secret-scanner (me): Exposed secrets and credentials security-auditor: Code vulnerability patterns
Works without sandboxing: ✅ Yes (recommended) Works with sandboxing: ✅ Yes
Detect exposed secrets, API keys, credentials, and tokens in code. Use before commits, on file saves, or when security is mentioned. Prevents accidental secret exposure. Triggers on file changes, git commits, security checks, .env file modifications. Source: sovranbitcoin/sovran.
Open your terminal or command line tool (Terminal, iTerm, Windows Terminal, etc.) Copy and run this command: npx skills add https://github.com/sovranbitcoin/sovran --skill secret-scanner Once installed, the skill will be automatically configured in your AI coding environment and ready to use in Claude Code, Cursor, or OpenClaw