Find every API key you hardcoded. Fix it. Make sure it never happens again.
One link. Paste it to your AI. Done.
From inside your project, paste this into Claude Code, Cursor, Codex, Windsurf, Copilot, or whatever agent you use:
Read https://raw.githubusercontent.com/tensorboyalive/keys/main/AGENTS.md and run that audit on this project. Follow it exactly.
Your AI will:
- scan the working tree and every git commit for leaked secrets, using gitleaks, not vibes
- move each key to
.env, wire the code to read it, add.envto.gitignore, commit a.env.example - hand you a rotate list: a key that was ever committed is burned, deleting the line does not un-leak it
- flag keys shipped to the browser (
NEXT_PUBLIC_*,VITE_*,REACT_APP_*) and move them server-side - install a pre-commit hook and a GitHub Action so the next one gets blocked
- re-scan and show you zero findings
It never prints a secret's value into the chat, and never rewrites git history without asking you first.
git clone https://github.com/tensorboyalive/keys.git
cd your-project
sh ../keys/audit.shInstalls gitleaks if you don't have it (brew, go, or the release binary), scans tree + history, prints a redacted report.
| File | What it is |
|---|---|
AGENTS.md |
The playbook your AI follows. Six steps, hard rules, exact output format. |
audit.sh |
One-command scan for humans. A thin wrapper over gitleaks. |
.pre-commit-config.yaml |
Copy into your repo: blocks commits that contain secrets. |
.github/workflows/secrets.yml |
Copy into your repo: blocks pushes and PRs that contain secrets. |
gitignore.snippet |
The lines your .gitignore is missing. |
Attackers run AI agents over public code to harvest credentials at scale. Anthropic's own threat intelligence reports document Claude being used to hunt for exposed keys. If you vibe-coded an app and hardcoded a key, assume it has already been found. The bill arrives before the breach notice.
This repo does not reinvent the scanner. gitleaks and trufflehog are excellent. What was missing is the fix workflow written for an AI agent: find, report, move to env, rotate, guard, verify. That is AGENTS.md.
Found a pattern gitleaks misses, or a framework whose env loading isn't covered in Step 3? Open a PR against AGENTS.md. Keep it short; agents read this.
Made by TensorBoy · @tensor._.boy · MIT
0 comments
log in to comment.