secret-hygiene
Scans staged changes for secrets and teaches Claude Code to avoid hardcoding credentials.
Scans staged changes for secrets and teaches Claude Code to avoid hardcoding credentials.
secret-hygiene teaches Claude Code to read credentials from the environment instead of hardcoding them, then uses a zero-dependency Python scanner on directories or staged changes. It detects JWTs, PEM keys, common cloud credentials, connection strings, and high-entropy secret-like variables, with narrowly scoped ignore rules. For public or production repositories, it recommends adding gitleaks and trufflehog.
Resource types
Use cases
Platforms
Audit suspension risks in a Claude Code working environment.
Check whether a specific CVE actually applies to your environment.
Capabilities
Audience
Public GitHub facts last synced Jul 10, 2026.
Store and inject development secrets through 1Password from Claude Code.
Audit a deployed public app for production gaps missed during coding.