PlugMyPlugin
← Browse

secret-scanner

matthews-wong ★ 2

secret-scanner is a heuristic safety net that scans working diffs for likely secrets—API keys, tokens, private keys, and high-entropy strings—before they are committed or shared. It provides a `/scan-secrets` command, detection patterns via a skill, and a PreToolUse hook that runs a POSIX grep-based scanner before Bash tool calls, designed as defense-in-depth rather than a guarantee.

Security DevOps No API key detected runs shell

Install

> /plugin marketplace add matthews-wong/claude-code-plugins/tree/HEAD/plugins/secret-scanner
> /plugin install secret-scanner

Source: https://github.com/matthews-wong/claude-code-plugins/tree/HEAD/plugins/secret-scanner

What it's made of

1 command · 1 skill · 1 hook

Commands
1
Agents
0
Skills
1
MCP servers
0
Hooks
1 · PreToolUse

What it needs & plugs into

API keys
none
Paid services
none detected
External tools
sh
Talks to
nothing external detected

Analyzed . Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.

Is this your plugin?

Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (matthews-wong).