A Python CLI tool that scans all repositories owned by a GitHub user/org for accidentally committed secrets (API keys, tokens, passwords, private keys, etc.).
-
Updated
May 3, 2026 - Python
A Python CLI tool that scans all repositories owned by a GitHub user/org for accidentally committed secrets (API keys, tokens, passwords, private keys, etc.).
Secrets scanner with a twist... this is for getting threat actor credentials from MALWARE. Acquire TA creds from FLOSS exports, memdumps, Binja exports, etc. to get C2 credentials, embedded API keys, crypto material, or hardcoded passwords.
convert secret patterns to gf compatible.
ReleaseGuard is an open-source artifact policy engine and hardening suite. It scans, transforms, obfuscates, attests, and verifies release artifacts before they ship across every build ecosystem.
This GitHub Action allows you to run Gitleaks in your GitHub workflow.
Credential Scanner for Popular Desktop AI Platforms
The Clutch VS code extension allows any user to scan for secrets in his/hers open workspace automatically within the IDE
Deterministic pre-push verification for AI-assisted codebases: AST mutation testing, credential scanning, sandbox-escape detection, mock-usage alerts, and dependency hallucination defense.
A sarcastic list of secret scanners
A secret scanner wrapper to aggregate results across multiple secret scanning tools
The guardian of your Pull Requests. She decides what gets to merge.
GitHub Action that wraps Yelp/detect-secrets and provides an enterprise friendly way of detecting and preventing secrets in code.
A blazing fast secret-hunting tool for bug bounty hunters and security enthusiasts.
An ongoing & curated collection of awesome software best practices and techniques, libraries and frameworks, E-books and videos, websites, blog posts, links to github Repositories, technical guidelines and important resources about Secrets Management Process in Cybersecurity.
SecretKeeper is a tool for detecting secrets and misconfigurations on your Git repositories (Bitbucket and GitHub).
noLeak, scans your entire Git history, identifies potential leaks (API keys, tokens, etc.), and provides an interactive wizard to permanently purge them from your repository.
Security linter for environment variables, Docker, CI, Kubernetes, and runtime configuration.
Autonomous secrets scanner — detects exposed API keys, dangerous file permissions and npm vulnerabilities in your project tree. Read-only. Zero dependencies.
Tiny byte-level AI on CPU: zero-dependency C++20 inference engine and neural decision models (2.8ms latency, 9.4MB RAM). Replaces tokenizers with a 256-byte vocabulary. Flagship specialists for pre-commit secret scanning (0.797 F1 vs 0.337 GitLeaks) and PII redaction. Apache 2.0.
🔍 Scan MCP (Model Context Protocol) configs for hardcoded secrets, leaked API keys, and security misconfigurations
To associate your repository with the secrets-scanner topic, visit your repo's landing page and select "manage topics."