/review-secrets¶
Review class · gate
Advise only. Reads changes, reports findings, and never writes a file or commits. Shared rules: CONVENTIONS.md.
REQUIRES a dedicated secret scanner (gitleaks/trufflehog/detect-secrets) on PATH — runs it over the diff first as a HARD GATE (BLOCKs with install instructions if none is installed) — then a deeper semantic security pass.
At a glance¶
| Run it | /review-secrets |
| Class | review · gate |
| Version | 0.4.0 |
| Author | navjyotnishant |
| Cost | 1–2 agent calls |
| Needs | gitleaks or trufflehog or detect-secrets |
| Source | skills/review-secrets/SKILL.md |
What it needs, and what happens without it¶
Every tool is detected at runtime — none is installed for you.
| Tool | Without it |
|---|---|
gitleaks or trufflehog or detect-secrets |
BLOCK with install instructions — there is no heuristic fallback |
Agents it spawns¶
secrets-reviewer— Use this agent for a deeper semantic security review of a code diff AFTER a local secret scan has already…
The procedure¶
The executable steps live in the skill file itself and are deliberately not reproduced here: they are instructions to the model at runtime, not documentation.