DCL Secret Leak Detector
by @daririnch
Instruction-only runtime secret and credential leak detector for AI agents and LLM pipelines. Catches API keys, tokens, private keys, database URLs, and .env...
clawhub install dcl-secret-leak-detectorπ About This Skill
description: "Instruction-only runtime secret and credential leak detector for AI agents and LLM pipelines. Catches API keys, tokens, private keys, database URLs, and .env values entirely within the agent context β no text ever leaves the agent. Every detection produces a deterministic DCL audit proof. The specialist companion to DCL Sentinel Trace β for secrets, not just PII." tags: [secret-detection, credential-leak, api-key, token-leak, private-key, env-leak, database-credentials, runtime-security, llm-guardrails, agent-safety, compliance, audit, tamper-evident, cryptographic-proof, leibniz-layer, ai-safety, pipeline-security, devsecops, secrets-management, instruction-only, zero-trust]
DCL Secret Leak Detector β Leibniz Layerβ’
Publisher: @daririnch Β· Fronesis Labs Version: 1.0.0 Part of: Leibniz Layerβ’ Security Suite
What this skill does
DCL Secret Leak Detector scans AI agent outputs, tool results, and pipeline data for exposed secrets and credentials β before they reach users, logs, or downstream systems.
This skill is 100% instruction-only. No text is sent to any external server. No webhook is called. The entire analysis runs inside the agent's context window using the detection checklist below. The scanned text never leaves the agent.
Every detection produces a deterministic dcl_fingerprint β a self-contained audit proof compatible with the Leibniz Layerβ’ chain.
What gets detected
| Category | Pattern class |
|----------|--------------|
| api_key | Provider-prefixed keys: OpenAI, Anthropic, Stripe, GitHub, Slack patterns |
| cloud_credential | AWS access key IDs, GCP service account fragments, Azure client secrets |
| token | Bearer tokens, JWT strings, OAuth access tokens, high-entropy credential-context strings |
| private_key_pem | PEM header/footer blocks for any private key type |
| database_url | Connection strings with embedded credentials: proto://user:pass@host |
| connection_string | ADO.NET, ODBC, SQLAlchemy strings containing password fields |
| env_assignment | .env-style lines where variable name matches known secret patterns |
| webhook_secret | Signed secrets for Stripe, GitHub, Twilio webhook endpoints |
| internal_endpoint | URLs containing API keys or tokens as query parameters |
How to run a scan
The user provides text to scan directly in the conversation β model output, tool result, generated code, retrieved document chunk, or any pipeline data. This skill makes no network requests and does not transmit content anywhere.
Step 1 β Confirm content is in context
Verify the text to scan is present in the conversation. If not provided, ask the user to paste it.
Step 2 β Compute content fingerprint
content_hash = SHA-256(raw text submitted for scanning)
Record this as the immutable identifier for this scan event.
Step 3 β Run the detection checklist
Work through every category in the Detection Checklist below. For each match found, record:
type β which category triggeredprovider β which service the credential belongs to (if identifiable)position β approximate character offset in the textredacted_sample β masked version showing only first 2 and last 4 charsseverity β critical, major, or minorIf no patterns match a category, mark it CLEAR.
Step 4 β Apply verdict logic
| Condition | Verdict |
|---|---|
| Any finding at any severity | NO_COMMIT |
| No findings | COMMIT |
Any detected secret, regardless of severity, results in NO_COMMIT. Secrets have no safe threshold.
Step 5 β Compute DCL proof
analysis_content = verdict + all findings serialized + timestamp
analysis_hash = SHA-256(analysis_content)
dcl_fingerprint = "DCL-SLD-" + date + "-" + content_hash[:8] + "-" + analysis_hash[:8]
Detection Checklist
Work through each item. Mark CLEAR or record finding with redacted evidence.
