Skip to content
TensorboyalivePublic

About

Find the API keys you left in your code. Fix them. Never again. One link, paste it to your AI.

Resources

Stars

1 star

Watchers

0 watching

Forks

Repository files navigation

KEYS: find the API keys you left in your code. fix them. never again.

Find every API key you hardcoded. Fix it. Make sure it never happens again.
One link. Paste it to your AI. Done.

The 30-second version

From inside your project, paste this into Claude Code, Cursor, Codex, Windsurf, Copilot, or whatever agent you use:

Read https://raw.githubusercontent.com/tensorboyalive/keys/main/AGENTS.md and run that audit on this project. Follow it exactly.

Your AI will:

  1. scan the working tree and every git commit for leaked secrets, using gitleaks, not vibes
  2. move each key to .env, wire the code to read it, add .env to .gitignore, commit a .env.example
  3. hand you a rotate list: a key that was ever committed is burned, deleting the line does not un-leak it
  4. flag keys shipped to the browser (NEXT_PUBLIC_*, VITE_*, REACT_APP_*) and move them server-side
  5. install a pre-commit hook and a GitHub Action so the next one gets blocked
  6. re-scan and show you zero findings

It never prints a secret's value into the chat, and never rewrites git history without asking you first.

No AI? Run it yourself

git clone https://github.com/tensorboyalive/keys.git
cd your-project
sh ../keys/audit.sh

Installs gitleaks if you don't have it (brew, go, or the release binary), scans tree + history, prints a redacted report.

What's in here

File What it is
AGENTS.md The playbook your AI follows. Six steps, hard rules, exact output format.
audit.sh One-command scan for humans. A thin wrapper over gitleaks.
.pre-commit-config.yaml Copy into your repo: blocks commits that contain secrets.
.github/workflows/secrets.yml Copy into your repo: blocks pushes and PRs that contain secrets.
gitignore.snippet The lines your .gitignore is missing.

Why this exists

Attackers run AI agents over public code to harvest credentials at scale. Anthropic's own threat intelligence reports document Claude being used to hunt for exposed keys. If you vibe-coded an app and hardcoded a key, assume it has already been found. The bill arrives before the breach notice.

This repo does not reinvent the scanner. gitleaks and trufflehog are excellent. What was missing is the fix workflow written for an AI agent: find, report, move to env, rotate, guard, verify. That is AGENTS.md.

Contributing

Found a pattern gitleaks misses, or a framework whose env loading isn't covered in Step 3? Open a PR against AGENTS.md. Keep it short; agents read this.


Made by TensorBoy · @tensor._.boy · MIT

About

Find the API keys you left in your code. Fix them. Never again. One link, paste it to your AI.

Resources

Stars

1 star

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages