---
title: "scan-secrets"
description: "Blocks known credential patterns, vendor key prefixes, private-key blocks, and key/token/password assignments, at two enforcement points: at commit (the git hook, over staged changes) and at agent tool-use (the mcp-gatew"
canonical: https://agentpluginsdirectory.com/plugins/scan-secrets--open-coder-ai-7
last-updated: 2026-10-03
---

# scan-secrets
Blocks known credential patterns, vendor key prefixes, private-key blocks, and key/token/password assignments, at two enforcement points: at commit (the git hook, over staged changes) and at agent tool-use (the mcp-gateway / agent write guard, over a tool call's arguments), so a secret is caught as the agent writes it, before it ever reaches a commit. Matched by pattern, not by entropy analysis. Best-effort guard; not a replacement for a dedicated secret scanner.
- Slug: scan-secrets--open-coder-ai-7
- Publisher: chock-core
- Repository: https://github.com/open-coder-ai/chock
- Manifest: .agents/policies/scan-secrets/plugin.json
- Version: 0.0.8
- License: Apache-2.0
- Category (editorial): other
- Skills: 1 (scan-secrets)
- MCP servers: 0
- Stars: 8
- Repository created: 2026-08-17
- Repository last pushed: 2026-10-03
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/scan-secrets--open-coder-ai-7
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## Skills

- scan-secrets: Blocks known credential patterns, vendor key prefixes, private-key blocks, and key/token/password assignments, at two enforcement points: at commit (the git hook, over staged changes) and at agent tool-use (the mcp-gateway / agent write guard, over a tool call's arguments), so a secret is caught as…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
