Secret Scanning
Independent PiSkill directory guide. The original skill remains hosted by GitHub Awesome Copilot.
What is Secret Scanning?
Finds exposed secrets and risky credential patterns in repositories, distinguishes likely findings from noise, and recommends safe rotation and remediation steps.
Compatible tools
Related skills
Agent Governance
Adds governance, policy, trust, audit, access-control, and safety patterns to AI-agent systems that call tools, APIs, databases, or other external systems.
CodeQL Code Scanning
Guides CodeQL code scanning through GitHub Actions and the CodeQL CLI, including workflow setup, language configuration, query suites, SARIF output, monorepos, and troubleshooting.
Prompt Engineering Safety Review
Reviews prompts for safety, bias, security weaknesses, prompt-injection risk, effectiveness, and testing gaps, then provides structured improvements and safer prompt-engineering guidance.
Agent OWASP Compliance
Reviews an AI-agent codebase against the OWASP Agentic Security Initiative Top 10 and produces structured security and compliance findings for agentic systems.
Security Review
Performs an AI-assisted application security review that traces data flows and looks for injection flaws, broken access control, leaked secrets, weak cryptography, vulnerable dependencies, and business-logic issues.
AWS IAM
Provides verified IAM guidance for policy evaluation, trust relationships, least-privilege role creation, STS sessions, condition operators, and common security edge cases.