How to fix it
- Rotate the key first. Deleting the line does not remove it from history.
- Move it to an environment variable or your host's secret store, and read it on the server only.
- Re-run the scan to confirm the finding is gone.
To make a demo work, an assistant will happily write the token straight into a config file. It compiles, it deploys, and now it is in git history.
npx @neuralaxis/vibedoctor scan What it looks like
A hardcoded key does not fail a build, a type check, or a test. Nothing in the normal loop notices it.
Once committed, it lives in git history even after you delete the line. Anyone with the repo, or a public mirror of it, has the key.
export const GITHUB_TOKEN = "ghp_••••••••••••••••••••••••••••••••••••"; Example: A demo app assembled from VibeDoctor's test fixtures, with a randomly generated, never-valid token.
What VibeDoctor reports
| Finding | Severity | Evidence | From |
|---|---|---|---|
| github-pat The rule ID comes from gitleaks. The value is redacted in the report. | critical | verified | gitleaks |
Evidence grades say how sure the finding is. What verified, observed and heuristic mean →
How to fix it
What this check can’t see
Run it
npx @neuralaxis/vibedoctor scan
Runs locally on JavaScript, TypeScript and Python repos. Hand the result to Cursor,
Claude Code, Codex or Copilot with agent-plan.
Agent setup →