Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.
-
Updated
Apr 14, 2026 - JavaScript
Passive API key and secret discovery browser extension for Chrome and Firefox. 80+ detection patterns, zero config.
Open-source cybersecurity analysis agent for Claude Code. Scans projects for vulnerabilities across all OWASP 2025 Top 10 and CWE Top 25 categories. 11 security domains, 60+ secret patterns, parallel subagent analysis, professional report generation. Built by tododeia.com
High-performance open-source security scanner combining SAST, SCA, Secret Detection, and IaC analysis, built for developers and CI/CD pipelines.
High-performance repository context generator for LLMs - Transform codebases into optimized formats for Claude, GPT-4/5, Gemini, and other LLMs
🔍 Gitsint is a cutting-edge OSINT platform designed for security researchers, threat intelligence teams, and developers. Uncover hidden connections, detect exposed secrets, and map digital footprints across GitHub's vast ecosystem.
Burp Suite extension for passive JS reconnaissance - detects 1,600+ secret patterns, API keys, endpoints, and security misconfigurations in HTTP responses in real-time.
Argus brings “a hundred eyes” to your project, combining leading open source security tools into a scalable, automated, continuous security pipeline.
JSpider is a smart crawler for hidden endpoints. It crawls and extracts hidden API endpoints and URLs from JavaScript files and HTML source code - all directly in your browser.
Some useful functionality to detect secrets
Automatically redacts sensitive data in screenshots before sending to AI agents
Fast Python static analysis powered by Rust. Detects dead code, security issues (including taint analysis), and code quality metrics like complexity, Halstead, maintainability, and nesting depth.
Free security scanner for AI-generated code. SAST + secret detection on every PR. 24-line YAML, 30-second setup. Built for vibe coding.
Security and cleanup toolkit for Claude Code. Auto secret detection, 99.4% config reduction. CLI & MCP Server.
Security Command Center for Model Context Protocol (MCP) servers. Detect prompt injection, tool poisoning, secrets, and vulnerabilities. The Trivy of MCP security.
Local MITM proxy that keeps secrets out of LLM traffic.
🔒 Security scanner for AI Skills | Detect dangerous commands, prompt injection, secrets, and suspicious patterns before install
Detects and obfuscates sensitive data before it reaches AI systems — clipboard, CLI, and MCP server
Secrets scanner with pattern matching, entropy analysis, and live validation
Git secrets, vulnurabilities scanner with rich reporting
A curated list of tools for credential discovery.
Add a description, image, and links to the secret-detection topic page so that developers can more easily learn about it.
To associate your repository with the secret-detection topic, visit your repo's landing page and select "manage topics."