Check a PoC or gist for secrets before you publish
A public PoC is read by everyone, the fork URL in line 12 included. Drop the files and get every key, token and private link as a file and a line.
Your content never leaves the browser.
Block and warn
Block is key material, a credential file or a link that only you can open. Take the line out before the file leaves your machine, and rotate the key if it was ever pushed. The workbench refuses a review that contains one.
Warn is an email address or a public IP address. Some belong in a proof: a contact line, a public RPC host. Read each one and decide.
The result names the kind and the line. It never prints the match.
Where secrets hide in a PoC
vm.createSelectForkand--fork-urllines with the provider key in the URL.foundry.tomlRPC endpoints and theaccountslist inhardhat.config.- A
.envcommitted next to the test. - Terminal output pasted into the README, with the RPC URL it ran against.
- A link back to your own report on the platform dashboard.
Kinds
| Kind | Level | What it matches |
|---|---|---|
| Wallet private key | LevelBlock | What it matchesA 64-digit hex value next to a key label, or passed to new Wallet(…), vm.startBroadcast(…) or an accounts list. |
| Wallet seed phrase | LevelBlock | What it matchesTwelve to twenty-four lowercase words next to “mnemonic” or “seed phrase”, or alone on a line. |
| Private key block | LevelBlock | What it matchesA PEM header: BEGIN … PRIVATE KEY. |
| RPC URL with an API key | LevelBlock | What it matchesAlchemy, Infura and QuickNode endpoints that carry the key in the path. |
| API key or token | LevelBlock | What it matchesModel-provider and payment keys, GitHub and Slack tokens, AWS and Google keys, npm tokens, webhook signing secrets, JSON web tokens. |
| URL with a username and password | LevelBlock | What it matcheshttps://user:password@host |
| Link to a private platform report | LevelBlock | What it matchesA dashboard link to your own submission on Immunefi, Cantina or Sherlock. |
| File that normally holds credentials | LevelBlock | What it matchesBy name: .env, id_rsa, wallet.dat, .pem, .har, cookie and keystore files, anything under .ssh or .aws. |
| Email address | LevelWarn | What it matchesA personal address. Placeholder and no-reply addresses are skipped. |
| Public IP address | LevelWarn | What it matchesA routable IPv4 address. Loopback, private and documentation ranges are skipped. |
Left alone on purpose: the ten default Anvil and Hardhat keys and their test … junk mnemonic, which are public; transaction hashes, storage slots and bytes32 constants; version strings that look like IP addresses.
Questions
Are the files uploaded?
No. The scan is JavaScript that runs in this tab. The page makes no request with a file name, a line or a match, and a result lists the kind of secret and its line, never the secret. After the page has loaded it makes one request: a counter that says the tool was used, with nothing of yours in it.
What does a clean result cover?
The key, token and link formats in the table above. A password written in a sentence, or a token in a format of your own, has no pattern to match. Read the diff once before you push.
Is this the same check the workbench runs?
Yes. It is the scanner that runs before every review. A file that shows a Block here is refused there until the line is removed.
Clean files. Next, the proof itself.
A proof review reads the test as the triager who will run it once: real path or mock, concrete values, and the assertion that proves the impact.