Run or install repo security leak checks with BetterLeaks and Trivy. Use when asked to scan for leaked secrets, vulnerable dependencies, misconfigurations, add secret-leak guardrails, add BetterLeaks, add forbidden-path hooks, or run secleak-check before release.
Installation
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
Run or install repo security leak checks with BetterLeaks and Trivy. Use when asked to scan for leaked secrets, vulnerable dependencies, misconfigurations, add secret-leak guardrails, add BetterLeaks, add forbidden-path hooks, or run secleak-check before release.
Secleak Check
Workflow
Confirm cwd and repo root.
For a scan request, run the bundled script from this skill, not a target-repo script.
For a setup request, add repo-local guardrails from references/guardrails.md.
Quote exact failing tool output, but never print raw secret values.
If the bundled script is unavailable, use the manual fallback commands below.
Bundled command
Resolve scripts/secleak-check.sh relative to this SKILL.md.