DEV Community

Arthur031221
Arthur031221

Posted on

Your coding agent may have saved your API keys in plain text. Here is how to find and remove them

Coding agents read .env files as a matter of course, and the tools write what the agent saw to disk: prompt histories, session transcripts, local databases. An API key that passed through a session can stay there in plain text for months.

agentleaks scanning and redacting a throwaway fixture

Where the keys go

Coding agents read .env files as a matter of course. Every tool then stores what it saw in its own format. Claude Code writes JSONL files under ~/.claude/projects. Codex uses ~/.codex/sessions. Cursor keeps a SQLite database. Cline, Gemini CLI, OpenCode and Aider each keep their own copy. These files sit there for months, and folder sync and backups copy them around.

Nothing I found cleaned up what had already leaked, and nothing stopped the next agent from doing the same, so I wrote a tool for it.

What agentleaks does

It is a single Go binary with three commands.

scan walks the history of 13 tools and checks it against 64 rules. The output is a table with the provider, the tool, the file, the line or database record, and a masked preview of the key, so the report itself never prints a full secret.

agentleaks
Enter fullscreen mode Exit fullscreen mode

fix redacts the keys in place. The replacement text contains no quote or backslash, so a JSON string stays a JSON string, and every JSONL record is re-validated after rewriting. SQLite rows are updated in a transaction. The original file is copied to ~/.agentleaks/backups first, and the modification time is preserved so tools that sort sessions by time do not reshuffle.

agentleaks fix          # dry run
agentleaks fix --yes    # apply
Enter fullscreen mode Exit fullscreen mode

guard installs hooks into the agents' own config so the next read of .env or ~/.aws/credentials is refused.

agentleaks guard
Enter fullscreen mode Exit fullscreen mode

The demo above runs against a throwaway home directory with randomly generated fake keys, not real history.

Install

go install github.com/Arthur031221/agentleaks/cmd/agentleaks@latest
Enter fullscreen mode Exit fullscreen mode

Static binaries for macOS, Linux and Windows are attached to each release on GitHub. There are no runtime dependencies, and nothing leaves your machine unless you run the opt-in verify command.

What is rough

Guard coverage is uneven, because each tool's hook system exposes different events. It also does not scan git history, for which gitleaks and trufflehog are the right tools.

The code and the rule list are at https://github.com/Arthur031221/agentleaks. If you use a tool or a key format I do not cover yet, tell me and I will add a rule for it.

Top comments (0)