Protect your secrets using Gitleaks-Action
-
Updated
Jul 21, 2026 - JavaScript
Protect your secrets using Gitleaks-Action
collectvars collects JavaScript variables, highlights risky ones, and helps you understand code structure, while you casually browse.
A community-led project that aims to scan published Repls to find secrets and invalidate them.
Free security & privacy scanner for AI-coded apps. 699 rules, 76 MCP tools, 13-layer defense, zero-trust sandbox, AI firewall. Runs locally, never sends data anywhere. Scan your AI-generated app for leaked keys, open databases, and injection holes in 5 seconds.
CLI tool to transform verbose noseyparker JSON reports into concise JSON or CSV summaries for security analysis
Open-source, local-first privacy code scanner for PII leaks, hardcoded secrets, GDPR/CCPA compliance, SARIF, and CI/CD
Pre-push Git safety CLI for AI-assisted coding: catch risky changes, possible secrets, weak PR readiness, and branch strategy issues before review.
Scan your entire git history for committed secrets & API keys — zero deps, 10 pattern classes, BFG remediation advice. MIT.
Kill-tested guard skills for AI coding agents , self-invoking quality gates that catch AI failure modes in security, tests, docs, dependencies, and diffs before the agent says "done." Works with Claude Code, Codex, and Cursor.
Find and redact secrets, API keys, and PII in a log or prompt before you paste it into an AI. Runs entirely in your browser, nothing is uploaded.
Environment variable validation, security scanning & documentation generator
Package a codebase into an LLM-optimized context bundle — per-model token budgeting + automatic secret redaction. Zero-dependency CLI.
your AI writes fast. leash-secrets makes sure it doesn't run away with your secrets. 71 patterns, 20+ agents.
Cut your GitHub Copilot token bill, locally. Certance Field compresses oversized context before it reaches the model, redacts and scans for secrets, and exports audit evidence. No cloud, no external calls.
Vuln Report Kit is a local-first Obsidian plugin for vulnerability research notes, responsible disclosure reports, secret scanning, sanitized public exports, templates, dashboards and case backups.
Secret scanner that detects and prevents API key leaks in Pull Requests with actionable PR comments and optional local blocking.
Local-first git pre-push hook that blocks committed secrets, tracked .env files, force-push blast radius & risky GitHub Actions. Zero dependencies, nothing leaves your machine.
GitHub Action wrapper for agent-secret-guard, an AI agent and MCP secret scanner.
Zero-dependency CLI that scans your code for leaked secrets (API keys, tokens, private keys, committed .env) — with a clean, colorful terminal UI.
🐕 Hunt leaked Shodan API keys across public GitHub and validate them live — zero-dependency Node.js.
Add a description, image, and links to the secret-scanning topic page so that developers can more easily learn about it.
To associate your repository with the secret-scanning topic, visit your repo's landing page and select "manage topics."