secrets-in-git-history
useosint/osint-skillsMine GitHub, GitLab and git history for identities, infrastructure and leaked credentials using commit author emails, GitHub code search, the commit .patch…
Scores out of 100 · grade A
2026-08-22Works
40% of the score100/100
- Loads cleanly: valid frontmatter, required fields present, no dangling references.
Maintained
25% of the score92/100
- no commits in the last 12 weeks
Adopted
20% of the score42/100
- 1,724 installs on skills.sh.
- 21 stars on the source repo.
Documented
15% of the score90/100
- 1,934 words with worked examples.
- Ships 2 bundled files.
Install
npx skills add useosint/osint-skills/secrets-in-git-historyWhat it says it does
Mine GitHub, GitLab and git history for identities, infrastructure and leaked credentials using commit author emails, GitHub code search, the commit .patch endpoint, trufflehog, gitleaks, git log pickaxe and full-ref history scans. Use when investigating a developer or organisation on GitHub, finding leaked API keys, AWS keys or tokens in code, enumerating org members and their personal repos, or recovering secrets deleted from HEAD but still present in history or forks. Applies to software supply-chain risk, credential exposure response, M&A technical diligence, and insider-threat investigation. Reference at useosint.com/skills/secrets-in-git-history.
Also in useosint/osint-skills
| Artifact | Score | What the check found | Type | Reach | Last commit |
|---|---|---|---|---|---|
| read-deleted-pagesuseosint/osint-skills | clean | Skill | 1,847 installs | 19 days ago | |
| secrets-in-file-metadatauseosint/osint-skills | clean | Skill | 1,651 installs | 19 days ago | |
| who-owns-this-domainuseosint/osint-skills | clean | Skill | 1,738 installs | 19 days ago | |
| find-exposed-serversuseosint/osint-skills | clean | Skill | 1,826 installs | 19 days ago | |
| find-hidden-subdomainsuseosint/osint-skills | clean | Skill | 1,587 installs | 19 days ago | |
| find-the-original-imageuseosint/osint-skills | clean | Skill | 56,329 installs | 19 days ago |
Other git & workflow skills
Browse all| Artifact | Score | What the check found | Category | Reach | Last commit |
|---|---|---|---|---|---|
| finishing-a-development-branchobra/superpowers | clean | Git & workflow | 167,156 installs | 2 days ago | |
| using-git-worktreesobra/superpowers | clean | Git & workflow | 170,252 installs | 2 days ago | |
| git-guardrails-claude-codemattpocock/skills | clean | Git & workflow | 252,653 installs | today | |
| github-issuesgithub/awesome-copilot | clean | Git & workflow | 14,854 installs | today | |
| setup-pre-commitmattpocock/skills | clean | Git & workflow | 245,932 installs | today | |
| commitmicrosoft/vscode | clean | Git & workflow | 189k stars | today |
Put this measurement in your README
A badge carrying how many listings this index holds from the repository and how many pass every static structural check. It reads from this index every time somebody loads your page, so it changes when the measurement changes and there is nothing to keep up to date. Free, no account, and the value is not something you or we can set by hand.
[](https://skillworks.kynth.studio/?q=useosint%2Fosint-skills)Would rather not hotlink us? Every badge is also served in shields.io’s endpoint schema, so shields renders the image and your readers never talk to our domain:
Published by Toolproof, the masthead over this index and eight others. The method behind the number is at toolproof.kynth.studio/methodology, and the whole thing is readable as JSON with no key at /api.
