Skip to main content
Back to the directory
ghostsecurity/skillsSoftware EngineeringFrontend and Design

ghost-scan-secrets

Automated secrets scanner that detects hardcoded API keys, tokens, passwords, and sensitive data in codebases.

SkillJury keeps community verdicts, source metadata, and external repository signals in separate lanes so ranking data never pretends to be a review.

SkillJury verdict
Pending

No approved reviews yet

Would recommend
Pending

Waiting on enough review volume

Install signal
1

Weekly or total install activity from catalog data

Sign in to review
0 review requests
Install command
npx skills add https://github.com/ghostsecurity/skills --skill ghost-scan-secrets
SkillJury does not have enough approved reviews to publish a community verdict yet. Source metadata and repository proof are still available above.
SkillJury Signal Summary

As of May 1, 2026, ghost-scan-secrets has 1 weekly installs, 0 community reviews on SkillJury. Community votes currently stand at 0 upvotes and 0 downvotes. Source: ghostsecurity/skills. Canonical URL: https://skills.sh/ghostsecurity/skills/ghost-scan-secrets.

Security audits
Gen Agent Trust HubFAIL
SocketPASS
SnykWARN
About this skill
Automated secrets scanner that detects hardcoded API keys, tokens, passwords, and sensitive data in codebases. You are the top-level orchestrator for secrets scanning. Your ONLY job is to call the Task tool to spawn subagents to do the actual work. Each step below gives you the exact Task tool parameters to use. Do not do the work yourself. $ARGUMENTS Any values provided above override the defaults. Run this Bash command to compute the repo-specific output directory, create it, and locate the skill files: Store scan_dir (the absolute path under ~/.ghost/repos/ ), cache_dir (the repo-level cache directory), and skill_dir (the absolute path to the skill directory containing agents/ , scripts/ , etc.). After this step, your only remaining tool is Task. Do not use Bash, Read, Grep, Glob, or any other tool for Steps 1–4.

Source description provided by the upstream listing. Community review signal and install context stay separate from this narrative layer.

Community reviews

Latest reviews

No community reviews yet. Be the first to review.

Browse this skill in context
FAQ
What does ghost-scan-secrets do?

Automated secrets scanner that detects hardcoded API keys, tokens, passwords, and sensitive data in codebases.

Is ghost-scan-secrets good?

ghost-scan-secrets does not have approved reviews yet, so SkillJury cannot publish a community verdict.

Which AI agents support ghost-scan-secrets?

ghost-scan-secrets currently lists compatibility with Skills CLI.

Is ghost-scan-secrets safe to install?

ghost-scan-secrets has been scanned by security audit providers tracked on SkillJury. Check the security audits section on this page for detailed results from Socket.dev and Snyk.

What are alternatives to ghost-scan-secrets?

Skills in the same category include review-management, conversation-memory, coverage, grimoire-aave.

How do I install ghost-scan-secrets?

Run the following command to install ghost-scan-secrets: npx skills add https://github.com/ghostsecurity/skills --skill ghost-scan-secrets

Related skills

More from ghostsecurity/skills

Related skills

Alternatives in Software Engineering