Secretly: An Open-Source Slack Bot That Stops Secrets Leaking in Real Time
Secretly is a free open-source Slack bot that detects and masks API keys, database credentials, and private tokens in real time before they leak.
Slack is where your team lives — and increasingly, where your secrets leak. An engineer pastes a database connection string to ask a quick question. Someone shares an AWS key to help a colleague debug. A bot posts a config snippet that includes an API token. By the time anyone notices, that secret has been seen by dozens of people, logged in Slack's message history, and potentially indexed by integrations you forgot you had. Secretly is an open-source Slack bot built to stop this before it happens.
The Problem: Slack as an Unintentional Secret Store
Most secret scanning tools focus on Git — and for good reason. But Git is only one of the places secrets end up. In practice, Slack is where engineers communicate about their work, and that means secrets flow through it constantly. Someone asks why a staging deployment is failing and pastes the full environment config. A contractor is onboarded and needs a database URL. A production incident is triaged and credentials get shared in the heat of the moment.
None of these are malicious. All of them are risks. And unlike a Git commit, a Slack message does not have an obvious remediation path — there is no git rebase -i to rewrite history. The message has been delivered, and if your workspace has integrations like Zapier, Notion, Jira, or analytics tools, it may already have been exported.
This is the gap Secretly fills.
What Secretly Does
Secretly monitors Slack messages in real time and automatically obfuscates sensitive information the moment it appears. When a message containing a secret is detected, Secretly replaces it with a masked version before other users can read it. Authorized users can restore the original content if it was a false positive. Every action is logged to a full audit trail.
Detection covers: credit card numbers (validated with Luhn algorithm to reduce false positives), Social Security Numbers, API keys and tokens from AWS, GitHub, Slack, and other providers, plaintext passwords, database connection strings, private keys, email addresses, phone numbers, IP addresses, and high-entropy strings that pattern-match as potential secrets. Sensitivity is configurable per channel — you can run stricter detection in public channels while relaxing it in dedicated ops channels where engineers legitimately share credential rotation procedures.
Architecture
Secretly is built in TypeScript on Node.js 18+, backed by PostgreSQL for audit logging and Redis for rate limiting and caching. It uses the Slack Bolt SDK for real-time event handling, Winston for structured logging, and ships with both Docker Compose and a production-hardened Helm chart for Kubernetes.
The bot subscribes to Slack message events and processes them through a detection pipeline before they are seen by other workspace members. Required OAuth scopes: channels:history, channels:read, chat:write, chat:write.public, commands, and reactions:write.
Getting Started
Prerequisites
Node.js 18+, npm, a PostgreSQL database, a Redis server, and a Slack workspace where you have admin access to install apps.
Clone and Install
git clone https://github.com/colibrisec/secretly.git
cd secretly
npm install
cp .env.example .envSlack App Setup
Create a new Slack app at api.slack.com/apps. Under OAuth & Permissions, add the Bot Token Scopes listed above. Enable Event Subscriptions and subscribe to message.channels and message.groups events. Copy the Bot Token, App Token, and Signing Secret to your .env file.
Environment Variables
SLACK_BOT_TOKEN=xoxb-your-token
SLACK_APP_TOKEN=xapp-your-token
SLACK_SIGNING_SECRET=your-secret
DATABASE_URL=postgresql://user:pass@host:5432/secretly?ssl=true
REDIS_URL=redis://user:pass@host:6379
ENCRYPTION_KEY=your-32-character-minimum-keyRun Locally
npm run devProduction Deployment
Docker Compose
# Production stack
docker compose -f docker-compose.prod.yml up -d
# Or build manually
docker build -t secretly .
docker run -d --env-file .env secretlyKubernetes with Helm
The included Helm chart ships with comprehensive security hardening — non-root containers, read-only root filesystem, dropped Linux capabilities, and resource limits. Deploy with:
helm install secretly ./helm/secretly \
--set slack.botToken=xoxb-your-token \
--set slack.appToken=xapp-your-token \
--set slack.signingSecret=your-secret \
--set database.url=postgresql://user:pass@host:5432/secretly \
--set redis.url=redis://host:6379 \
--set encryption.key=your-32-char-keyMonitoring and Audit Trail
Secretly uses Winston for structured logging across all components. The monitoring stack covers rate limit tracking, database health checks, and a full audit trail for every detection event and remediation action — what was detected, when, in which channel, and what action was taken. This is essential for any compliance or incident review process.
The Supply Chain Connection
If you have read our breakdown of the TeamPCP supply chain campaign, you will recognize the pattern. The Trivy compromise succeeded in part because CI/CD pipelines ran with broad secret access and no monitoring. But secrets do not only flow through pipelines — they flow through the communication channels engineers use to build and operate those pipelines. A leaked AWS key shared in Slack to debug a failing workflow is just as dangerous as one committed to a repository.
Secretly is the Slack-layer complement to Git-layer secret scanning and the SBOM-based supply chain monitoring we covered in the Dependency-Track post. Neither tool alone closes the full picture — together they address the two most common paths through which secrets escape the environments they are supposed to stay in.
Contributing
Secretly is GPLv3 licensed and open to contributions. The repository is at github.com/colibrisec/secretly — fork it, create a feature branch, add tests, and submit a pull request. Issues and questions go through GitHub Issues.