Pre-publication safety check

Your .env is gone.
Git remembers.

Check current files and reachable Git history locally. Get redacted findings and a verdict to review: GO, GO WITH REVIEW, or NO-GO.

$ ./bin/did-i-leak --repo /path/to/target-repo --full

Run from the cloned checkout and replace /path/to/target-repo with your repository. Install guide

local-first / redacted output / no credential mutations

Working tree and Git history flow into a redacted report, then a person reviews the findings.
Tree + reachable history → redacted findings → your decision. No automatic publication.
LOCAL REFSbranches + tags + deleted blobs
2 SCANNERSGitleaks + TruffleHog when available
REDACTEDfull values never reach the output

01 / THE MOMENT BEFORE PUBLISH

One check.
Less dread.

Inspect what is present, find what history retained, and resolve the findings before you decide to publish.

01

Run it where the code lives.

Call the CLI locally without an account or repository upload. Or load the skill in a Codex-compatible agent, subject to that agent's own data policies.

02

Let Git tell the whole story.

Current files are only half the picture. Reachable history, branches, tags, deleted files, and suspicious blobs count.

03

Review and resolve the findings.

Review the redacted file and commit references. Rotate exposed credentials first; assess PII and internal paths in context.

02 / WHAT IT CHECKS

History is
evidence.

Established scanners do the secret detection. Did I Leak? adds the context that makes their output useful before a public push.

01NOW

Current tree

Tracked and untracked files, including ignored .env files outside dependency and build directories.

03REPORT

Redacted output

No full credentials in the terminal, JSON, examples, or handoff. You see the risk, not the secret.

03 / SEE THE VERDICT

Useful beats
noisy.

Illustrative output, not results from your repository. A verdict summarizes findings and detector coverage; it is not a security certificate.

did-i-leak / verdict redacted
DID I LEAK?

NO-GO

1 blocker

Historical credential detected
Commit: a83f2c1
File: scripts/test_api.py
Status: deleted from current tree
Confidence: high

Action: Revoke/rotate before publishing.

Coverage
Gitleaks: completed
TruffleHog: completed
Git history: all reachable commits

CONCRETE BEFORE / AFTER

“I deleted the .env.”

Before: the current folder looks clean, but an old commit still contains a credential.

After: a redacted historical finding points to the file and commit. Revoke or rotate the credential before considering history cleanup.

“The scan found nothing.”

Before: a missing detector could look like a clean scan.

After: missing or disabled scanners keep the verdict at GO WITH REVIEW. Check coverage and any review items before deciding.

The rule

“Deleted” is not the same as “never exposed.”

If a real credential was ever committed or shared: revoke it first, verify its replacement is absent, then decide whether history cleanup is worth the consequences.

04 / MAKE IT A HABIT

Before public,
run this.

Requires Python 3.9+ and Git. Clone into an unused directory. Gitleaks and TruffleHog are optional but recommended; install them separately through their official instructions.

git clone https://github.com/pengusto/did-i-leak.git
cd did-i-leak
./bin/did-i-leak --repo /path/to/target-repo --full

Replace the target path. For Codex-compatible agents, load SKILL.md and invoke $did-i-leak.

Read the install guide Browse the source

KNOW THE LIMITS

A report.
Your decision.