# Monitor exposed secrets in GitHub and CI logs with WhatsApp alerts

> Quick overview This workflow runs every 6 hours (or on demand) to scan GitHub commits and CI/CD logs for leaked secrets, verify suspected credentials against GitHub and Stripe when possible, score risk severity, and send WhatsApp alerts with a remediation confirmation and re-verification loop. How it works 1. Runs on a 6-hour schedule or via a manual trigger and loads configuration values like GitHub repo details, CI log URL, and WhatsApp recipients. 2. Fetches the most recent commit list from the configured GitHub repository and then pulls CI/CD pipeline logs from the configured CI API endpoint. 3. Scans the collected text for common secret patterns (for example AWS keys, GitHub tokens, Stripe keys, and high-entropy strings), masks matches, deduplicates findings, and emits one item per suspected secret. 4. Routes each finding by category to verify validity using provider API calls (GitHub /user and Stripe /v1/account) or marks generic high-entropy matches as unverifiable for manual re

- **Domain**: `n8n-workflow-18452.n8n.io`
- **Provider**: n8n.io (https://n8n.io)
- **Kind**: workflow
- **Live-responds (last probe)**: None
- **Signed card**: False
- **Streaming**: False
- **Quality score**: 40%

## URLs
- Agent card: https://n8n.io/workflows/18452
- Page (HTML): https://agenstry.com/agents/n8n-workflow-18452.n8n.io
- Documentation: https://n8n.io/workflows/18452