S1 β API Keys (Critical)
S2 β Cloud Credentials (Critical)
S3 β Tokens & JWTs (Critical)
S4 β Private Keys (Critical)
-----BEGIN + key type descriptor + ----------END + key type descriptor + -----S5 β Database & Connection Strings (Critical)
:// + username + : + password + @ + hostUser ID= and Password= or Pwd= fieldsS6 β Environment Variable Assignments (Major)
KEY, SECRET, TOKEN, PASS, PWD, CREDENTIAL, AUTHVARNAME=value where value is non-trivial (not placeholder, not empty)S7 β Webhook & Signed URL Secrets (Major)
S8 β Internal Endpoints with Auth (Minor β Major)
.internal, .local, .corp, .intra) with auth query parametersapi_key=, apikey=, token=, secret=, or access_token= appears with a non-trivial value (Major)Output schema
{
"verdict": "COMMIT | NO_COMMIT",
"risk_score": 0.0,
"content_hash": "sha256:<64-char hex>",
"analysis_hash": "sha256:<64-char hex>",
"dcl_fingerprint": "DCL-SLD-2026-04-14--",
"detections": [
{
"type": "api_key",
"provider": "identified provider name",
"redacted_sample": "[PREFIX]-**...**[SUFFIX]",
"position": 87,
"severity": "critical"
}
],
"detection_count": 0,
"categories_checked": ["S1","S2","S3","S4","S5","S6","S7","S8"],
"categories_clear": ["S1","S2","S3","S4","S5","S6","S7","S8"],
"timestamp": "2026-04-14T09:00:00Z",
"powered_by": "DCL Secret Leak Detector Β· Leibniz Layerβ’ Β· Fronesis Labs"
}
detections is an empty array [] when verdict is COMMIT.
Secret Leak Detector vs DCL Sentinel Trace
These two skills are complementary, not competing. Run both.
| | DCL Sentinel Trace | DCL Secret Leak Detector | |---|---|---| | Focus | Personal identity data | Technical credentials | | Catches | Emails, phones, SSNs, IBANs, card PANs | API keys, tokens, private keys, DB URLs | | Regulation | GDPR, HIPAA | SOC 2, ISO 27001, internal SecOps | | Primary risk | Privacy breach | Security breach / credential compromise | | External calls | Via webhook | None β instruction-only |
A response can be PII-clean and still contain a live credential. Both checks are necessary for complete output coverage.
Where Secret Leak Detector fits in the DCL pipeline
Untrusted input
β
βΌ
DCL Prompt Firewall β blocks malicious input
β COMMIT
βΌ
LLM call
β
βΌ
DCL Policy Enforcer β compliance & jailbreak check
β COMMIT
βΌ
DCL Sentinel Trace β PII redaction
β COMMIT
βΌ
DCL Secret Leak Detector β credential & secret scan (instruction-only)
β COMMIT
βΌ
DCL Output Sanitizer β final sweep: toxic, unsafe commands
β COMMIT
βΌ
DCL Semantic Drift Guard β hallucination & grounding check
β IN_COMMIT
βΌ
Safe to deliver
High-risk agent patterns
Coding agents β generate shell scripts, Dockerfiles, CI configs, Terraform. Common vector for hardcoded credentials appearing in generated output.
DevOps / infrastructure agents β read deployment configs, env files, Kubernetes secrets. May quote them verbatim in responses.
RAG pipelines over internal docs β internal wikis and runbooks routinely contain credentials left by engineers. Retrieved chunks can carry them into LLM context and outputs.
Tool-calling agents β an agent that calls an API internally may reproduce the key in its reasoning trace or final response.
Privacy & Data Policy
This skill is operated by Fronesis Labs and is 100% instruction-only.
No data leaves the agent. The text submitted for scanning is analyzed entirely within the agent's context window. No content is transmitted to any server β including Fronesis Labs infrastructure.
No retention. Nothing is stored, logged, or transmitted. The only artifact produced is the structured JSON output and dcl_fingerprint, which remain within the agent's session unless the caller saves them.
Detected secrets: Only redacted samples are included in output. Raw credential values are never reproduced in the result.
Full policy: https://fronesislabs.com/#privacy Β· Browse the full DCL Security Suite: hub.fronesislabs.com Β· Questions: support@fronesislabs.com
Related skills
dcl-sentinel-trace β PII redaction and identity exposure detectiondcl-prompt-firewall β Input-layer injection and jailbreak detectiondcl-output-sanitizer β Final output sweep: toxic content, unsafe commandsdcl-secret-leak-detector-crypto β Specialist version for wallet keys, seed phrases, exchange credentialsLeibniz Layerβ’ Β· Fronesis Labs Β· fronesislabs.com