mirror of
https://github.com/alirezarezvani/claude-skills.git
synced 2026-10-07 02:58:13 +00:00
Same root cause as #587/#591 — Claude Code's runtime loader rejects array-form skills paths like ["./content-production", "./ai-seo", ...] even when each entry is a valid subdirectory containing SKILL.md. `claude plugin validate` accepts them but the loader does not. The proven canonical layout (used by self-improving-agent in #536): <plugin>/ ├── .claude-plugin/plugin.json skills: "./skills" └── skills/ ├── <skill-1>/SKILL.md ├── <skill-2>/SKILL.md └── ... Restructured 9 multi-skill domain plugins: - business-growth (4 skills moved) - c-level-advisor (28) - engineering (36) - engineering-team (32) - finance (2) - marketing-skill (43) - product-team (12) - project-management (8) - ra-qm-team (13) Also fixed standalone plugins that had root SKILL.md + ./skills/ subdir (agenthub, autoresearch-agent, executive-mentor, playwright-pro). The loader rejected them despite skills="./skills" because of the conflicting root SKILL.md (compare self-improving-agent which works because PR #536 moved its root SKILL.md). Moved each root SKILL.md into ./skills/<name>/. Restored standalone plugin folders to their original paths after the multi-skill restructure swept them into parent skills/ directories (marketplace.json source paths require original locations). Removed 7 orphaned marketplace entries that pointed to skill folders without their own plugin.json (content-creator, demand-gen, fullstack-engineer, aws-architect, product-manager, scrum-master, skill-security-auditor) — these were already non-functional. Bumped patch versions on every changed plugin and synced marketplace.json. Marketplace now lists 29 working plugins (down from 36). After merge: users run `/plugin marketplace update claude-code-skills` followed by `/plugin update --all` to pick up the working layout.
1.1 KiB
1.1 KiB
Secret Pattern Reference
Detection Categories
Critical
- OpenAI-like keys (
sk-...) - GitHub personal access tokens (
ghp_...) - AWS access key IDs (
AKIA...)
High
- Slack tokens (
xox...) - Private key PEM blocks
- Hardcoded assignments to
secret,token,password,api_key
Medium
- JWT-like tokens in plaintext
- Suspected credentials in docs/scripts that should be redacted
Severity Guidance
critical: immediate rotation required; treat as active incidenthigh: likely sensitive; investigate and rotate if real credentialmedium: possible exposure; verify context and sanitize where needed
Response Playbook
- Revoke or rotate exposed credential.
- Identify blast radius (services, environments, users).
- Remove from code/history where possible.
- Add preventive controls (pre-commit hooks, CI secret scans).
- Verify monitoring and access logs for abuse.
Preventive Baseline
- Commit only
.env.example, never.env. - Keep
.gitignorepatterns for env and key material. - Use secret managers for staging/prod.
- Redact sensitive values from logs and debug output.