Works with the AI tools you already use
SecretSanitize
A high-stakes incident response workflow to revoke leaked credentials and purge them from Git history.
$19
SecretSanitize
Example session with this skill installed
I accidentally committed my AWS_SECRET_ACCESS_KEY in a .env file three days ago. I've already deleted the file in a new commit, but I'm worried it's still in the history. What do I do?
- Read your context and instructions
- Compiled the secretsanitize
I have analyzed the incident. A follow-up commit deleting the .env file is insufficient because the secret remains visible in your Git history. You must execute a full incident response.
⚠️ URGENT: LEAKED CREDENTIAL RESPONSE
Step 1 (DO THIS FIRST): Rotate your AWS Access Keys in the IAM console immediately. Because the key was exposed for three days, it must be treated as compromised. Deleting it from history does not invalidate the key itself.
Step 2: Create a mirror backup of your repository to ensure you can recover data if the rewrite fails:
git clone --mirror git@github.com:your-org/your-repo.git repo-backup.git
Step 3: Purge the secret from all historical commit blobs.
Remediation Commands
# Option A: Using git filter-repo (Recommended)
# Install via: pip install git-filter-repo
git filter-repo --invert-paths --path .env
# Option B: Using BFG Repo-Cleaner
# Install via: brew install bfg
bfg --delete-files .env
git reflog expire --expire=now --all && git gc --prune=now --aggressive
Step 4: Coordinate with your team. A force-push will break their local history. Once they are notified, run:
git push origin --force --all
Step 5: Verify that your CI/CD environment now pulls these keys from AWS Secrets Manager or GitHub Actions Secrets rather than a file.
Next steps
- Check AWS CloudTrail logs for any unauthorized API calls made with the leaked key.
- Update your
.gitignoreto include.envto prevent future leaks. - Ensure all team members delete their local clones and re-clone the sanitized repository.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
Leaking a credential in Git history is a high-priority security incident that a simple delete commit cannot fix. This skill provides a rigid, five-step incident response workflow to revoke the compromised secret and purge it from every commit blob in your repository history.
What it does
- Enforces revocation by requiring provider-side secret rotation before any code cleanup begins.
- Automates backups by generating mirror clone commands to ensure the pre-rewrite state is recoverable.
- Purges history using specific
git filter-repoor BFG commands to strip secrets from all historical commit blobs. - Coordinates pushes by providing the necessary workflow and warnings for a safe, team-wide force-push.
- Remediates root causes by guiding the transition of secrets from the repository to dedicated secrets managers.
How it works
- Revoke the secret at the provider (AWS, Stripe, GitHub, etc.) and halt active CI/CD pipelines.
- Clone a mirror backup of the repository to prevent permanent data loss during destructive operations.
- Rewrite the entire Git history using specific command-line tools to scrub the secret from all branches and tags.
- Push the sanitized history back to the remote server after ensuring all team members are notified.
Frameworks & tools
This skill utilizes git, git filter-repo, and BFG Repo-Cleaner. It supports credentials from any provider, including AWS, Azure, GCP, and SaaS platforms.
Why this beats prompting it yourself
Most LLMs suggest simple file deletion, which leaves the secret exposed in Git history. This skill enforces a security-first protocol that prioritizes revocation over hygiene, preventing the "false sense of security" that leads to further exploits.
Use cases
- Scrubbing an
.envfile that was committed multiple commits ago. - Responding to a GitHub "Secret Scanning" alert for a leaked API key.
- Migrating a legacy project from hardcoded secrets to a Vault while cleaning the history.
Known limitations
Requires local shell access with git filter-repo or BFG installed. Cannot rotate secrets automatically; the user must have administrative access to the secret provider.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 2 days ago
- Passed all security checks, Safe to install