Redact Secrets

skillerr/redact-secrets

Submitted by @cade_m · Cade Morales

Jul 8, 2026 · minted Jul 10, 2026

sha256:a996bbfdb6ed
FreeNot anchoredmintedinspectablecapabilitiesdigest-pinnednative

85/ 100 · Strong seal

WIP · 2.0-signals

Skill Score is actively being developed and will get sharper over time.

  • Sealed package20/20

    Minted .skill blob in the registry

  • Digest published15/15

    sha256 pin published on skillerr.com

  • Permissions declared15/15

    Capabilities / permissions declared

  • Source attested10/10

    Namespace, submitter, or source URL (not a vendor endorsement)

  • Transparency log0/15

    Not anchored

  • Release profile15/15

    evaluateReleaseProfile passed

  • Registry signal5/5

    2340 install(s) on registry

  • Not revoked5/5

    No revocation on log

Not a malware scan. Not “safe to run.” Transparent registry signals only. Inclusion is not endorsement.

npx @skillerr/add skillerr/redact-secrets

Registry pin: sha256:a996bbfdb6ed (shown on TrustView; install by name resolves to this sealed blob)

Sealed install targets

Writes redact-secrets.skill (sealed ZIP) plus optional skillerr.json. Not a bare SKILL.md.

Download redact-secrets.skill

Sealed ZIP with digest + skillerr.json. Not a bare SKILL.md.

Free skills install with npx @skillerr/add. Sign in for account history.

Install and download deliver a digest-pinned open .skill package (docs.skillerr.com). Pasting a SKILL.md from the internet has none of this proof.

  • redact-secrets.skill ZIP

    Open-protocol .skill ZIP (skill.json + workflow), not a public raw SKILL.md URL

  • Registry digest pin

    sha256:a996bbfdb6ed…

  • Inspect before run

    TrustView on skillerr.com; SKILL.md is a lossy adapter inside the package

  • Permissions surface

    Capabilities declared for review before install

  • Transparency log

    Inclusion proof in the skillerr.com registry log

  • fsFilesystemelevated

    Read or write files in the workspace

Declarations for humans and agents. Not a runtime sandbox guarantee.

Confirm the digest on this page matches the live registry. This checks identity pins only: not a security scan.

expect sha256:a996bbfdb6edaa77
npx @skillerr/add info skillerr/redact-secrets
curl -sS https://skillerr.com/api/v1/skills/skillerr/redact-secrets | grep -o '"digest":"[^"]*"'

Scrub API keys, tokens, and credentials before compile, seal, or share.

Scan skill sources, chat exports, and sealed package contents for common secret patterns and redact them before publish. Prevents accidental credential leakage into digests and transparency logs. Run as a gate before seal-skill and publish-skill.

TrustView preview on skillerr.com. Install and download serve the sealed package: there is no public raw SKILL.md URL.

---
name: redact-secrets
title: Redact Secrets
description: Scrub API keys, tokens, and credentials before compile, seal, or share.
---

# Redact Secrets

Scrub API keys, tokens, and credentials before compile, seal, or share.

## Description

Scan skill sources, chat exports, and sealed package contents for common secret patterns and redact them before publish. Prevents accidental credential leakage into digests and transparency logs. Run as a gate before seal-skill and publish-skill.

## Capabilities

- fs
Public Ledger
Not anchored
published_at
2026-02-05T13:00:00.000Z
version
0.1.1
updated_at
2026-07-02T15:20:00.000Z
license
MIT
minted_at
2026-07-10T10:24:36.000Z
permanence
in registry log
digest
sha256:a996bbfdb6edaa77b2394a368e55a35b08e4028bae737427a058373ff9f42300

Public permanence uses Sigstore Rekor. The ledger link is shown when a real logIndex was recorded at mint. Green Anchored requires an offline inclusion proof verify. Catalog claims alone never paint Anchored. Inclusion is not endorsement.