Find the API keys your AI pasted into the code.

To make a demo work, an assistant will happily write the token straight into a config file. It compiles, it deploys, and now it is in git history.

npx @neuralaxis/vibedoctor scan

What it looks like

It compiles. It ships. It’s wrong.

A hardcoded key does not fail a build, a type check, or a test. Nothing in the normal loop notices it.

Once committed, it lives in git history even after you delete the line. Anyone with the repo, or a public mirror of it, has the key.

src/config.ts
export const GITHUB_TOKEN = "ghp_••••••••••••••••••••••••••••••••••••";

Example: A demo app assembled from VibeDoctor's test fixtures, with a randomly generated, never-valid token.

What VibeDoctor reports

A ranked finding with the exact location.

  • Gitleaks rules for cloud, payment, source-control, and chat tokens. VibeDoctor can download a pinned copy for you.
  • A credential check on every match: known prefixes such as sk-, ghp_, AKIA, AIza, glpat-, xox and private-key headers, plus entropy.
  • Placeholders and identifiers are downgraded and relabelled, so “your-key-here” does not outrank a real token.
FindingSeverityEvidenceFrom
github-pat
The rule ID comes from gitleaks. The value is redacted in the report.
critical verified gitleaks

Evidence grades say how sure the finding is. What verified, observed and heuristic mean →

How to fix it

  1. Rotate the key first. Deleting the line does not remove it from history.
  2. Move it to an environment variable or your host's secret store, and read it on the server only.
  3. Re-run the scan to confirm the finding is gone.

What this check can’t see

  • It does not know whether a VITE_ or NEXT_PUBLIC_ variable ends up in the browser bundle. Check those by hand.
  • It cannot tell you whether a leaked key was already used. Assume it was.

Fixing it, and the limits of this check

Run it

Check your repo now.

npx @neuralaxis/vibedoctor scan

Runs locally on JavaScript, TypeScript and Python repos. Hand the result to Cursor, Claude Code, Codex or Copilot with agent-plan. Agent setup →