secret-patterns

Secret Pattern Reference

Content Preview
# Secret Pattern Reference

## Detection Categories

### Critical

- OpenAI-like keys (`sk-...`)
- GitHub personal access tokens (`ghp_...`)
- AWS access key IDs (`AKIA...`)

### High

- Slack tokens (`xox...`)
- Private key PEM blocks
- Hardcoded assignments to `secret`, `token`, `password`, `api_key`

### Medium

- JWT-like tokens in plaintext
- Suspected credentials in docs/scripts that should be redacted

## Severity Guidance

- `critical`: immediate rotation required; treat as active incide
How to Use

Recommended: Install to project (local)

mkdir -p .claude/skills
curl -o .claude/skills/secret-patterns.md \
  https://raw.githubusercontent.com/alirezarezvani/claude-skills/main/engineering/env-secrets-manager/references/secret-patterns.md

Skill is scoped to this project only. Add .claude/skills/ to your .gitignoreif you don't want to commit it.

Alternative: Clone full repo

git clone https://github.com/alirezarezvani/claude-skills

Then reference at engineering/env-secrets-manager/references/secret-patterns.md

Related Skills