
SecretSentinel
Detect hardcoded secrets in VS Code before you commit them
What it does
SecretSentinel scans your code in real-time and flags hardcoded API keys, passwords and credentials before you commit them. Unlike GitHub's secret scanning which catches leaks after you push, this stops them at the source — your editor. Uses Shannon entropy scoring to catch secrets that don't match any known pattern. Also scans git history, comparesenv files, and generates security reports. Free. Works offline. Your code never leaves your machine.
Does a similar job
all alternatives →


- IBI built a tool that helps people scan and clean any repo for secrets2024 · securelog.com · ▲20
- KDKeyLeak Detector – Scan websites for exposed API keys and secretsNov 2025 · github.com · ▲30
I built this after seeing multiple teams accidentally ship API keys in their frontend code. The problem: Modern web development moves fast. You're vibe-coding, shipping features, and suddenly your AWS keys are sitting in a tag visible to anyone who opens DevTools. I've personally witnessed this happen to at least 3-4 production apps in the past year alone. KeyLeak Detector runs through your site (headless browser + network interception) and checks for 50+ types of leaked secrets: AWS/Google keys, Stripe tokens, database connection strings, LLM API keys (OpenAI, Claude, etc.), JWT…

More dev tools this month
the category →



OpenTrailPaper is open-source bike computer firmware for the LilyGO T5S3 4.7" E-Paper PRO. It supports offline maps, GPX routes, FIT recording and Bluetooth sensors.
Dev tools · 2d ago · opentrailpaper.com

Open-source GTM skills for technical founders
Dev tools · 30d ago · gtmcofounder.com

Launched alongside, March 2026
the whole month →

Switch from ChatGPT to Claude with import memory feature
AI · Mar 2026 · claude.com


