secret-leak-preflight skillA
secret-leak-preflight is agent-read markdown (skill) from yeaight7/agent-powerups: Use when about to commit, push, or publish -- staged changes touch config or environment files, generated artifacts (relay sessions, logs, build output) are being added, or the session handled credentials even indirectly..
Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.
What the file says
## Purpose
Catch secrets before they enter git history or a published artifact. A leaked credential in a commit is a rotation incident even after the file is deleted — history retains it. The preflight is the last cheap moment to stop that.
## When to Use
- Before committing config, environment, or infrastructure changes
- Before pushing or opening a PR that includes generated artifacts
- Before publishing a release or packaging files
- After any session that handled credentials, even indirectly
## Inputs
- The staged diff and the untracked-file list
- Knowledge of which artifact directories the session wrote (relay sessions, logs, build output)
## Workflow
1. **Scan the staged diff — not the worktree.** What gets committed is the staged content:
```sh
git diff --cached | rg -n 'AKIA[0-9A-Z]{16}|ghp_[A-Za-z0-9]{36}|github_pat_|sk-[A-Za-z0-9]{20,}|xox[baprs]-|-----BEGIN [A-Z ]*PRIVATE KEY-----'
git diff --cached | rg -in '(api[_-]?key|secret|token|password|bearer)\s*[:=]'
```
2. **Review untracked files before adding.** New environment or credential files are the classic leak:
```sh
git status --short
```
…Read the whole file at its exact version.
How to install
mdr add yeaight7/agent-powerups/secret-leak-preflight@git:20260606.1a16b8fmdr add yeaight7/agent-powerups/secret-leak-preflight@sha256:15896a4f74570a91Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.
[](https://markdownregistry.com/a/art_bvhnhsngxj5s7suu)
1 badge views in 30 days
Versions
| version | committed | commit | size | audit | |
|---|---|---|---|---|---|
| git:20260606.1a16b8f latest | 2026-06-06 | 1a16b8f | 3,377 B | A | view · diff |
| git:20260504.9cbf7b3 | 2026-05-04 | 9cbf7b3 | 74 B | B | view |
Audit of the latest version
- pass: Frontmatter block present
- pass: Frontmatter declares a name
- pass: Frontmatter declares a description
- pass: Size between 200 bytes and 200 KB (3377 bytes)
- pass: No zero-width or bidi control characters
- pass: No instruction hidden inside an HTML comment
- pass: No link to an exfiltration or paste host
- pass: No credential-shaped string
- pass: No instruction to send local credentials anywhere
- pass: No text hidden with inline styles
- pass: No prompt-injection phrasing
- pass: No curl or wget piped into a shell
- pass: No recursive delete of root, home or parent
- pass: No instruction to read or print local credentials
- pass: No base64 blob over 200 characters
- pass: No link to a raw IP address
- pass: No script tag
Source
yeaight7/agent-powerups · 6 stars · license Apache-2.0 · pushed 2026-09-21 · branch main
API
GET https://markdownregistry.com/api/v1/artifacts/art_bvhnhsngxj5s7suu GET https://markdownregistry.com/api/v1/resolve?ref=yeaight7/agent-powerups/secret-leak-preflight GET https://markdownregistry.com/api/v1/blob/15896a4f74570a915626e6f27bf8192d512ebc88a00e0c07884680aae4819b01
Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.