AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Specstory Guard

skill-specstoryai-agent-skills-specstory-guard · by specstoryai

Install a pre-commit hook that scans .specstory/history for secrets before commits. Run when user says "set up secret scanning", "install specstory guard", "protect my history", or "check for secrets".

No reviews yet
0 installs
6 views
0.0% view→install

Install

$ agentstack add skill-specstoryai-agent-skills-specstory-guard

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-specstoryai-agent-skills-specstory-guard)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
6mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Specstory Guard? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

SpecStory Guard

A pre-commit guardrail that scans .specstory/history for potential secrets and blocks commits until they are removed or redacted.

How It Works

  1. Installs a git pre-commit hook in your repository
  2. Scans .specstory/history files on every commit
  3. Detects common secret patterns (API keys, tokens, private keys)
  4. Blocks the commit if secrets are found
  5. Reports findings with redacted previews for safe review

Why Use Guard?

AI coding sessions may inadvertently capture sensitive data:

  • API keys you pasted into chat
  • Environment variables in command output
  • Private keys or tokens in error messages
  • Credentials in configuration examples

Guard prevents accidental commits of these secrets.

Usage

Slash Command

| User says | Action | |-----------|--------| | /specstory-guard | Install the pre-commit hook | | /specstory-guard install | Install the pre-commit hook | | /specstory-guard scan | Run a manual scan without installing | | /specstory-guard check | Alias for scan | | /specstory-guard uninstall | Remove the pre-commit hook |

Direct Script Usage

# Install the pre-commit hook
python skills/specstory-guard/scripts/guard.py install

# Run a manual scan
python skills/specstory-guard/scripts/guard.py scan --root .

# Uninstall the hook
python skills/specstory-guard/scripts/guard.py uninstall

# Scan with custom allowlist
SPECSTORY_GUARD_ALLOWLIST='example-key,PLACEHOLDER_.*' \
  python skills/specstory-guard/scripts/guard.py scan --root .

Output

Scan with findings:

SpecStory Guard - Security Scan
===============================

Scanning .specstory/history/...

ALERT: Potential secrets found!

File: .specstory/history/2026-01-22_19-20-56Z-api-setup.md
  Line 142: AWS_SECRET_ACCESS_KEY=AKIA...redacted...XYZ
  Line 289: private_key: "-----BEGIN RSA PRIVATE KEY-----..."

File: .specstory/history/2026-01-20_10-15-33Z-debug-auth.md
  Line 56: Authorization: Bearer eyJhbG...redacted...

Total: 3 potential secrets in 2 files

Commit blocked. Please redact or remove these secrets before committing.

Clean scan:

SpecStory Guard - Security Scan
===============================

Scanning .specstory/history/...

All clear! No secrets detected in 47 files.

Installation success:

SpecStory Guard - Setup
=======================

Pre-commit hook installed at .git/hooks/pre-commit

The hook will now scan .specstory/history/ before each commit.
To test: python skills/specstory-guard/scripts/guard.py scan --root .

Detected Patterns

Guard scans for these common secret patterns:

| Pattern | Example | |---------|---------| | AWS Keys | AKIA..., aws_secret_access_key | | API Tokens | Bearer ..., token: ... | | Private Keys | -----BEGIN RSA PRIVATE KEY----- | | GitHub Tokens | ghp_..., github_pat_... | | Generic Secrets | password=, secret=, api_key= |

Tuning with Allowlist

If you have false positives (example keys, placeholders), use the allowlist:

# Environment variable (comma-separated regex patterns)
SPECSTORY_GUARD_ALLOWLIST='example-key,PLACEHOLDER_.*,test-token' \
  python skills/specstory-guard/scripts/guard.py scan --root .

Remediation

When secrets are found:

  1. Open the file - Find the line number from the report
  2. Redact the secret - Replace with [REDACTED] or remove the line
  3. Re-run scan - Verify the fix with another scan
  4. Commit - The pre-commit hook will pass

Present Results to User

After running guard commands:

  1. For install - Confirm the hook is installed and explain what it does
  2. For scan with findings - List the findings and offer to help redact them
  3. For clean scan - Confirm no secrets were found

Example Response (findings)

I found 3 potential secrets in your SpecStory history:

1. **AWS credentials** in `2026-01-22_19-20-56Z-api-setup.md` (line 142)
2. **Private key** in the same file (line 289)
3. **Bearer token** in `2026-01-20_10-15-33Z-debug-auth.md` (line 56)

Would you like me to help redact these? I can replace them with `[REDACTED]`
while preserving the rest of the conversation context.

Notes

  • Uses no external dependencies (pure Python)
  • Hook runs automatically on git commit
  • Scan is fast - typically under 1 second for hundreds of files
  • Allowlist patterns are regular expressions

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.