exposure-discovery

Identify leaked credentials and secrets in public breach datasets and repositories.

6|Updated May 30, 2026
One-click install
npx skills add https://github.com/jassics/awesome-claude-security --skill exposure-discovery
Or copy as Structured Prompt for Agent▼
Please help me install this Agent Skill.
Skill: exposure-discovery
Source: https://github.com/jassics/awesome-claude-security/tree/main/plugins/osint/skills/exposure-discovery
Command: npx skills add https://github.com/jassics/awesome-claude-security --skill exposure-discovery

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes scripts (resource) and references (resource) components.

What problem does it solve?

The exposure-discovery Skill helps you find and respond to data breaches and leaks that are publicly available, thereby reducing the risk of exploitation or misuse.

Core Features & Use Cases

  • Identify Leaked Credentials: Detect corporate emails, passwords, and API keys in breach datasets.
  • Find Code-Secrets: Scan for secrets and credentials in public repositories, gists, and artifacts.
  • Exposure Analysis: Discover exposed services, storage, and documents that could be targeted by attackers.
  • Quick Response: Recommend immediate actions to mitigate the effects of identified breaches.

Quick Start

To scan for public data leaks related to your organization, use the 'exposure-discovery' skill.

Frequently Asked Questions about exposure-discovery

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I find leaked credentials and public data breaches for my organization?▼

You can identify leaked credentials by scanning publicly accessible sources, code search engines, and passive scan datasets to catalog exposed corporate emails, passwords, and API keys for your organization.

What is exposure assessment for public data leaks?▼

Exposure assessment for public data leaks is the process of discovering and cataloging exposed services, storage, and documents from publicly accessible sources. It provides actionable intelligence to mitigate risks and protect against exploitation within authorized scopes.

How do I scan public repositories for exposed secrets and API keys?▼

You scan public repositories by utilizing publicly available code search engines to detect secrets, credentials, and API keys in public gists and artifacts. This identifies valid, current leaks before any remediation actions are taken.

Can I use this for breach detection across publicly accessible sources without authentication?▼

Yes, you can use this for breach detection across publicly accessible sources without authentication. It operates within defined authorized scopes to passively catalog data risks before any authentication or remediation actions are initiated.

What is the best way to respond to discovered data breaches and leaks?▼

The best way to respond to discovered data breaches is to recommend immediate actions that mitigate the effects of the identified exposures. This ensures all actions are authorized before any authentication or remediation steps are executed.