This skill activates when the user mentions "extract secrets", "find credentials", "hardcoded passwords", "API keys", "embedded keys", "connection strings", "tokens", "secret scanning", "credential extraction", "extract crypto keys", "private keys", "certificate extraction", "config extraction", "encryption keys", "AES key", "RSA key", "HMAC secret", "JWT secret", "bearer token", "OAuth token", "AWS access key", "Azure key", "GCP key", "cloud credentials", "database password", "admin password", "default credentials", "service account", "FLOSS", "stack strings", "obfuscated strings", "decoded strings", "string analysis", "binary strings", "base64 decode", "hex decode", "XOR decode", "entropy analysis", "high entropy", "embedded certificate", "PEM key", "PKCS", "keystore", "wallet address", "crypto wallet", "bitcoin address", "ethereum address", "extract URLs", "extract IPs", "C2 addresses", "callback URLs", "exfiltration endpoints", "registry keys", "file paths", "UNC paths", "findcrypt", "signsrch", "crypto constants", "magic bytes", "binwalk extract", "firmware secrets", "PE resources secrets", "ELF sections", ".rodata secrets", "resource extraction", "anti-analysis bypass", "deobfuscate", "decrypt config", "decode payload", "RC4 decrypt", "XOR brute force", "string decryption routine", "unpacked strings", "credential harvesting from binary", "secret in binary", "sensitive data in executable", "password in firmware", "key material", "symmetric key", "asymmetric key", "initialization vector", "IV extraction", "salt extraction", "YARA crypto", "find secrets in malware", "credential dumping", "embedded config", "configuration block", "hardcoded URL", "API endpoint extraction", "Slack token", "GitHub token", "Stripe key", "SendGrid key", "Twilio key", "Firebase key", "Telegram bot token", "Discord token", "npm token", "PyPI token", "NuGet key", "Docker registry token", "Kubernetes secret", "HashiCorp Vault token", "Artifactory token", "LDAP password", "SMTP credentials", "S3 bucket credentials", "SAS token", "password hash", "NTLM hash", "shadow file", "passwd extraction", or discusses finding sensitive data, credentials, keys, or secrets in compiled binaries, firmware, or executables.
$npx -y skills add ogrodev/fsociety --skill secret-extractionInstalls into the current project.
Run `npx skills use "https://github.com/ogrodev/fsociety" --skill "ogrodev/fsociety/secret-extraction"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.
Use the skills in "https://github.com/ogrodev/fsociety" that are relevant to the current task. Run `npx skills add "https://github.com/ogrodev/fsociety"` and select the relevant skills, then follow their instructions.