Git Security Scanner for Openclaw

A comprehensive security auditing tool that scans Git history and commits to identify and prevent the exposure of sensitive credentials.

guohongbin-git
v1.0.0
Feb 19, 2026
0
2.7k
0

Install & Download

1. ClawHub CLI

The fastest way to install a skill directly from the registry.

npx clawhub@latest install git-secrets-scanner

2. Manual Installation

Copy the skill folder to one of these locations

Global
~/.openclaw/skills/
Workspace
<project>/skills/

Priority: Workspace > Local > Bundled

3. Prompt Installation

Copy this prompt to OpenClaw to install it automatically.

Help me install git-secrets-scanner using Clawhub. If Clawhub is not installed, install it first (npm i -g clawhub).

Prefer to download?

Get the raw skill files in a ZIP archive.

What is Git Security Scanner?

The Git Security Scanner is an essential security utility designed to prevent the accidental disclosure of sensitive information within your codebase. By leveraging powerful engines like Gitleaks, TruffleHog, and git-secrets, it provides a multi-layered defense against credential leaks. This skill is a vital component of the Openclaw Skills library, enabling developers to scan local repositories, specific commits, or entire project histories for API keys, database passwords, and private tokens.

In addition to simple detection, this tool supports advanced entropy analysis to find high-randomness strings that often signify encrypted keys or certificates. Integrating this tool into your daily routine ensures that your development process remains secure and compliant with modern devsecops standards. By utilizing Openclaw Skills for security scanning, you can automate the detection of secrets before they are ever pushed to a remote server.

Git Security Scanner Use Cases

  • Scanning current local repositories for accidental inclusion of Slack, AWS, or GitHub tokens.
  • Auditing the entire Git history of a project to identify legacy security vulnerabilities.
  • Preventing sensitive data from being committed by using pre-commit hooks.
  • Automating security checks within CI/CD pipelines to ensure every pull request is secret-free.
  • Verifying the validity of discovered secrets using automated verification tools.

How Git Security Scanner Works

  1. The scanner is initiated on a target directory or specific Git branch using a chosen engine like Gitleaks.
  2. It traverses the Git logs or the current filesystem, applying a series of regex rules and entropy checks to every line of code.
  3. When a potential secret is identified, the tool captures metadata such as the file path, line number, and commit author.
  4. For advanced users, the scanner can verify the secret against live APIs to confirm if the credential is still active.
  5. A detailed report is generated, allowing developers to revoke compromised keys and scrub their Git history using remediation tools.

Git Security Scanner Setup

To get started with this security tool, install your preferred scanning engine:

# Install Gitleaks for fast, Go-based scanning
brew install gitleaks

# Install TruffleHog for secret verification
brew install trufflehog

# Install git-secrets for pre-commit protection
brew install git-secrets
cd your-repo && git secrets --install

Git Security Scanner Data Schema & Taxonomy

The scanner organizes detection data into a structured format for easy analysis and remediation:

Attribute Description
Finding The actual string or token detected in the source code.
Secret The sensitive value flagged by the scanner.
RuleID The identifier for the matching detection logic (e.g., generic-api-key).
Entropy A numerical value representing the randomness of the string.
File/Line The exact location within the repository where the leak occurred.
Fingerprint A unique hash used to track the specific finding across different scans.

Git Security Scanner Advanced Features

  • Custom rule configuration via .gitleaks.toml to detect proprietary tokens like Moltbook API keys.
  • Integration with BFG Repo-Cleaner for professional-grade removal of sensitive data from Git history.
  • Multi-repository scanning scripts to audit an entire developer workspace simultaneously.
  • Native support for GitHub Actions, enabling automated security gates on every push.
  • Support for verified scanning which attempts to check if discovered secrets are currently valid and active.

SKILL.md


Loading

Related Openclaw Skills

METADATA

Github Stars: 0
forks: 0

Featured*