Skip to main content

outbound-secret-redaction-gate

Prevent AI agents from publishing live credentials in outbound GitHub/Slack/email/gist artifacts. Trigger when an agent reads git remote -v, .git/config, gh auth status -t, env, printenv, cat ~/.bashrc, an AO runner yaml, the ao-go-daemon plist, or any disk_diagnosis report and pastes the raw output into a public artifact - especially after a GitHub Personal Access Token found in issue email or when the user says 'PAT in issue', 'secret leak', 'yet again', 'token exposed', 'credential in GitHub', 'rotate the PAT', or asks for a postmortem on a recurring credential leak. Verified 2026-07-17: jleechanorg/disk_magician issue 25 was opened by an AI disk/swarm run that pasted three live PATs copied verbatim from local .git/config remote URLs (one inline https://x-access-token:ghp_...@...git, two more PATs surfaced from disk-scan output). Same root cause as the 2026-07-12 incident - recurring 3rd+ time.

跳到安装

来源信息

仓库
jleechanorg/claude-commands
最近来源活动
2026年8月2日 01:06
检测到的 SKILL.md 语言
英语
星标
3
分支
0

安装方式

默认使用会先检查来源的 Prompt;你也可以切换为直接命令,或下载本地副本。

检查来源文件

决定是否安装前,请先阅读 SKILL.md,以及 SkillsMP 当前展示的配套文件。