GitGuardian avatar

gitguardian

v0.6.2

by GitGuardian

Find hardcoded secrets (API keys, tokens, database URLs, and 700+ other types) across files, git history, commits, Docker images, and PyPI packages with the ggshield CLI. Also plants honeytokens, installs git and AI-assistant hooks, checks known secrets against public-leak data, inventories credentials across a whole machine, and triages secret incidents in the dashboard. Triggers proactively when writing code that handles credentials or preparing to publish.

What gitguardian does, in the publisher's words

> Beta: this distribution is pre-1.0. The skills work today, but they may change shape between releases: no stability guarantee yet on skill names, slash commands, or file layout.

Find exposed credentials before attackers abuse them, block new leaks before they ship, and plant honeytokens to detect future misuse. This repo ships skill files that teach AI coding agents how to use GitGuardian through the GitGuardian CLI (ggshield), the Developer MCP server, and API-backed workflows where appropriate, when to scan, which flags to use, how to interpret findings, how to walk the user through removal and rotation, and when and where to plant honeytokens.

Supported agents: Claude Code, Codex, Cursor, VS Code (GitHub Copilot), Kiro. Install into your agents with curl -fsSL agents.gitguardian.com | sh: details below.

From the project README, punctuation lightly normalized · Open the README on GitHub

Skills
6
MCP servers
1
Stars
8
License
MIT
Repo created
2026-05-20
Last pushed
2026-09-28
Publisher type
Organization
Version
0.6.2

Links

Skills · 6

check-hmsl
Check whether a known credential has already leaked publicly via GitGuardian's HasMySecretLeaked (HMSL) hash-lookup service. Use when the user inherits credentials, suspects a specific token leaked, wants to vet a HashiCorp Vault inventory, or asks "has this secret leaked", "is this compromised", o…
create-honeytokens
Use when generating or planting GitGuardian honeytokens, canary tokens, decoys, or tripwire credentials. Use around.env.example, sample configs, pre-publication open-source repos, internal wikis, runbooks, deploy scripts, or other attractive leak surfaces.
install-hooks
Install ggshield as a hook so secrets are caught before they leak. Covers git hooks (pre-commit and pre-push) that block secrets from entering git history, and AI-assistant hooks (claude-code, codex, copilot, cursor, vscode) that scan an AI coding tool's prompts, actions, and outputs in real time.…
scan-machine
Scan a developer's entire machine for credentials across local git repositories, dotfiles, ~/.aws/credentials, ~/.kube/config, ~/.docker/config.json, ~/.npmrc, browser profile databases, shell history, AI agent caches, and abandoned project trees via ggshield machine scan. Use when preparing to wip…
scan-secrets
Use when scanning code, commits, git history, Docker images, or packages for hardcoded secrets, when editing credential-handling code,.env files, CI/CD workflows, Dockerfiles, or deployment scripts, or before committing or pushing.
triage-incidents
Use when triaging or reviewing GitGuardian secret incidents already detected in the dashboard, when asked what is leaking in the org or what to fix first, when remediating or rotating a credential flagged in an incident, after a Public Monitoring alert, or to assign, tag, or resolve incidents. Oper…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.

MCP servers · 1

GitGuardianhttp
https://mcp.gitguardian.com/mcp

Read from the plugin's own mcp.json. We list environment variable names, never values.

Category

Security & Compliance. Assigned by this directory. Agent Plugins 1.0.0 has no category field, so no manifest declares one.

Keywords

ggshield · gitguardian · secrets · credentials · honeytoken · dotenv · secret-scanning

Related by publisher and keywords

  • infisical-devAgents-Store

    Infisical CLI dev plugin for Agents Store. Complete command-line coverage for secrets management: install & auth, infisical run/secrets/export, dynamic secrets, secret scanning with pre-commit hooks, machine-identity CI/CD auth, self-hosted, and troubleshooting.

  • skarnskarn-security

    Skarn for Cursor: audit your AI coding sessions and assistant configs for leaked credentials and risky configuration, and run the pre-execution guard. Backed by the Skarn detection engine on your machine; the skarn binary is installed separately. It declares one local MCP server, named skarn, with four tools (scan_sessions, vet_configs, list_sessions, session_stats): every tool is read-only, none of them writes or changes a file, none of them makes a network call, and every matched value comes back masked.

  • trustlessikkun1222

    Credential broker CLI for AI agents. Injects credentials into subprocess memory: agent never sees plaintext values.

  • Connect Copilot and compatible agents to an existing SandBase Harness runtime for agents, sessions, turns, artifacts, and cancellation.

  • infisicaluseopencompany

    Use current Infisical documentation and safely inject or update secrets through the authenticated sandbox CLI.

  • 1claw1clawAI

    Secure secrets management, multi-chain signing, agent memory, automations, and 155 tools (offered per agent entitlement, in toolsets) for AI agents via 1Claw vault.

Add the verified badge to your README[![Verified by AgentPluginsDirectory.com against Schema 1.0.0](https://agentpluginsdirectory.com/badge.svg)](https://agentpluginsdirectory.com/plugins/gitguardian)

✓ Verified . We fetched the manifest from GitHub and checked it against the official Agent Plugins 1.0.0 schema at agent-plugins.org.