Tools
Small tools, each listed with what it catches and what it misses. The second list is the one that matters.
A dependency-free script that scans staged changes for credential-shaped strings and blocks the commit before the value enters history.
What it catches
- Provider-issued keys with fixed shapes: AWS access key ids, GitHub, Slack and Stripe tokens, Google API keys.
- PEM private key blocks, including RSA, EC, OPENSSH and PGP headers.
- JSON Web Tokens, by their three base64url segments.
- Connection strings that carry an inline password, in any scheme.
- Assignments like password = "…" or api_key: "…" where the value is eight characters or more.
What it misses
- Passwords someone chose. There is no pattern for hunter2 and no entropy threshold that separates it from ordinary text.
- Anything already in history. It reads staged changes only, so it prevents the next leak rather than finding the last one.
- Encoded or encrypted values. Base64 a key and it no longer matches the shape it is recognised by.
- Secrets outside the diff: a screenshot, a stack trace, a log line, a value pasted into an issue.
- Values that look like placeholders. Anything containing example, changeme, your-, <…> or ${…} is skipped on purpose, which means a real key with EXAMPLE in it is skipped too.
