github-sensitive-data-cleanup
Scan and remove secrets, keys, private IPs and PII from GitHub repository history before force-push.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for github-sensitive-data-cleanup, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
Community Agent Skill that scans and rewrites git history to remove leaked secrets, API keys, private domains/IPs and PII. Verifies visibility, backs up, and scans before any force push to a public repo. Runs history-rewriting and scanning commands that mutate the repository — high security surface.
Key features and capabilities
- Secret/PII history scanning
- History rewrite and force-push safety checks
- Pre-push visibility and backup verification
Use cases
- Repairing a repo after a secret leak
- Sanitizing history before making a repo public