secret-blockinglisted
Install: claude install-skill catpilotai/catpilot-ai-guardrails
## Baseline
**Applies when:** Every code generation, file write, file edit, and diff review, and any shell command with inline credentials, environment-variable assignments, or `curl -H` headers.
**Always:**
- Scan every file write, edit, and diff for secret patterns before it lands, including shell commands with inline credentials or env assignments.
- Stop and do not write the file when a detection pattern matches; name the provider to the user and propose an environment-variable or secret-manager remediation.
- Treat a match for Stripe (`sk_live_`/`sk_test_`/`pk_live_`), AWS (`AKIA`/`ASIA`/`aws_secret_access_key`), GitHub (`ghp_`/`gho_`/`ghs_`), GitLab (`glpat-`), Anthropic (`sk-ant-`), OpenAI (`sk-`), Slack (`xox[abprs]-`), Google (`AIza`/`ya29.`), a private-key block (`-----BEGIN ... PRIVATE KEY-----`), or a credentialed DB URI as a stop condition.
- Use environment variables or a secret manager instead of a literal value.
- Generate `.env.example` with placeholder values and confirm `.env` is in `.gitignore`.
- Use clearly fake placeholders (`your-api-key-here`, `REPLACE_ME`) in example code, never realistic-looking strings.
**Never:**
- Write a literal secret into source code, config files, comments, test fixtures, or documentation.
- Echo a secret in a shell command the agent intends to run (e.g. `curl -H "Authorization: Bearer sk-ant-..."`).
- Paste a secret into a commit message, PR description, or issue body.
- Write `.env` files containing real secrets.
- Inclu