inblog logo
|
ShipSafeScan Blog: Security for AI-coded apps

    How to check your GitHub repo for leaked secrets (free)

    Scan a public GitHub repo for leaked API keys and secrets, free. Paste your repo URL into ShipSafe for a security score in about 30 seconds, or run gitleaks.
    ShipSafeScan Team's avatar
    ShipSafeScan Team
    Aug 23, 2026
    How to check your GitHub repo for leaked secrets (free)
    Contents
    Why this matters for AI-coded appsWhat counts as a "leaked secret"Three ways to check your repoWhat to do if you find oneThe takeaway

    To check a public GitHub repository for leaked secrets, scan it for hardcoded API keys, tokens, and credentials with a secret scanner. The fastest free way is to paste your repository URL into ShipSafe, which reads the repo and reports any exposed secrets along with a security score. You can also run open-source tools like gitleaks locally.

    Why this matters for AI-coded apps

    When you build fast with AI coding tools, it is easy to commit a .env file or paste a real API key into the code "just to test it," and then forget. Once that is pushed to a public repo, anyone can find it.

    This is not a rare edge case. In its 2025 GenAI Code Security Report, Veracode found that about 45% of AI-generated code samples introduced a known security weakness. Leaked credentials are one of the most damaging, because an exposed key can be abused immediately.

    What counts as a "leaked secret"

    • Cloud keys (for example, AWS access keys)

    • API keys and tokens (Stripe, OpenAI, GitHub, Slack, and others)

    • Private keys (PEM blocks)

    • Passwords or connection strings hardcoded in source

    • A committed .env file that was meant to stay local

    Three ways to check your repo

    1. Scan it with ShipSafe (free, no install)

    Paste a public GitHub repo URL into ShipSafe. It reads the repository, checks for exposed secrets, risky patterns, dependency and quality signals, and returns a score with an issue report in about 30 seconds. Detected secrets are masked, and your source code is not stored.

    What it does not cover: ShipSafe works on public repos only, and it reads the current state of your default branch through the GitHub API rather than your full commit history. It is a fast first pass, so use option 2 when you need history or a private repo.

    1. Run gitleaks locally

    gitleaks is a popular open-source scanner. Install it and run gitleaks detect in your project to find secrets in your working tree and history.
    It needs a local install, but it covers private repos and your full commit history, and it can run in CI on every push.

    1. Turn on GitHub secret scanning

    GitHub offers secret scanning that alerts you when known secret formats are pushed. It is a good backstop, though coverage depends on the secret type.

    What to do if you find one

    1. Treat the secret as compromised and rotate it immediately (issue a new key, revoke the old one).

    2. Remove it from the code and load it from an environment variable instead.

    3. Add a .env.example (without real values) so setup is documented.

    4. Remember that deleting the line is not enough if it is already in git history, so rotate the key regardless.

    The takeaway

    AI can write a lot of code quickly, and that is a good thing. The habit worth adding is a quick security check before you ship, so a forgotten key does not become an incident.

    Vibe code fast, ship safe.

    Share article
    Contents
    Why this matters for AI-coded appsWhat counts as a "leaked secret"Three ways to check your repoWhat to do if you find oneThe takeaway

    ShipSafeScan Blog: Security for AI-coded apps

    RSSยทPowered by Inblog