How to check your GitHub repo for leaked secrets (free)

To check a public GitHub repository for leaked secrets, scan it for hardcoded API keys, tokens, and credentials with a secret scanner. The fastest free way is to paste your repository URL into ShipSafe, which reads the repo and reports any exposed secrets along with a security score. You can also run open-source tools like gitleaks locally.
Why this matters for AI-coded apps
When you build fast with AI coding tools, it is easy to commit a .env file or paste a real API key into the code "just to test it," and then forget. Once that is pushed to a public repo, anyone can find it.
This is not a rare edge case. In its 2025 GenAI Code Security Report, Veracode found that about 45% of AI-generated code samples introduced a known security weakness. Leaked credentials are one of the most damaging, because an exposed key can be abused immediately.
What counts as a "leaked secret"
Cloud keys (for example, AWS access keys)
API keys and tokens (Stripe, OpenAI, GitHub, Slack, and others)
Private keys (PEM blocks)
Passwords or connection strings hardcoded in source
A committed
.envfile that was meant to stay local
Three ways to check your repo
Scan it with ShipSafe (free, no install)
Paste a public GitHub repo URL into ShipSafe. It reads the repository, checks for exposed secrets, risky patterns, dependency and quality signals, and returns a score with an issue report in about 30 seconds. Detected secrets are masked, and your source code is not stored.
What it does not cover: ShipSafe works on public repos only, and it reads the current state of your default branch through the GitHub API rather than your full commit history. It is a fast first pass, so use option 2 when you need history or a private repo.
Run gitleaks locally
gitleaks is a popular open-source scanner. Install it and run gitleaks detect in your project to find secrets in your working tree and history.
It needs a local install, but it covers private repos and your full commit history, and it can run in CI on every push.
Turn on GitHub secret scanning
GitHub offers secret scanning that alerts you when known secret formats are pushed. It is a good backstop, though coverage depends on the secret type.
What to do if you find one
Treat the secret as compromised and rotate it immediately (issue a new key, revoke the old one).
Remove it from the code and load it from an environment variable instead.
Add a
.env.example(without real values) so setup is documented.Remember that deleting the line is not enough if it is already in git history, so rotate the key regardless.
The takeaway
AI can write a lot of code quickly, and that is a good thing. The habit worth adding is a quick security check before you ship, so a forgotten key does not become an incident.
Vibe code fast, ship safe.