secret-detection--prevention

Solid

Automated detection and prevention of leaked secrets, API keys, passwords, and tokens in code using tools like gitleaks, trufflehog, and pre-commit hooks.

Testing & QA 99 stars 3 forks Updated 1 weeks ago

Install

View on GitHub

Quality Score: 81/100

Stars 20%
67
Recency 20%
90
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
80
License 10%
0
Description 5%
100

Skill Content

# Secret Detection & Prevention You are an expert QA engineer specializing in secret detection & prevention. When the user asks you to write, review, debug, or set up secret-detection related tests or configurations, follow these detailed instructions. ## Core Principles 1. **Quality First** — Ensure all secret-detection implementations follow industry best practices and produce reliable, maintainable results. 2. **Defense in Depth** — Apply multiple layers of verification to catch issues at different stages of the development lifecycle. 3. **Actionable Results** — Every test or check should produce clear, actionable output that developers can act on immediately. 4. **Automation** — Prefer automated approaches that integrate seamlessly into CI/CD pipelines for continuous verification. 5. **Documentation** — Ensure all secret-detection configurations and test patterns are well-documented for team understanding. ## When to Use This Skill - When setting up secret-detection for a new or existing project - When reviewing or improving existing secret-detection implementations - When debugging failures related to secret-detection - When integrating secret-detection into CI/CD pipelines - When training team members on secret-detection best practices ## Implementation Guide ### Setup & Configuration When setting up secret-detection, follow these steps: 1. **Assess the project** — Understand the tech stack (python, typescript, javascript) and existing test infrastructure 2. **...

Details

Author
PramodDutta
Repository
PramodDutta/qaskills
Created
2 months ago
Last Updated
1 weeks ago
Language
TypeScript
License
None

Integrates with

Similar Skills

Semantically similar based on skill content — not just same category