, license compliance, and supply chain security. Analyze project dependencies for known vulnerabilities, licensing issues, outdated packages, and provide actionable remediation strategies.

7k tokens
Hubspot Integration
by lingxling
×1

Expert patterns for HubSpot CRM integration including OAuth authentication, CRM objects, associations, batch operations, webhooks, and custom objects. Covers Node.js and Python SDKs.

5k tokens
Security Best Practices
by christophacham
×1

Perform language and framework specific security best-practice reviews and suggest improvements. Use when the user explicitly requests security best practices guidance, a security review or report, or secure-by-default coding help. Supports Python, JavaScript/TypeScript, and Go. Do NOT use for general code review, debugging, threat modeling (use security-threat-model), or non-security tasks.

102k tokens
API Gateway Configuration
by ComeOnOliver
×1

Configures API gateways for routing, authentication, rate limiting, and request transformation in microservice architectures. Use when setting up Kong, Nginx, AWS API Gateway, or Traefik for centralized API management.

525 tokens

How to use it

Copy the folder

Take bitwarden/detecting-secrets from the repository into ~/.claude/skills for personal use, or into .claude/skills inside a project.

Check the name does not clash

The agent identifies a skill by the name field in its header. Two skills with the same name cannot sit side by side — one of them will be ignored.