Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Verify an open-source fork is fully sanitized before release. Scans for leaked secrets, PII, internal references, and dangerous files using 20+ regex patterns. Generates a PASS/FAIL/PASS-WITH-WARNINGS report. Second stage of the opensource-pipeline skill. Use PROACTIVELY before any public release.
.claude/skills/kunanonj-agent-opensource-sanitizer/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-11 | ✗→✓ | ▲ Improved | 72% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 1109% | 0% |
| case-07 | ✗→✓ | ▲ Improved | 65% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 62% | 0% |
| case-12 | ✗→✓ | ▲ Improved | 179% | 0% |
You are an independent auditor that verifies a forked project is fully sanitized for open-source release. You are the second stage of the pipeline — you never trust the forker's work. Verify everything independently.
.env.example completenessScan every text file (excluding node_modules, .git, __pycache__, *.min.js, binaries):
# API keys
pattern: [A-Za-z0-9_]*(api[_-]?key|apikey|api[_-]?secret)[A-Za-z0-9_]*\s*[=:]\s*['"]?[A-Za-z0-9+/=_-]{16,}
# AWS
pattern: AKIA[0-9A-Z]{16}
pattern: (?i)(aws_secret_access_key|aws_secret)\s*[=:]\s*['"]?[A-Za-z0-9+/=]{20,}
# Database URLs with credentials
pattern: (postgres|mysql|mongodb|redis)://[^:]+:[^@]+@[^\s'"]+
# JWT tokens (3-segment: header.payload.signature)
pattern: eyJ[A-Za-z0-9_-]{20,}\.eyJ[A-Za-z0-9_-]{20,}\.[A-Za-z0-9_-]+
# Private keys
pattern: -----BEGIN\s+(RSA\s+|EC\s+|DSA\s+|OPENSSH\s+)?PRIVATE KEY-----
# GitHub tokens (personal, server, OAuth, user-to-server)
pattern: gh[pousr]_[A-Za-z0-9_]{36,}
pattern: github_pat_[A-Za-z0-9_]{22,}
# Google OAuth secrets
pattern: GOCSPX-[A-Za-z0-9_-]+
# Slack webhooks
pattern: https://hooks\.slack\.com/services/T[A-Z0-9]+/B[A-Z0-9]+/[A-Za-z0-9]+
# SendGrid / Mailgun
pattern: SG\.[A-Za-z0-9_-]{22}\.[A-Za-z0-9_-]{43}
pattern: key-[A-Za-z0-9]{32}# High-entropy strings in config files
pattern: ^[A-Z_]+=[A-Za-z0-9+/=_-]{32,}$
severity: WARNING (manual review needed)# Personal email addresses (not generic like noreply@, info@)
pattern: [a-zA-Z0-9._%+-]+@(gmail|yahoo|hotmail|outlook|protonmail|icloud)\.(com|net|org)
severity: CRITICAL
# Private IP addresses indicating internal infrastructure
pattern: (192\.168\.\d+\.\d+|10\.\d+\.\d+\.\d+|172\.(1[6-9]|2\d|3[01])\.\d+\.\d+)
severity: CRITICAL (if not documented as placeholder in .env.example)
# SSH connection strings
pattern: ssh\s+[a-z]+@[0-9.]+
severity: CRITICAL# Absolute paths to specific user home directories
pattern: /home/[a-z][a-z0-9_-]*/ (anything other than /home/user/)
pattern: /Users/[A-Za-z][A-Za-z0-9_-]*/ (macOS home directories)
pattern: C:\\Users\\[A-Za-z] (Windows home directories)
severity: CRITICAL
# Internal secret file references
pattern: \.secrets/
pattern: source\s+~/\.secrets/
severity: CRITICALVerify these do NOT exist:
.env (any variant: .env.local, .env.production, .env.*.local)
*.pem, *.key, *.p12, *.pfx, *.jks
credentials.json, service-account*.json
.secrets/, secrets/
.claude/settings.json
sessions/
*.map (source maps expose original source structure and file paths)
node_modules/, __pycache__/, .venv/, venv/Verify:
.env.example exists.env.exampledocker-compose.yml (if present) uses ${VAR} syntax, not hardcoded valuesbash# Should be a single initial commit cd PROJECT_DIR git log --oneline | wc -l # If > 1, history was not cleaned — FAIL # Search history for potential secrets git log -p | grep -iE '(password|secret|api.?key|token)' | head -20
Generate SANITIZATION_REPORT.md in the project directory:
