instructa/secleak-check
Run or install repo security leak checks with BetterLeaks and Trivy. Use when asked to scan for leaked secrets, vulnerable dependencies, misconfigurations, add secret-leak guardrails, add BetterLeaks, add forbidden-path hooks, or run secleak-check before release.
npx skills add https://github.com/instructa/agent-skills --skill secleak-check
references/guardrails.md.Resolve scripts/secleak-check.sh relative to this SKILL.md.
Common installed path:
/Users/kregenrek/.agents/skills/secleak-check/scripts/secleak-check.sh
betterleaks git --no-banner --redact=100 .
trivy fs --scanners vuln,secret,misconfig --exit-code 1 .
Prefer .betterleaks.toml when present. If only .gitleaks.toml exists, pass --config .gitleaks.toml; BetterLeaks supports it for compatibility.
betterleaks findings are blockers until verified false-positive or remediated.trivy dependency vulnerabilities should be summarized by severity and top fixed versions.node_modules are dependency artifact noise unless that file is built or shipped by the repo.When asked to harden a repo against secret leaks:
.betterleaks.toml, .gitleaks.toml, secret-scan workflows, Dependabot, and hook tooling..forbidden-paths.regex and a staged-file hook..betterleaks.toml with path-based filters only for fixtures.scripts/secleak-check.sh only when the repo wants a first-class local script..gitignore for runtime dirs, env files, credentials, keys, and infra state.Templates live in references/guardrails.md; small examples live in references/examples.md.
Take instructa/secleak-check from the repository into ~/.claude/skills for personal
use, or into .claude/skills inside a project.
The agent identifies a skill by the name field in its header. Two skills with the
same name cannot sit side by side — one of them will be ignored.