secrets-in-git-history
Mine GitHub, GitLab and git history for identities, infrastructure and leaked credentials using commit author emails, GitHub code search, the commit .patch endpoint, trufflehog, gitleaks, git log pickaxe and full-ref history scans. Use when investigating a developer or organisation on GitHub, finding leaked API keys, AWS keys or tokens in code, enumerating org members and their personal repos, or recovering secrets…
- installs 8w
- 1,794
- 30-day movement
- starts with the next reading
- Related entries
- 1
- Connections
- 0
An agent skill (SKILL.md) that teaches an AI coding agent how to mine GitHub, GitLab and git history for identities, infrastructure and leaked credentials. It covers commit author emails, GitHub code search, the commit .patch endpoint, trufflehog, gitleaks, git log pickaxe and full-ref history scans, with worked examples, confidence grading and an ethics reference.
Reach for it when you need a structured, tool-backed playbook for investigating a developer or organisation's git footprint or hunting secrets that survive deletion from HEAD.
Use it to
- Investigate a developer or organisation on GitHub
- Find leaked API, AWS keys or tokens in code
- Enumerate org members and their personal repos
- Recover secrets deleted from HEAD but present in history or forks
- Respond to credential exposure or run M&A diligence
For Security investigators, OSINT practitioners and supply-chain risk analysts
- Host repository
- UseOSINT/Skills
- Installs, lifetime
- 1,800
- Installs, 8 weeks
- 1,794
- Host stars
- 35
- Host language
- Shell