Now liveThe Skillselion MCP - thousands of ranked skills, loaded into your agent mid-task. No install.Get it →
kochetkov-ma avatar

Brewcode:Secrets Scan

  • 13 installs
  • 29 repo stars
  • Updated August 2, 2026
  • kochetkov-ma/claude-brewcode

Scan codebases and commits for exposed credentials, API keys, and secrets using Gitleaks

About

Brewcode skill for automated credential scanning and secrets detection in codebases and git history. Solo developers use this to audit their projects for accidentally committed API keys, passwords, and tokens before shipping to production.

  • Secrets detection
  • Gitleaks integration
  • Automated scanning

Brewcode:Secrets Scan by the numbers

  • 13 all-time installs (skills.sh)
  • Ranked #1,634 of 2,203 Security skills by installs in the Skillselion catalog
  • Data as of Aug 5, 2026 (Skillselion catalog sync)
npx skills add https://github.com/kochetkov-ma/claude-brewcode --skill brewcodesecrets-scan

Add your badge

Show developers this skill is listed on Skillselion. Paste this into your README.

Listed on Skillselion
Installs13
repo stars29
Last updatedAugust 2, 2026
Repositorykochetkov-ma/claude-brewcode

What it does

Scan codebases and commits for exposed credentials, API keys, and secrets using Gitleaks

Who is it for?

Developers auditing code security

When should I use this skill?

Pre-commit or pre-deployment security scanning

Files

SKILL.mdMarkdownGitHub ↗

Secrets Scan

<phase name="1-setup">

Phase 1: Setup

EXECUTE using Bash tool:

git rev-parse --is-inside-work-tree 2>/dev/null || { echo "ERROR: Not git repo"; exit 1; }
REPO=$(git rev-parse --show-toplevel) && cd "$REPO"
TS=$(date +%Y%m%d-%H%M%S)
DIR="$REPO/.claude/reports/${TS}_secrets-scan" && mkdir -p "$DIR"
git ls-files > "$DIR/files.txt"
echo "DIR=$DIR|REPO=$REPO|TS=$TS|TOTAL=$(wc -l < "$DIR/files.txt" | tr -d ' ')"
cat "$DIR/files.txt"
STOP if ERROR — must run in git repository.

</phase>

<phase name="2-parallel-scan">

Phase 2: Split & Launch 10 Agents

1. Parse file list → split into 10 chunks (ceil(total/10)) 2. Send 10 Task calls in parallel (single message)

Config: Task(subagent_type="general-purpose", model="haiku", description="Agent N/10 scan")

<agent-prompt> Agent {N}/10 secrets scanner.

FILES: {FILES}

Read each file → detect secrets → return JSON.

PATTERNS:

CategoryMatch
Passwordspassword/passwd/secret/pwd + = or :
API Keysapi_key, access_key, apikey, api_secret
Tokenstoken, bearer, auth_token, access_token
AWSAKIA[0-9A-Z]{16}, aws_secret, aws_access_key
DB URLsjdbc/mongodb/mysql/postgres with credentials
Keys-----BEGIN.*PRIVATE KEY-----, client_secret, encryption_key

CRITICALITY:

LevelCriteria
CRITICALReal credentials, private keys, DB connection strings
HIGHReal API keys/tokens, AWS creds
MEDIUMSuspicious hardcoded values
LOWPlaceholders: changeme, YOUR_KEY, xxx, dummy

SKIP: env refs (process.env.*, ${VAR}, os.getenv()), placeholders, docs/comments.

OUTPUT (JSON):

{"agent":{N},"scanned":["f1","f2"],"skipped":[{"path":"x","reason":"binary"}],"findings":[{"path":"f","line":1,"content":"pwd=x","desc":"Hardcoded pwd","crit":"HIGH"}]}

No findings: "findings":[] </agent-prompt>

</phase>

<phase name="3-merge">

Phase 3: Merge Results

1. Collect 10 JSON responses 2. Parse each (handle errors gracefully) 3. Merge scanned[], skipped[], findings[] 4. Dedupe by path+line 5. Sort: CRITICAL → HIGH → MEDIUM → LOW

</phase>

<phase name="4-report">

Phase 4: Generate Report

Write {DIR}/report.md:

<report-template>

Secrets Scan Report

Scan: {TS} | Repo: {REPO} | Files: {TOTAL} | Agents: 10

Summary

MetricCount
Scanned{N}
Skipped{N}
CRITICAL{N}
HIGH{N}
MEDIUM{N}
LOW{N}

Findings

CRITICAL ({N})

#FileLineContentDescription

{ROWS}

HIGH / MEDIUM / LOW

(same table format)

Agent Stats

AgentAssignedScannedFindings
1-10.........
Total{N}{N}{N}

File Inventory

Scanned ({N})

#PathAgent

{ALL}

Skipped ({N})

#PathReason

{SKIP} </report-template>

</phase>

<phase name="5-summary">

Phase 5: Display Summary

## Secrets Scan Complete

| Metric | Value |
|--------|-------|
| Files | {N} |
| CRITICAL | {N} |
| HIGH | {N} |
| MEDIUM | {N} |
| LOW | {N} |

Report: {DIR}/report.md

</phase>

<phase name="6-fix">

Phase 6: Fix Mode

Trigger: --fix arg OR CRITICAL/HIGH findings exist → AskUserQuestion

OptionAction
Fix interactivelyReview each: delete, move to env var, add to .gitignore, skip, mark false positive
Add to .gitignoreAppend paths
SkipDone

</phase>

Related skills

Securitysecretsaudit

This week in AI coding

Five minutes, every Monday - the tools, releases and tactics for developers.

unsubscribe anytime.