Skip to main content

envleak

Find your exposed API keys before someone else does.

One command. No config. Nothing ever leaves your machine.

pipx run envleak
  ┌────────────────────────────────────────────┐
  │            E N V L E A K   S C A N         │
  └────────────────────────────────────────────┘

   F   █░░░░   Crítico

   5 hallazgo(s) en 128 archivos
   5 critical

   ⚡ 2 en la superficie de agentes/LLM

   ✗ ARCHIVOS DE ENTORNO RASTREADOS POR GIT:
     .env

   CRIT  Anthropic API key
         .env:2
         ANTHROPIC_API_KEY=sk-a********o9Pq

   CRIT  GitHub token
         .config/mcp.json:1
         {"mcpServers":{"gh":{"env":{"GITHUB_TOKEN":"ghp_********3zA5"}}}}

Why another secret scanner?

There are good ones already — gitleaks and trufflehog scan git history and belong in your CI pipeline. envleak is for a different moment: right now, on your laptop, in ten seconds, with a grade you can screenshot.

Two things it does that the others don't:

1. It scans the agent surface. Everyone is shipping AI agents in 2026, and the credentials moved with them — MCP server configs, claude_desktop_config.json, n8n and LangGraph workflows, notebooks, LLM provider keys pasted into JSON. envleak knows what an OpenAI, Anthropic, Groq, LangSmith or Hugging Face key looks like and where agent tooling hides them.

2. It gives you a grade, not a JSON dump. A 400-line report gets closed. An F gets fixed.

Install

pipx run envleak          # no install, just run it
pip install envleak       # or keep it around

Python 3.8+. Zero dependencies.

Use

envleak                   # scan current directory
envleak ~/code/myproject  # scan somewhere else
envleak --markdown        # scorecard ready to paste in an issue or PR
envleak --json            # machine-readable, for pipelines

In CI

Exits 1 when it finds anything high or worse:

- run: pipx run envleak --fail-on critical
envleak --fail-on none    # report only, never fail

What it looks for

Surface Examples
AI / agents OpenAI, Anthropic, Google AI, Groq, Mistral, Hugging Face, Replicate, LangSmith, Perplexity, MCP configs
Cloud / infra AWS access keys, GCP service accounts, private key blocks, Docker registry auth
Classic GitHub, GitLab, Stripe, Slack, Telegram, SendGrid, Twilio, JWTs, database URLs with passwords
Generic High-entropy values assigned to *_KEY, *_TOKEN, *_SECRET, *_PASSWORD — in config files only

It also flags the thing that actually causes breaches: .env files tracked by git.

Privacy

This is a security tool, so the guarantee matters more than the feature list:

  • It makes no network calls. None. Read the source — it's a few hundred lines with zero dependencies.
  • Secrets are redacted in output. You see sk-a********o9Pq, never the full key, so a screenshot is safe to post.
  • Nothing is written anywhere except stdout.

False positives

The generic entropy check runs only in config files (.env, .json, .yaml, .toml, .ini). In source code it fires on ordinary expressions like key = key.upper() and buries the real findings, so it doesn't run there.

Template files (.env.example, *.sample, *.template) are downgraded, and documentation credentials (user:password@localhost) are ignored.

Found a false positive? Open an issue with the pattern — that feedback is the whole roadmap.

What it is not

envleak scans your working tree, not git history. If a key was committed and later deleted, it's still in your history and still compromised — use trufflehog for that, and rotate the key regardless.

Finding a key is step one. Rotate it. A key that appeared in this scan should be considered burned.

License

MIT

Metadata

Release files for envleak-cli 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for envleak-cli 0.1.0
File Size Uploaded
envleak_cli-0.1.0.tar.gz 11.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for envleak-cli 0.1.0
File Interpreter ABI Platform
envleak_cli-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 25.5 kB

Release files / envleak_cli-0.1.0.tar.gz

Download URL envleak_cli-0.1.0.tar.gz
Size 11.6 kB
Tags Source
SHA-256 checksum
How to use checksums
034bd3743a5f23846b5244363589db3f2b1cef9b679e6fddbdaac0a7be562cad
BLAKE2b-256 checksum
How to use checksums
006a08f263958640908fcbf4d2d8c0f89b7a248d17e11d13684ddd52bf6e0f24
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.4

Release files / envleak_cli-0.1.0-py3-none-any.whl

Download URL envleak_cli-0.1.0-py3-none-any.whl
Size 13.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
07f3a91cc9d3de60878a84a740793dcf766ded76d17ddb872ced97b763004315
BLAKE2b-256 checksum
How to use checksums
59dedc958dc0fa5798eda971210d5540b526a70c6855409401d31327cffa1f2b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.14.4

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page