Check a PoC or gist for secrets before you publish

A public PoC is read by everyone, the fork URL in line 12 included. Drop the files and get every key, token and private link as a file and a line.

Your content never leaves the browser.

secret-checkLocal · no upload
Paste text insteadA gist, a trace, a config

Block and warn

Block is key material, a credential file or a link that only you can open. Take the line out before the file leaves your machine, and rotate the key if it was ever pushed. The workbench refuses a review that contains one.

Warn is an email address or a public IP address. Some belong in a proof: a contact line, a public RPC host. Read each one and decide.

The result names the kind and the line. It never prints the match.

Where secrets hide in a PoC

  • 01vm.createSelectFork and --fork-url lines with the provider key in the URL.
  • 02foundry.toml RPC endpoints and the accounts list in hardhat.config.
  • 03A .env committed next to the test.
  • 04Terminal output pasted into the README, with the RPC URL it ran against.
  • 05A link back to your own report on the platform dashboard.

Kinds

What the scan reports
KindLevelWhat it matches
Wallet private keyLevelBlockWhat it matchesA 64-digit hex value next to a key label, or passed to new Wallet(…), vm.startBroadcast(…) or an accounts list.
Wallet seed phraseLevelBlockWhat it matchesTwelve to twenty-four lowercase words next to “mnemonic” or “seed phrase”, or alone on a line.
Private key blockLevelBlockWhat it matchesA PEM header: BEGIN … PRIVATE KEY.
RPC URL with an API keyLevelBlockWhat it matchesAlchemy, Infura and QuickNode endpoints that carry the key in the path.
API key or tokenLevelBlockWhat it matchesModel-provider and payment keys, GitHub and Slack tokens, AWS and Google keys, npm tokens, webhook signing secrets, JSON web tokens.
URL with a username and passwordLevelBlockWhat it matcheshttps://user:password@host
Link to a private platform reportLevelBlockWhat it matchesA dashboard link to your own submission on Immunefi, Cantina or Sherlock.
File that normally holds credentialsLevelBlockWhat it matchesBy name: .env, id_rsa, wallet.dat, .pem, .har, cookie and keystore files, anything under .ssh or .aws.
Email addressLevelWarnWhat it matchesA personal address. Placeholder and no-reply addresses are skipped.
Public IP addressLevelWarnWhat it matchesA routable IPv4 address. Loopback, private and documentation ranges are skipped.

Left alone on purpose: the ten default Anvil and Hardhat keys and their test … junk mnemonic, which are public; transaction hashes, storage slots and bytes32 constants; version strings that look like IP addresses.

Questions

Are the files uploaded?

No. The scan is JavaScript that runs in this tab. The page makes no request with a file name, a line or a match, and a result lists the kind of secret and its line, never the secret. After the page has loaded it makes one request: a counter that says the tool was used, with nothing of yours in it.

What does a clean result cover?

The key, token and link formats in the table above. A password written in a sentence, or a token in a format of your own, has no pattern to match. Read the diff once before you push.

Is this the same check the workbench runs?

Yes. It is the scanner that runs before every review. A file that shows a Block here is refused there until the line is removed.

Clean files. Next, the proof itself.

A proof review reads the test as the triager who will run it once: real path or mock, concrete values, and the assertion that proves the impact.

More free tools