# GitGuardian

> Open-source publisher. Listings imported from github.com/GitGuardian — credited to the original author with their license.

- **Listings:** 7
- **Total installs:** 0
- **Profile:** https://agentstack.voostack.com/s/gitguardian
- **Website:** https://github.com/GitGuardian

## Published listings

- [Ggmcp](https://agentstack.voostack.com/l/mcp-gitguardian-ggmcp) — MCP server · Free · security-reviewed — `agentstack add mcp-gitguardian-ggmcp`
  MCP server for remediating hardcoded secrets using GitGuardian’s API. It detects over 600 secret types and prevents credential leaks before code is made public.
- [Check Hmsl](https://agentstack.voostack.com/l/skill-gitguardian-agent-skills-check-hmsl) — Skill · Free · security-reviewed — `agentstack add skill-gitguardian-agent-skills-check-hmsl`
  Check whether a known credential has already leaked publicly via GitGuardian's HasMySecretLeaked (HMSL) hash-lookup service. Use when the user inherits credentials, suspects a specific token leaked, wants to vet a HashiCorp Vault inventory, or asks "has this secret leaked", "is this compromised", or "check against HMSL". Distinct from scan-secrets, which finds unknown secrets in code; this checks…
- [Triage Incidents](https://agentstack.voostack.com/l/skill-gitguardian-agent-skills-triage-incidents) — Skill · Free · security-reviewed — `agentstack add skill-gitguardian-agent-skills-triage-incidents`
  Use when triaging or reviewing GitGuardian secret incidents already detected in the dashboard, when asked what is leaking in the org or what to fix first, when remediating or rotating a credential flagged in an incident, after a Public Monitoring alert, or to assign, tag, or resolve incidents. Operates through the GitGuardian Developer MCP server.
- [Scan Machine](https://agentstack.voostack.com/l/skill-gitguardian-agent-skills-scan-machine) — Skill · Free · security-reviewed — `agentstack add skill-gitguardian-agent-skills-scan-machine`
  Scan a developer's entire machine for credentials across local git repositories, dotfiles, ~/.aws/credentials, ~/.kube/config, ~/.docker/config.json, ~/.npmrc, browser profile databases, shell history, AI agent caches, and abandoned project trees via ggshield machine scan. Use when preparing to wipe, sell, or hand off a laptop, when onboarding a new machine, when auditing what credentials live on…
- [Install Hooks](https://agentstack.voostack.com/l/skill-gitguardian-agent-skills-install-hooks) — Skill · Free · security-reviewed — `agentstack add skill-gitguardian-agent-skills-install-hooks`
  Install ggshield as a hook so secrets are caught before they leak. Covers git hooks (pre-commit and pre-push) that block secrets from entering git history, and AI-assistant hooks (claude-code, codex, copilot, cursor, vscode) that scan an AI coding tool's prompts, actions, and outputs in real time. Use when asked to install Claude Code, Cursor, Copilot, or git hooks, or to block secrets from being…
- [Scan Secrets](https://agentstack.voostack.com/l/skill-gitguardian-agent-skills-scan-secrets) — Skill · Free · security-reviewed — `agentstack add skill-gitguardian-agent-skills-scan-secrets`
  Use when scanning code, commits, git history, Docker images, or packages for hardcoded secrets, when editing credential-handling code, .env files, CI/CD workflows, Dockerfiles, or deployment scripts, or before committing or pushing.
- [Create Honeytokens](https://agentstack.voostack.com/l/skill-gitguardian-agent-skills-create-honeytokens) — Skill · Free · security-reviewed — `agentstack add skill-gitguardian-agent-skills-create-honeytokens`
  Use when generating or planting GitGuardian honeytokens, canary tokens, decoys, or tripwire credentials. Use around .env.example, sample configs, pre-publication open-source repos, internal wikis, runbooks, deploy scripts, or other attractive leak surfaces.

---
Seller on AgentStack — the marketplace for AI agent skills and MCP servers. Every listing is security-reviewed. Install any with `agentstack add <slug>`.
