Skip to main content

check-security

Scan the repository for accidentally committed secrets (API keys, passwords, tokens, private keys, etc.) using the `detect-secrets` CLI (https://github.com/Yelp/detect-secrets). Checks whether `detect-secrets` is installed and attempts to install it (`pip`/`pip3`/`pipx`, falling back to `brew` on macOS) if it isn't; if every install attempt fails, warns the user with the actual error and asks whether to continue without scanning or stop. For a whole-repository run (no argument), maintains a `.secrets.baseline` file at the repository root and reports only secrets that are new since the last baseline or were never triaged (audited); for a scoped run (`<path-or-glob>` argument) it scans just that path ad hoc and reports every finding, without touching the baseline. Invoke as `/check-security` to scan the whole repository, or `/check-security <path-or-glob>` to scope the scan to specific files/directories. Use whenever the user wants a secret-scanning pass before committing/pushing/opening a PR, instead of eyebal

Jump to install

Source facts

Repository
albertoirurueta/irurueta-statistics
Last source activity
July 14, 2026 at 12:31
Detected SKILL.md language
English
Stars
0
Forks
0

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.