{"actions":{"bootstrapAndRun":{"effect":"installs rote if missing, inspects, prepares, and asks before running","href":"https://play.modiqo.ai/install?play=dotisacat/shell-history-leak-scan@0.1.0","method":"GET","rel":"https://rote.dev/rels/bootstrap-and-run","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"inspect":{"command":"rote play inspect https://play.modiqo.ai/dotisacat/shell-history-leak-scan@0.1.0","effect":"read-only"},"installCliOnly":{"effect":"installs the rote CLI, nothing else","href":"https://play.modiqo.ai/install","method":"GET","rel":"https://rote.dev/rels/install-cli","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"run":{"command":"rote play run https://play.modiqo.ai/dotisacat/shell-history-leak-scan@0.1.0","effect":"executes the play locally after consent","headless":{"approvalAssertion":"--yes","approvalRequiredBeforeInvocation":true,"commandTemplate":"rote play run https://play.modiqo.ai/dotisacat/shell-history-leak-scan@0.1.0 <name=value...> --yes","stdinPolicy":"never pipe input to automate the interactive Ready selector"},"requiresConsent":true}},"description":"A git-history scanner reads what got committed. It never reads what got TYPED: an export/curl/psql/python invocation carrying a raw credential at a shell prompt lands in ~/.zsh_history, ~/.bash_history, ~/.local/share/fish/fish_history, ~/.python_history, or ~/.psql_history instead -- files no commit-scanner ever opens. himanshu-jha's git-history-secret-scan covers commits; this covers the shell. Five jobs: locate_histories stats all five known files -- present or not, readable or not -- every one reported on by name, never silently skipped, and never opening or reading a single one; scan streams every located, readable file line by line -- a multi-gigabyte history is never loaded whole -- parsing zsh's EXTENDED_HISTORY \u0060: <ts>:<elapsed>;cmd\u0060 framing and its backslash line-continuation so a multi-line paste reads as the one logical entry it was, plus fish's \u0060- cmd: ...\u0060 block form, and never treating a \u0060#\u0060-led comment line (however common a typed \"remember to rotate the api key\" aside is) as a command; it cla","distribution":{"digest":"sha256:6979379a723e48198c315b5e4323ebe7d0c65525860d5f588b86e540c96bbf03","mediaType":"application/vnd.modiqo.rote-flow","size":32391,"verifiedBy":"rote verifies the downloaded archive against this digest before it runs"},"effects":{"credentialsProvidedBy":"runner","credentialsRemainLocal":true,"declaredWrites":[],"publisherReceivesCredentials":false},"id":"https://play.modiqo.ai/dotisacat/shell-history-leak-scan@0.1.0","inputPolicy":{"optionalWithDefault":"show_default_and_accept_override","optionalWithoutDefault":"omit_unless_supplied","required":"ask","secrets":"collect_locally_outside_conversation"},"links":{"docs":"https://rote.dev","page":"https://play.modiqo.ai/dotisacat/shell-history-leak-scan@0.1.0","protocol":"https://play.modiqo.ai/.well-known/rote","self":"https://play.modiqo.ai/dotisacat/shell-history-leak-scan@0.1.0.json"},"name":"shell-history-leak-scan","owner":{"kind":"user","slug":"dotisacat"},"parameters":[{"default":50,"description":"Maximum number of findings to list individually (1-500), the rest summarized as a count","example":50,"input":{"allowCustom":true,"choices":[],"label":"Max findings"},"name":"max_findings","required":false,"type":"integer"}],"preparation":[{"action":{"command":"rote play inspect https://play.modiqo.ai/dotisacat/shell-history-leak-scan@0.1.0 --json","effect":"read-only"},"step":1,"type":"inspect_local_readiness"},{"references":["/parameters"],"step":2,"type":"collect_parameters"},{"references":["/parameters","/requirements","/effects"],"step":3,"type":"review"},{"consentBoundary":"the user approves the exact play and parameter values","references":["/parameters","/requirements","/effects"],"step":4,"type":"obtain_run_consent"},{"action":{"command":"rote play run https://play.modiqo.ai/dotisacat/shell-history-leak-scan@0.1.0","headlessCommandTemplate":"rote play run https://play.modiqo.ai/dotisacat/shell-history-leak-scan@0.1.0 <name=value...> --yes"},"preservesAcquisitionBoundaries":["adapter_selection","oauth_dcr","google_discovery","static_token_setup","runtime_security_checks"],"requiresConsent":true,"step":5,"type":"run"}],"producedBy":{"roteVersion":"0.77.0"},"publishedAt":"2026-09-02T21:19:07.009056+00:00","reference":"dotisacat/shell-history-leak-scan@0.1.0","requirements":{"adapters":[],"browser":{"dependencies":[],"runtime":false,"signIn":false},"localTools":["python3"],"roteCli":{"minimumVersion":"0.62.0"},"sessions":false},"resolution":"pinned","schema":"rote.play.v1","stats":{"downloads":2,"installs":0},"steps":{"count":2,"names":["locate_histories","scan"]},"title":"shell-history-leak-scan","type":"play","version":"0.1.0","visibility":"public"}