Skip to main content
{ Vulnerability Management / Application Security }

Bitbucket Repository Secrets Triage

Scans a Bitbucket repository for hardcoded secrets and separates the real, exposed credentials from placeholders, test values, and safely loaded config.

What this agent does

This read-only agent scans a Bitbucket repository for API keys, tokens, passwords, private keys, and other credentials. It checks each match against the surrounding code to decide whether it is a real secret, whether it is hardcoded, and whether it ships in production code. It rates each confirmed secret by what it grants access to and how exposed it is. It never prints or tests a secret.

The challenge

Secret scanners match patterns, so they flag example keys, test fixtures, and placeholder values alongside real credentials. After enough fake matches, engineers stop reading the scanner's results. They miss the one real credential in that list and leave it in the code, and often in the git history, until someone abuses it.

The solution

The agent reads the code around every match the way an engineer would. It filters out placeholders, values loaded from the environment or a secrets manager, and test-only files, and it gives the reason for each. It checks whether a confirmed secret is tracked in git, present in history, logged, or sent to the client. Provides a short list of real secrets to rotate, each with its location and the steps to fix it.

Workflow

  1. 01

    Scan

    Scan every file in the repository for secret patterns, and record each match with its value redacted.

  2. 02

    Check each match

    Decide whether the match is a real secret, hardcoded rather than loaded, and in production code.

  3. 03

    Check exposure

    Check whether each confirmed secret is tracked in git, in its history, logged, or sent to the client.

  4. 04

    Report

    List confirmed secrets by severity with remediation steps, then the filtered matches and why.

Agent template

# Bitbucket Repository Secrets Triage

## Measurable outcomes

Every secret match in the repository is either confirmed as a real, exposed credential or filtered with a reason. Every confirmed secret has a severity and remediation steps. Track the candidate, confirmed, and filtered counts on every run.

## Procedure

For a given repository, scan every file with [Poltergeist](https://github.com/ghostsecurity/poltergeist), Ghost's open source secret scanner, and use the [ghost-scan-secrets](https://github.com/ghostsecurity/skills/tree/main/plugins/ghost/skills/scan-secrets) skill in the [Ghost skills repository](https://github.com/ghostsecurity/skills) as a working reference. Look for cloud credentials, database passwords and connection strings, private keys, API keys, OAuth tokens, and generic passwords. Record each match with its value redacted. Never print, store, or test a full secret value. For each match, read the code around it. Filter it out when it is a placeholder or an obvious example value, when it is loaded from an environment variable, an ignored config file, or a secrets manager, or when it only appears in tests, fixtures, examples, or documentation. Give the reason for every filtered match. Confirm a match only when it is a real value, hardcoded, and in production code. For each confirmed secret, check whether the file is tracked in git, whether the value appears in git history, and whether the code logs it or sends it to the client. Rate cloud credentials, database credentials, private keys, production API keys, and OAuth tokens as high, generic passwords as medium, and internal development tokens as low. Raise the rating when the secret is exposed or the repository handles sensitive data. For each confirmed secret, recommend rotating it, moving it to a secrets manager, removing it from git history, and checking the service's access logs for misuse. Put confirmed secrets at the top of the report, ordered by severity.

## Requirements

It needs Bitbucket read access to the repository and its history, and nothing more. It never changes the repository, rotates a secret, or uses a secret to call a service.