Back to loops
Securitymanual triggermarkdown-export Hardened

Secret Leak Scan Loop

A security loop that makes secret scanning an explicit feedback gate for AI-generated repository changes.

Use loop copies the kickoff prompt. Copy Markdown and Download loop include the complete Markdown page with context, source attribution, anchors, and guardrails. Cursor / Claude Code buttons prepare the shorter kickoff prompt only.

Run shape

Supported agents

Claude CodeCodexGemini CLIOpenCode

Goal

Prevent secrets and local credentials from leaving the working tree.

Feedback gate

git diff --cached | rg -n "(API_KEY|SECRET|TOKEN|PASSWORD|PRIVATE_KEY|BEGIN RSA|BEGIN OPENSSH)"

Stop condition

No unapproved secrets or local credentials are present in staged or changed files.

Do not weaken, skip, delete, or rewrite the validation command to force success.
Do not claim completion until the stated exit condition is actually satisfied.
If blocked, report the blocker, evidence, and next safest action instead of gaming the metric.
Required context

Give the agent these inputs before it starts the loop. This keeps discovery bounded and prevents vague retries.

Changed files.
Known secret naming conventions.
Required tools

The loop assumes these commands or integrations are available. Missing tools should be reported as blockers, not ignored.

git
rg
How to run

Two separate pieces: the kickoff prompt starts the loop, while the downloaded Markdown carries the complete reference page.

1. Copy or download

Use the kickoff for a fast agent run. Download the full Markdown when you need source, context, and attribution in one file.

2. Paste into the agent

Start a fresh agent session in the target repo and provide the requested project context if the loop asks for it.

3. Let it self-pace

The agent should act, check evidence, retry only when the gate fails, and stop at the stated exit condition.

manual triggerSecurity Step flow
Manual start
Scan staged diff
Scan file names
Remove or replace
Re-scan
Feedback gate
Goal complete with evidence
not done → return to next actiondone → exit condition met
Manual startScan staged diffScan file namesRemove or replaceRe-scanFeedback gatedoneGoal complete with evidencenot done
Action checklist

The diagram shows the order. This checklist keeps only the action, command, and failure handling needed during a real pass.

1. Scan staged diff

Search staged content for common secret patterns.

git diff --cached | rg -n "(API_KEY|SECRET|TOKEN|PASSWORD|PRIVATE_KEY)"

2. Scan file names

Check for committed env or credential files.

git status --short | rg "(.env|pem|key|credentials)"

3. Remove or replace

Move secrets to env templates or secret managers and rotate if exposed.

4. Re-scan

Run the scan again and report evidence.

Kickoff prompt

This is the text copied by Use loop. It is intentionally shorter than the Markdown export.

Scan changed and staged files for secrets, local env files, and debug leaks. Remove or redact unsafe values and repeat until clean.
Goal: Prevent secrets and local credentials from leaving the working tree.
Check command: git diff --cached | rg -n "(API_KEY|SECRET|TOKEN|PASSWORD|PRIVATE_KEY|BEGIN RSA|BEGIN OPENSSH)"
Exit condition: No unapproved secrets or local credentials are present in staged or changed files.
Max iterations: 4
Guardrails:
- Do not weaken, skip, delete, or rewrite the validation command to force success.
- Do not claim completion until the stated exit condition is actually satisfied.
- If blocked, report the blocker, evidence, and next safest action instead of gaming the metric.
- Never print raw secrets in the final answer. Redact values if they appear in output.

Quality

90/100

Safety

97/100

Expected output

A redacted scan report and any required cleanup actions.

Related loops

Browse all
Securityevent trigger Hardened

Pre-Commit Guard

Before committing, run diff hygiene, secrets checks, and the closest validation command.

Claude CodeCodexGemini CLIOpenCode
pre-commitsecuritygit

Kickoff preview

Before committing, inspect the staged diff, scan for secrets/debug flags, run relevant validation, and only commit if the guard passes.
Goal: Block commits that contain secrets, debug switches, or unverified broken code.
Check command: git diff --cached --check
Exit condition: Staged diff is clean, no obvious secrets/debug flags are present, and relevant validation passes or is explained.
Max iterations: 3
Guardrails:
- Do not weaken, skip, delete, or rewrite the validation command to force success.
- Do not claim completion until the stated exit condition is actually satisfied.
- If blocked, report the blocker, evidence, and next safest action instead of gaming the metric.
- Do not commit secrets, local env files, debug flags, or generated private artifacts.
View
DevOpsmanual trigger Hardened

Environment Variable Audit

Compare env templates, runtime config, deployment secrets, and code references to catch missing or leaked variables.

Claude CodeCodexGemini CLIOpenCode
envsecretsdeployment

Kickoff preview

Audit all environment variable references, classify public vs secret scope, compare env templates and deployment config, and report missing or unsafe variables.
Goal: Ensure required env vars exist in the right place and secrets are not exposed client-side.
Check command: rg -n "process.env|import.meta.env|VITE_" src .env.example wrangler.example.jsonc
Exit condition: All referenced env vars are documented and correctly scoped.
Max iterations: 3
Guardrails:
- Do not weaken, skip, delete, or rewrite the validation command to force success.
- Do not claim completion until the stated exit condition is actually satisfied.
- If blocked, report the blocker, evidence, and next safest action instead of gaming the metric.
- Never move server-only secrets into public `VITE_` variables.
View
Securitymanual trigger Hardened

npm Audit Fix Loop

Review npm audit findings, apply safe upgrades, and verify the app still builds and tests.

Claude CodeCodexGemini CLIOpenCode
npm-auditdependenciessecurity

Kickoff preview

Run audit, review safe remediation paths, update targeted dependencies, verify build/tests, and report remaining vulnerability risk.
Goal: Remediate actionable vulnerabilities without unsafe forced upgrades.
Check command: npm audit --audit-level=high
Exit condition: No high/critical audit findings remain, or remaining findings are documented with blockers.
Max iterations: 5
Guardrails:
- Do not weaken, skip, delete, or rewrite the validation command to force success.
- Do not claim completion until the stated exit condition is actually satisfied.
- If blocked, report the blocker, evidence, and next safest action instead of gaming the metric.
- Do not run force upgrades without explaining breaking-change risk and receiving approval.
View
CImanual trigger Hardened

Ship PR Until Green

Implement a scoped change, open or update a pull request, inspect CI, and continue until all required PR checks pass.

CursorClaude CodeCodex
pull-requestcigithub-actionsverification

Kickoff preview

Take this branch to a green pull request. Implement the requested change, run local verification, open or update the PR, run `gh pr checks`, inspect failures, fix root causes, and repeat until every required check passes or you hit the iteration cap.
Goal: Open or update a pull request and stop only when all required PR checks are green.
Check command: gh pr checks
Exit condition: All required pull request checks are successful and the PR is ready for review or merge.
Max iterations: 10
Guardrails:
- Do not weaken, skip, delete, or rewrite the validation command to force success.
- Do not claim completion until the stated exit condition is actually satisfied.
- If blocked, report the blocker, evidence, and next safest action instead of gaming the metric.
- Do not disable required checks, edit loops to skip jobs, or remove tests to make CI green.
- Do not merge the PR unless the user explicitly asked for merge authority.
View