claude-skills/engineering/skills/env-secrets-manager/references/secret-patterns.md
Reza Rezvani 1851c8fb09 fix(plugins): restructure 9 multi-skill domain plugins into ./skills/ layout
Same root cause as #587/#591 — Claude Code's runtime loader rejects
array-form skills paths like ["./content-production", "./ai-seo", ...]
even when each entry is a valid subdirectory containing SKILL.md.
`claude plugin validate` accepts them but the loader does not.

The proven canonical layout (used by self-improving-agent in #536):

  <plugin>/
  ├── .claude-plugin/plugin.json    skills: "./skills"
  └── skills/
      ├── <skill-1>/SKILL.md
      ├── <skill-2>/SKILL.md
      └── ...

Restructured 9 multi-skill domain plugins:
- business-growth (4 skills moved)
- c-level-advisor (28)
- engineering (36)
- engineering-team (32)
- finance (2)
- marketing-skill (43)
- product-team (12)
- project-management (8)
- ra-qm-team (13)

Also fixed standalone plugins that had root SKILL.md + ./skills/ subdir
(agenthub, autoresearch-agent, executive-mentor, playwright-pro). The
loader rejected them despite skills="./skills" because of the conflicting
root SKILL.md (compare self-improving-agent which works because PR #536
moved its root SKILL.md). Moved each root SKILL.md into ./skills/<name>/.

Restored standalone plugin folders to their original paths after the
multi-skill restructure swept them into parent skills/ directories
(marketplace.json source paths require original locations).

Removed 7 orphaned marketplace entries that pointed to skill folders
without their own plugin.json (content-creator, demand-gen,
fullstack-engineer, aws-architect, product-manager, scrum-master,
skill-security-auditor) — these were already non-functional.

Bumped patch versions on every changed plugin and synced
marketplace.json. Marketplace now lists 29 working plugins (down
from 36).

After merge: users run `/plugin marketplace update claude-code-skills`
followed by `/plugin update --all` to pick up the working layout.
2026-05-02 22:51:20 +02:00

1.1 KiB

Secret Pattern Reference

Detection Categories

Critical

  • OpenAI-like keys (sk-...)
  • GitHub personal access tokens (ghp_...)
  • AWS access key IDs (AKIA...)

High

  • Slack tokens (xox...)
  • Private key PEM blocks
  • Hardcoded assignments to secret, token, password, api_key

Medium

  • JWT-like tokens in plaintext
  • Suspected credentials in docs/scripts that should be redacted

Severity Guidance

  • critical: immediate rotation required; treat as active incident
  • high: likely sensitive; investigate and rotate if real credential
  • medium: possible exposure; verify context and sanitize where needed

Response Playbook

  1. Revoke or rotate exposed credential.
  2. Identify blast radius (services, environments, users).
  3. Remove from code/history where possible.
  4. Add preventive controls (pre-commit hooks, CI secret scans).
  5. Verify monitoring and access logs for abuse.

Preventive Baseline

  • Commit only .env.example, never .env.
  • Keep .gitignore patterns for env and key material.
  • Use secret managers for staging/prod.
  • Redact sensitive values from logs and debug output.