<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: BloodAndCode</title>
    <description>The latest articles on DEV Community by BloodAndCode (@bloodandcode).</description>
    <link>https://dev.to/bloodandcode</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3817471%2F2e1d3d89-5be5-4445-b9bc-cf23c484f650.png</url>
      <title>DEV Community: BloodAndCode</title>
      <link>https://dev.to/bloodandcode</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/bloodandcode"/>
    <language>en</language>
    <item>
      <title>I almost leaked an API key into ChatGPT, so I built a Chrome extension</title>
      <dc:creator>BloodAndCode</dc:creator>
      <pubDate>Tue, 10 Mar 2026 20:36:13 +0000</pubDate>
      <link>https://dev.to/bloodandcode/i-almost-leaked-an-api-key-into-chatgpt-so-i-built-a-chrome-extension-1mhm</link>
      <guid>https://dev.to/bloodandcode/i-almost-leaked-an-api-key-into-chatgpt-so-i-built-a-chrome-extension-1mhm</guid>
      <description>&lt;p&gt;I use AI chats a lot when coding and analyzing logs.&lt;/p&gt;

&lt;p&gt;A few days ago I almost pasted a real &lt;strong&gt;API key&lt;/strong&gt; into ChatGPT while sharing some logs.&lt;/p&gt;

&lt;p&gt;I noticed it just before sending.&lt;/p&gt;

&lt;p&gt;But it made me realize something:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;It's extremely easy to accidentally leak sensitive data when using AI chats.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;So I built a small Chrome extension called &lt;strong&gt;PasteSafe&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F58ekbn2kkmmrb6i4lq35.gif" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2F58ekbn2kkmmrb6i4lq35.gif" alt=" "&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fyxa57s909ncf8lclipu9.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fyxa57s909ncf8lclipu9.png" alt=" "&gt;&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  What it does
&lt;/h2&gt;

&lt;p&gt;When you paste text into AI chats, it scans the content and detects things like:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;API keys
&lt;/li&gt;
&lt;li&gt;emails
&lt;/li&gt;
&lt;li&gt;phone numbers
&lt;/li&gt;
&lt;li&gt;IBAN
&lt;/li&gt;
&lt;li&gt;UUID
&lt;/li&gt;
&lt;li&gt;URLs
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If something sensitive is detected, it automatically &lt;strong&gt;masks the values before sending&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Example:&lt;br&gt;
API_KEY → [API_KEY#1]&lt;/p&gt;


&lt;h2&gt;
  
  
  &lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Farticles%2Fcs692ol5ntkn66m5g6mh.png" alt=" "&gt;
&lt;/h2&gt;
&lt;h2&gt;
  
  
  Works with
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;ChatGPT
&lt;/li&gt;
&lt;li&gt;Claude
&lt;/li&gt;
&lt;li&gt;Gemini &lt;/li&gt;
&lt;/ul&gt;


&lt;h2&gt;
  
  
  Privacy first
&lt;/h2&gt;

&lt;p&gt;Everything runs &lt;strong&gt;locally in the browser&lt;/strong&gt;.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;no servers
&lt;/li&gt;
&lt;li&gt;no tracking
&lt;/li&gt;
&lt;li&gt;no data collection
&lt;/li&gt;
&lt;/ul&gt;


&lt;h2&gt;
  
  
  Small update:
&lt;/h2&gt;

&lt;p&gt;The extension just got approved in the Chrome Web Store.&lt;/p&gt;

&lt;p&gt;

&lt;/p&gt;
&lt;div class="crayons-card c-embed text-styles text-styles--secondary"&gt;
    &lt;div class="c-embed__content"&gt;
        &lt;div class="c-embed__cover"&gt;
          &lt;a href="https://chromewebstore.google.com/detail/pastesafe-%E2%80%94-ai-paste-sani/gpoiombmmaegnfijmcelgbkfbkelgdih" class="c-link align-middle" rel="noopener noreferrer"&gt;
            &lt;img alt="" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Flh3.googleusercontent.com%2FtFJbq-c9v3E1hnJISdwrDVatzysvlzXXimpsNKOpCesBJrP325GJ2Oe2BDK2AUPwlaTrvzUM48JQbBXWBmPtK85f0XY%3Ds128-rj-sc0x00ffffff" height="auto" class="m-0"&gt;
          &lt;/a&gt;
        &lt;/div&gt;
      &lt;div class="c-embed__body"&gt;
        &lt;h2 class="fs-xl lh-tight"&gt;
          &lt;a href="https://chromewebstore.google.com/detail/pastesafe-%E2%80%94-ai-paste-sani/gpoiombmmaegnfijmcelgbkfbkelgdih" rel="noopener noreferrer" class="c-link"&gt;
            PasteSafe — AI Paste Sanitizer - Chrome Web Store
          &lt;/a&gt;
        &lt;/h2&gt;
          &lt;p class="truncate-at-3"&gt;
            Protects API keys, emails and sensitive data when pasting into ChatGPT, Claude and Gemini. Detects and masks sensitive data.
          &lt;/p&gt;
        &lt;div class="color-secondary fs-s flex items-center"&gt;
            &lt;img alt="favicon" class="c-embed__favicon m-0 mr-2 radius-0" src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fssl.gstatic.com%2Fchrome%2Fwebstore%2Fimages%2Ficon_48px.png"&gt;
          chromewebstore.google.com
        &lt;/div&gt;
      &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;




&lt;p&gt;If anyone wants to try it with real prompts or logs and share feedback, I'd really appreciate it.&lt;/p&gt;




&lt;p&gt;GitHub repo:&lt;br&gt;&lt;br&gt;
&lt;a href="https://github.com/pastsafe-ext/pastesafe" rel="noopener noreferrer"&gt;https://github.com/pastsafe-ext/pastesafe&lt;/a&gt;&lt;/p&gt;




&lt;p&gt;Curious:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Have you ever accidentally pasted something sensitive into an AI chat?&lt;/strong&gt;&lt;/p&gt;

</description>
      <category>ai</category>
      <category>chatgpt</category>
      <category>security</category>
      <category>webdev</category>
    </item>
  </channel>
</rss>