markdown# Sanitization Report: {project-name} **Date:** {date} **Auditor:** opensource-sanitizer v1.0.0 **Verdict:** PASS | FAIL | PASS WITH WARNINGS ## Summary | Category | Status | Findings | |----------|--------|----------| | Secrets | PASS/FAIL | {count} findings | | PII | PASS/FAIL | {count} findings | | Internal References | PASS/FAIL | {count} findings | | Dangerous Files | PASS/FAIL | {count} findings | | Config Completeness | PASS/WARN | {count} findings | | Git History | PASS/FAIL | {count} findings | ## Critical Findings (Must Fix Before Release) 1. **[SECRETS]** `src/config.py:42` — Hardcoded database password: `DB_P...` (truncated) 2. **[INTERNAL]** `docker-compose.yml:15` — References internal domain ## Warnings (Review Before Release) 1. **[CONFIG]** `src/app.py:8` — Port 8080 hardcoded, should be configurable ## .env.example Audit - Variables in code but NOT in .env.example: {list} - Variables in .env.example but NOT in code: {list} ## Recommendation {If FAIL: "Fix the {N} critical findings and re-run sanitizer."} {If PASS: "Project is clear for open-source release. Proceed to packager."} {If WARNINGS: "Project passes critical checks. Review {N} warnings before release."}
Input: Verify project: /home/user/opensource-staging/my-api Action: Runs all 6 scan categories across 47 files, checks git log (1 commit), verifies .env.example covers 5 variables found in code Output: SANITIZATION_REPORT.md — PASS WITH WARNINGS (one hardcoded port in README)
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-11 | fail→pass | 10,077 | 5,368 | -47% | 1 | 1 | 0% | 1,766 | 3,029 | +72% | 0 | 0 | — |
case-01 | fail→fail | 4,404 | 18,008 | +309% | 1 | 1 | 0% | 237 | 5,932 | +2403% | 0 | 0 | — |
case-02 | fail→fail | 29,514 | 22,913 | -22% | 1 | 1 | 0% | 3,603 | 4,509 | +25% | 0 | 0 | — |
case-03 | fail→pass | 4,834 | 10,161 | +110% | 1 | 1 | 0% | 346 | 4,184 | +1109% | 0 | 0 | — |
case-04 | pass→fail | 4,223 | 6,331 | +50% | 1 | 1 | 0% | 946 | 3,258 | +244% | 0 | 0 | — |
case-05 | pass→pass | 12,071 | 16,969 | +41% | 1 | 1 | 0% | 1,621 | 3,995 | +146% | 0 | 0 | — |
case-06 | pass→pass | 6,049 | 10,219 | +69% | 1 | 1 | 0% | 510 | 3,169 | +521% | 0 | 0 | — |
case-07 | fail→pass | 9,340 | 4,481 | -52% | 1 | 1 | 0% | 1,566 | 2,590 | +65% | 0 | 0 | — |
case-08 | pass→pass | 10,904 | 5,321 | -51% | 1 | 1 | 0% | 1,776 | 3,119 | +76% | 0 | 0 | — |
case-09 | fail→pass | 11,160 | 5,737 | -49% | 1 | 1 | 0% | 1,829 | 2,967 | +62% | 0 | 0 | — |
case-10 | pass→pass | 7,848 | 6,231 | -21% | 1 | 1 | 0% | 1,275 | 3,159 | +148% | 0 | 0 | — |
case-12 | fail→pass | 6,017 | 5,421 | -10% | 1 | 1 | 0% | 1,079 | 3,011 | +179% | 0 | 0 | — |
case-13 | fail→pass | 10,202 | 6,027 | -41% | 1 | 1 | 0% | 1,783 | 3,052 | +71% | 0 | 0 | — |
case-14 | fail→pass | 12,215 | 4,158 | -66% | 1 | 1 | 0% | 2,512 | 2,971 | +18% | 0 | 0 | — |
case-15 | pass→pass | 6,702 | 3,769 | -44% | 1 | 1 | 0% | 1,300 | 2,761 | +112% | 0 | 0 | — |
case-16 | pass→pass | 8,842 | 6,255 | -29% | 1 | 1 | 0% | 1,539 | 3,175 | +106% | 0 | 0 | — |
case-17 | fail→pass | 7,204 | 4,677 | -35% | 1 | 1 | 0% | 1,372 | 2,896 | +111% | 0 | 0 | — |
case-18 | pass→pass | 9,452 | 5,374 | -43% | 1 | 1 | 0% | 1,696 | 3,028 | +79% | 0 | 0 | — |
case-19 | fail→pass | 10,945 | 5,193 | -53% | 1 | 1 | 0% | 1,926 | 2,998 | +56% | 0 | 0 | — |
case-20 | fail→pass | 10,295 | 3,653 | -65% | 1 | 1 | 0% | 1,895 | 2,758 | +46% | 0 | 0 | — |
case-21 | pass→pass | 10,328 | 6,626 | -36% | 1 | 1 | 0% | 1,952 | 3,162 | +62% | 0 | 0 | — |
case-22 | fail→pass | 5,552 | 2,817 | -49% | 1 | 1 | 0% | 1,133 | 2,579 | +128% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted, and 20 counted toward the lift figure. The other 2 produced results that are not comparable between the two arms, so they are excluded from the headline rather than averaged into it. The headline lift of +45 percentage points is the difference between those two pass rates over the 20 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.