Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.
-
Updated
Jul 19, 2026 - JavaScript
Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.
JSpider is a smart crawler for hidden endpoints. It crawls and extracts hidden API endpoints and URLs from JavaScript files and HTML source code - all directly in your browser.
Open-source, local-first privacy code scanner for PII leaks, hardcoded secrets, GDPR/CCPA compliance, SARIF, and CI/CD
Chrome extension that stops engineers from leaking API keys and secrets into ChatGPT, Cursor, and other AI tools. 100% local scanning.
Dual-agent AI code review for solo founders. Sends diffs to Claude + GPT, cross-checks findings, auto-detects secrets. CLI, GitHub Action, VS Code extension.
Safe-Paste is a developer-focused tool that ensures you never leak sensitive information when sharing code. It scans your pasted content for secrets, tokens, credentials, and confidential values, then redacts or replaces them with safe placeholders. Ideal for AI prompts, documentation, issue reports, and public chats.
A GitHub App that automatically scans pull requests for exposed secrets, high-entropy credentials, and known-vulnerable dependencies — posting findings directly as a PR review comment before code is merged.
Tiny security gate for CI/CD. Wraps Semgrep, Gitleaks, osv-scanner, Trivy, and npm audit. One command, one report, one exit code.
Local secrets firewall for coding agents — redacts credentials in prompts, file reads & tool output before they reach the LLM (Claude Code, Codex, OpenCode). No proxy, no npm, deterministic hooks.
your AI writes fast. leash-secrets makes sure it doesn't run away with your secrets. 71 patterns, 20+ agents.
Browser extension for detecting exposed API keys, tokens, and secrets in client-side storage. Scans localStorage, cookies, IndexedDB, WebSocket traffic, and more. 157 patterns. ML-powered. Zero dependencies.
MCP server providing security scanning, prompt injection detection, secret leak detection, and agent permission auditing for AI agent workflows
🛡️ AegisGate Lens v0.2.0 — privacy-first Chrome extension that detects PII, secrets, XSS, and compliance risks in prompts to 8 AI chat tools. 100% on-device regex detection (132 patterns, 4 facets). 0.14ms p99 latency (500 char prompts). Zero prompt data ever leaves your browser. Free, forever. Apache 2.0.
Fast local security checks before trusting, installing, or publishing automation.
🔍 Detect hardcoded tokens and secrets in JavaScript files to enhance your code security and prevent leaks efficiently.
GitHub Action for secretlint: scan PRs for leaked secrets & credentials in CI — zero config, fail on detection
Intentionally vulnerable demo target for evaluating secret-detection tools. All credentials are synthetic test data — auth-tested non-functional.
Add a description, image, and links to the secret-detection topic page so that developers can more easily learn about it.
To associate your repository with the secret-detection topic, visit your repo's landing page and select "manage topics."