gitguardian
v0.6.2by GitGuardian
Find hardcoded secrets (API keys, tokens, database URLs, and 700+ other types) across files, git history, commits, Docker images, and PyPI packages with the ggshield CLI. Also plants honeytokens, installs git and AI-assistant hooks, checks known secrets against public-leak data, inventories credentials across a whole machine, and triages secret incidents in the dashboard. Triggers proactively when writing code that handles credentials or preparing to publish.
What gitguardian does, in the publisher's words
> Beta: this distribution is pre-1.0. The skills work today, but they may change shape between releases: no stability guarantee yet on skill names, slash commands, or file layout.
Find exposed credentials before attackers abuse them, block new leaks before they ship, and plant honeytokens to detect future misuse. This repo ships skill files that teach AI coding agents how to use GitGuardian through the GitGuardian CLI (ggshield), the Developer MCP server, and API-backed workflows where appropriate, when to scan, which flags to use, how to interpret findings, how to walk the user through removal and rotation, and when and where to plant honeytokens.
Supported agents: Claude Code, Codex, Cursor, VS Code (GitHub Copilot), Kiro. Install into your agents with curl -fsSL agents.gitguardian.com | sh: details below.
From the project README, punctuation lightly normalized · Open the README on GitHub
- Skills
- 6
- MCP servers
- 1
- Stars
- 8
- License
- MIT
- Repo created
- 2026-05-20
- Last pushed
- 2026-09-28
- Publisher type
- Organization
- Version
- 0.6.2
Links
Skills · 6
- check-hmsl
- Check whether a known credential has already leaked publicly via GitGuardian's HasMySecretLeaked (HMSL) hash-lookup service. Use when the user inherits credentials, suspects a specific token leaked, wants to vet a HashiCorp Vault inventory, or asks "has this secret leaked", "is this compromised", o…
- create-honeytokens
- Use when generating or planting GitGuardian honeytokens, canary tokens, decoys, or tripwire credentials. Use around.env.example, sample configs, pre-publication open-source repos, internal wikis, runbooks, deploy scripts, or other attractive leak surfaces.
- install-hooks
- Install ggshield as a hook so secrets are caught before they leak. Covers git hooks (pre-commit and pre-push) that block secrets from entering git history, and AI-assistant hooks (claude-code, codex, copilot, cursor, vscode) that scan an AI coding tool's prompts, actions, and outputs in real time.…
- scan-machine
- Scan a developer's entire machine for credentials across local git repositories, dotfiles, ~/.aws/credentials, ~/.kube/config, ~/.docker/config.json, ~/.npmrc, browser profile databases, shell history, AI agent caches, and abandoned project trees via ggshield machine scan. Use when preparing to wip…
- scan-secrets
- Use when scanning code, commits, git history, Docker images, or packages for hardcoded secrets, when editing credential-handling code,.env files, CI/CD workflows, Dockerfiles, or deployment scripts, or before committing or pushing.
- triage-incidents
- Use when triaging or reviewing GitGuardian secret incidents already detected in the dashboard, when asked what is leaking in the org or what to fix first, when remediating or rotating a credential flagged in an incident, after a Public Monitoring alert, or to assign, tag, or resolve incidents. Oper…
Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
MCP servers · 1
- GitGuardianhttp
- https://mcp.gitguardian.com/mcp
Read from the plugin's own mcp.json. We list environment variable names, never values.
Category
Security & Compliance. Assigned by this directory. Agent Plugins 1.0.0 has no category field, so no manifest declares one.
Keywords
ggshield · gitguardian · secrets · credentials · honeytoken · dotenv · secret-scanning
Related by publisher and keywords
Infisical CLI dev plugin for Agents Store. Complete command-line coverage for secrets management: install & auth, infisical run/secrets/export, dynamic secrets, secret scanning with pre-commit hooks, machine-identity CI/CD auth, self-hosted, and troubleshooting.
Skarn for Cursor: audit your AI coding sessions and assistant configs for leaked credentials and risky configuration, and run the pre-execution guard. Backed by the Skarn detection engine on your machine; the skarn binary is installed separately. It declares one local MCP server, named skarn, with four tools (scan_sessions, vet_configs, list_sessions, session_stats): every tool is read-only, none of them writes or changes a file, none of them makes a network call, and every matched value comes back masked.
Credential broker CLI for AI agents. Injects credentials into subprocess memory: agent never sees plaintext values.
Connect Copilot and compatible agents to an existing SandBase Harness runtime for agents, sessions, turns, artifacts, and cancellation.
Use current Infisical documentation and safely inject or update secrets through the authenticated sandbox CLI.
Secure secrets management, multi-chain signing, agent memory, automations, and 155 tools (offered per agent entitlement, in toolsets) for AI agents via 1Claw vault.
[](https://agentpluginsdirectory.com/plugins/gitguardian)✓ Verified . We fetched the manifest from GitHub and checked it against the official Agent Plugins 1.0.0 schema at agent-plugins.org.