Skip to content

/review-secrets

Review class · gate

Advise only. Reads changes, reports findings, and never writes a file or commits. Shared rules: CONVENTIONS.md.

REQUIRES a dedicated secret scanner (gitleaks/trufflehog/detect-secrets) on PATH — runs it over the diff first as a HARD GATE (BLOCKs with install instructions if none is installed) — then a deeper semantic security pass.

At a glance

Run it /review-secrets
Class review · gate
Version 0.4.0
Author navjyotnishant
Cost 1–2 agent calls
Needs gitleaks or trufflehog or detect-secrets
Source skills/review-secrets/SKILL.md

What it needs, and what happens without it

Every tool is detected at runtime — none is installed for you.

Tool Without it
gitleaks or trufflehog or detect-secrets BLOCK with install instructions — there is no heuristic fallback

Agents it spawns

  • secrets-reviewer — Use this agent for a deeper semantic security review of a code diff AFTER a local secret scan has already…

The procedure

The executable steps live in the skill file itself and are deliberately not reproduced here: they are instructions to the model at runtime, not documentation.

Read review-secrets/SKILL.md →