Skip to main content

outbound-secret-redaction-gate

Prevent AI agents from publishing live credentials in outbound GitHub/Slack/email/gist artifacts. Trigger when an agent reads git remote -v, .git/config, gh auth status -t, env, printenv, cat ~/.bashrc, an AO runner yaml, the ao-go-daemon plist, or any disk_diagnosis report and pastes the raw output into a public artifact - especially after a GitHub Personal Access Token found in issue email or when the user says 'PAT in issue', 'secret leak', 'yet again', 'token exposed', 'credential in GitHub', 'rotate the PAT', or asks for a postmortem on a recurring credential leak. Verified 2026-07-17: jleechanorg/disk_magician issue 25 was opened by an AI disk/swarm run that pasted three live PATs copied verbatim from local .git/config remote URLs (one inline https://x-access-token:ghp_...@...git, two more PATs surfaced from disk-scan output). Same root cause as the 2026-07-12 incident - recurring 3rd+ time.

Jump to install

Source facts

Repository
jleechanorg/claude-commands
Last source activity
August 2, 2026 at 01:06
Detected SKILL.md language
English
Stars
3
Forks
0

Install options

The review-first prompt is selected by default. You can switch to a direct command or download a local copy.

Review the source files

Read SKILL.md and any companion files shown by SkillsMP before deciding whether to install.