Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.
-
Updated
Jul 19, 2026 - JavaScript
Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.
Runtime leak detector for modern web apps — finds exposed API keys, validates BaaS misconfigurations (Supabase/Firebase RLS), and catches secrets in JS bundles. Chrome extension + CLI.
Open-source cybersecurity analysis agent for Claude Code. Scans projects for vulnerabilities across all OWASP 2025 Top 10 and CWE Top 25 categories. 11 security domains, 60+ secret patterns, parallel subagent analysis, professional report generation. Built by tododeia.com
High-performance open-source security scanner combining SAST, SCA, Secret Detection, and IaC analysis, built for developers and CI/CD pipelines, using AI for recommendation!
Bug bounty focused JavaScript security analysis for crawling web assets, source maps, and secret discovery
AI agent firewall that intercepts tool calls (file, shell, network) and enforces deterministic policies at sub-microsecond latency using CEL, IFC, secret scanning, and audit logging.
🔍 Gitsint is a cutting-edge OSINT platform designed for security researchers, threat intelligence teams, and developers. Uncover hidden connections, detect exposed secrets, and map digital footprints across GitHub's vast ecosystem.
Argus brings “a hundred eyes” to your project, combining leading open source security tools into a scalable, automated, continuous security pipeline.
High-precision secret scanner for code, tickets, logs, and web app with ml validation
Burp Suite extension for passive JS reconnaissance - detects 1,600+ secret patterns, API keys, endpoints, and security misconfigurations in HTTP responses in real-time.
A developer CLI tool that manages .env files, detects secret leaks, syncs env drift across teammates, and validates environment parity between local/staging/prod all from your terminal. Written in Go.
Local security proxy that keeps secrets and sensitive data out of AI requests. Supports Codex, Claude Code and more.
JSpider is a smart crawler for hidden endpoints. It crawls and extracts hidden API endpoints and URLs from JavaScript files and HTML source code - all directly in your browser.
Tool-neutral attack corpus for AI agent egress security
A powerful and lightweight tool for bug bounty hunters and security researchers to identify hardcoded secrets, API keys, tokens, credentials, and other sensitive data in code repositories, web applications, and configuration files.
Stop API keys and passwords leaking into AI tools. Offline secret detection and redaction for VSCode, Cursor, Windsurf, and Claude Code.
ALNUR — Open-source end-to-end security vulnerability scanner. Detects CVEs, hardcoded secrets, architecture flaws, and port risks across Node.js, Python, PHP, Go, Rust, Java, .NET, Ruby and more
A curated list of tools for credential discovery.
Some useful functionality to detect secrets
Automatically redacts sensitive data in screenshots before sending to AI agents
Add a description, image, and links to the secret-detection topic page so that developers can more easily learn about it.
To associate your repository with the secret-detection topic, visit your repo's landing page and select "manage topics."