rderickson9

Hardcoded Secret Scanner — Development agent for Claude Code

Development community

Scan a trading codebase for credentials that live in code, config committed to git, logs, tests, or documentation instead of a secret store: broker API keys and secrets, exchange keys, bot and webhook.

How to install Hardcoded Secret Scanner

Installs to ~/.claude/agents/rderickson9-trading-safety-pack-free-hardcoded-secret-scanner.md

Terminal
mkdir -p ~/.claude/agents && curl -fsSL https://raw.githubusercontent.com/rderickson9/trading-safety-pack-free/HEAD/agents/hardcoded-secret-scanner.md -o ~/.claude/agents/rderickson9-trading-safety-pack-free-hardcoded-secret-scanner.md

Restart Claude Code, or start a new session, for it to be picked up.

What Hardcoded Secret Scanner does


name: hardcoded-secret-scanner description: Scan a trading codebase for credentials that live in code, config committed to git, logs, tests, or documentation instead of a secret store: broker API keys and secrets, exchange keys, bot and webhook tokens, database URLs with passwords, private keys, account numbers, and the near-miss patterns that leak them (printing settings, logging request headers, committing .env). Reports presence and location only; never prints the secret value. Use before

Alternatives in Development

  • Browser Stealth Agent — Stealth browser automation agent for targets behind Cloudflare, Akamai, Google, DataDome, or PerimeterX bot de 812 ★
  • Dashclaw Drift Auditor — Audits DashClaw's drift-prone hardcoded counts and version stamps — SDK method counts (Node/Python), MCP tool/ 297 ★
  • Mack — Automation Specialist 296 ★

Full documentation available on GitHub

View Source Repository