All loops
Claude CodeEasy 6 min· claude-sonnet-4-5
Secret-in-code scanner
Pre-commit hook that asks Claude to confirm a regex match is really a secret.
Read the full Claude Code build guide →NOT DEPLOYEDNOT DEPLOYED
0191ms
Trigger
POST https://hooks.claudeloops.run/secret-in-code-scanner · event=linear.issue.updated
021031ms
Agent
claude-sonnet-4-5 · in 1531 tok · out 708 tok
03281ms
Tools
github-mcp/anthropic:messages.create → 200 OK · 291ms
0481ms
Verify
schema check · pydantic v2 passed
05171ms
Output
PR #182 opened · review comments added
0651ms
Notify
audit log written · runbook link attached
SUCCESS
0%
0 runs
P50
0ms
median
P95
0ms
tail
AVG COST
—
per run
LAST OK
never
—
LAST FAIL
never
none
Latency · last 30 runs0 samples
no runs yet
Latest output · what your users see
Openacme/api #1951
chore: bump @tanstack/react-router
6 files+71-121
- ✓ Ran full test suite → 218 passed, 0 failed (12.3s)
- ✓ Coverage delta: +0.4% on `src/lib/*`
- ✓ No breaking changes detected in public API
// press Test to run once · Watch live to keep streaming · Deploy to make it real
The problem
security,git
The outcome
Pure regex secret scanners cry wolf on every test fixture.
Ingredients & skills
Secrets
- ANTHROPIC_API_KEY
- GITHUB_TOKEN
Providers
- Anthropic
- GitHub
MCP servers
- github-mcp
#claude-code#github#automation
How it works
Pre-commit hook that asks Claude to confirm a regex match is really a secret.
Step 1
1 — Create the locker
Locker `secret-in-code-scanner` holds the GitHub token (repo scope) and the Anthropic key.
bash
locker create secret-in-code-scanner
locker set $_ ANTHROPIC_API_KEY=sk-ant-...
locker set $_ GITHUB_TOKEN=ghp_...Step 2
2 — Wire the GitHub event
Subscribe to the relevant GitHub webhook through the `github-mcp` server. Claude only sees the event payload and the files it requests.
Step 3
3 — Ship the agent
Single TS file in `agents/`. Stateless; the locker is bound at runtime so no env editing for new repos.
One-line deploy
The button above runs the same command with your saved config. This is the raw CLI form.
bash
npx claudeloops deploy secret-in-code-scanner https://hooks.claudeloops.run/secret-in-code-scanner
Related loops
Claude Code
PR review → risk-tagged comment
Claude Code reviews every PR and posts a risk-banded comment with suggested tests.
Claude Code
Test synthesizer for changed files
Claude Code writes Vitest + Playwright tests for every file touched in a PR.
Claude Code
Schema diff → migrations bot
Claude Code reads schema.prisma diffs, writes safe SQL with rollback notes.