Skip to main content
在 Manus 中运行任何 Skill
一键导入
$pwd:

sast-hardcodedsecrets

// Detect hardcoded sensitive data (API keys, access tokens, private keys, passwords, etc.) in publicly accessible code — frontend JavaScript, mobile apps, client-side bundles, and HTML templates. Uses a three-phase approach: recon (find secret candidates), batched verify (confirm real secrets in public code paths, 3 candidates each), and merge (consolidate batch results). Requires sast/architecture.md (run sast-analysis first). Outputs findings to sast/hardcodedsecrets-results.md. Use when asked to find hardcoded secrets, leaked API keys, or exposed credentials.

$ git log --oneline --stat
stars:648
forks:29
updated:2026年4月2日 20:45
SKILL.md
readonly