A comprehensive security auditing tool that scans Git history and commits to identify and prevent the exposure of sensitive credentials.
The fastest way to install a skill directly from the registry.
npx clawhub@latest install git-secrets-scanner
Copy the skill folder to one of these locations
~/.openclaw/skills/ <project>/skills/ Priority: Workspace > Local > Bundled
Copy this prompt to OpenClaw to install it automatically.
Help me install git-secrets-scanner using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).
Get the raw skill files in a ZIP archive.
The Git Security Scanner is an essential security utility designed to prevent the accidental disclosure of sensitive information within your codebase. By leveraging powerful engines like Gitleaks, TruffleHog, and git-secrets, it provides a multi-layered defense against credential leaks. This skill is a vital component of the Openclaw Skills library, enabling developers to scan local repositories, specific commits, or entire project histories for API keys, database passwords, and private tokens.
In addition to simple detection, this tool supports advanced entropy analysis to find high-randomness strings that often signify encrypted keys or certificates. Integrating this tool into your daily routine ensures that your development process remains secure and compliant with modern devsecops standards. By utilizing Openclaw Skills for security scanning, you can automate the detection of secrets before they are ever pushed to a remote server.
To get started with this security tool, install your preferred scanning engine:
# Install Gitleaks for fast, Go-based scanning
brew install gitleaks
# Install TruffleHog for secret verification
brew install trufflehog
# Install git-secrets for pre-commit protection
brew install git-secrets
cd your-repo && git secrets --install
The scanner organizes detection data into a structured format for easy analysis and remediation:
| Attribute | Description |
|---|---|
| Finding | The actual string or token detected in the source code. |
| Secret | The sensitive value flagged by the scanner. |
| RuleID | The identifier for the matching detection logic (e.g., generic-api-key). |
| Entropy | A numerical value representing the randomness of the string. |
| File/Line | The exact location within the repository where the leak occurred. |
| Fingerprint | A unique hash used to track the specific finding across different scans. |
Loading
A professional model fine-tuning service specializing in LLM and Stable Diffusion LoRA training using high-performance 20GB VRAM hardware.

An intelligent personal assistant that analyzes, de-duplicates, and restructures your file system automatically.

An AI-driven assistant designed to maximize engagement and visibility for Douyin creators through data-backed content optimization.

A comprehensive monitoring tool for tracking Douban trending movies, books, and music charts with detailed rating analysis.

Monitor and analyze GitHub trending repositories and developers across multiple languages and timeframes.

A powerful monitoring tool to track Hacker News top stories, tech discussions, and startup launches in real-time.








































