mirror of
https://github.com/andrewyng/openworker.git
synced 2026-09-14 00:00:58 +00:00
Security, Cloud Posture, and Dependency Audit coworkers as self-contained bundle dirs (manifest + skills) driving OSS scanners; registry loads bundle subdirs; packaging includes them.
1.7 KiB
1.7 KiB
name, description
| name | description |
|---|---|
| secret-scan | Hunt committed secrets with gitleaks and drive safe rotation |
Find committed credentials and get them rotated and removed — without ever exposing them further yourself.
ABSOLUTE RULE: never print a secret's value — not in output, notes, todo items, commits, or PRs. Refer to every hit as " in : (commit )".
- Check the tool:
gitleaks version. If missing, tell the user how to install it (brew install gitleaks) and STOP — ask before installing anything. - Scan working tree AND history:
gitleaks detect --source . --report-format json --report-path /tmp/gitleaks.json(history matters: a secret deleted in HEAD is still live in every clone). - Triage each hit by reading its context:
- Real credential, test fixture, or example placeholder? Say which and why.
- For real ones: what does it grant access to, and is it plausibly still valid?
- For every real secret, in this order:
a. ROTATE first — tell the user exactly where to revoke/rotate it (the provider's
console page or CLI command). Rotation beats removal: history rewrite without
rotation is false comfort.
b. Remove it from the code: move to env vars or the project's secret store, matching
how this codebase already handles configuration.
c. Prevent recurrence: add/extend
.gitignorefor local secret files and offer a.gitleaks.tomlbaseline plus a pre-commit hook. d. History purge (git filter-repo/BFG) is DESTRUCTIVE and rewrites shared history — describe the trade-off and only proceed if the user explicitly asks. - Deliver: a hit list (kind · location · verdict · rotation status), the cleanup branch/PR, and the prevention setup you added or recommend.