Agentleak — AI skill for Claude Code
Find secrets you already leaked into AI chat sessions — offline, local-first.
How to install Agentleak
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open GavenXia/agentleak and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Agentleak does
Find secrets you already leaked into AI chat sessions — offline, local-first.
Alternatives in AI
README
agentleak
**Find the secrets you already leaked into AI chat sessions — before someone else does.**
[](https://github.com/GavenXia/agentleak/actions/workflows/ci.yml) [](https://www.npmjs.com/package/agentleak) [](LICENSE) [](package.json) [](SECURITY.md)
An offline, local-first CLI that discovers **every AI-agent conversation store on your machine**, scans it for API keys / SSH keys / tokens, and turns the findings into a **rotation checklist** — with a persistent baseline so you only ever see _new_ leaks.
[Quick start](#-quick-start) · [How it works](#-how-it-works) · [Agent integrations](#-install-per-agent) · [Security promises](#️-security--trust)
[中文文档](README.zh-CN.md)
🚨 The problem
**Your AI agent chats are a credential leak you have never audited.**
Every time you (or a teammate) pasted an API key into a chat — "here, use this token to deploy" — that secret was written to disk in plaintext, unencrypted, often forever:
~/.claude/projects/**/session-*.jsonl # full Claude Code transcripts
~/.codex/sessions/**/*.jsonl # full Codex CLI transcripts
~/Library/Application Support/Cursor/ # chat bodies in SQLite
~/.claude/paste-cache/*.txt # raw pasted blobs
Meanwhile, the blast radius of any single paste keeps growing:
| Fact | Source | | ------------------------------------------------------------------
Related Skills
Residoo
Find secrets your AI coding agent leaked to disk. Free, MIT, zero deps, zero network calls. Beat TruffleHog an
Agents Recap
Local, offline recap and RAG memory of your AI coding sessions. Reads Claude Code, Cursor and VS Code Copilot
Agf
Local-first TUI to find, search, and resume AI coding-agent sessions across Claude Code, Codex, Grok Build, Ki
Foci
openclaw-like ai agent platform. Written in go for speed and memory-efficiency. Supports claude code as backen
Llmscrub
Sweep LLM agent logs (Claude Code, Codex) for leaked secrets and redact them in place.
Kage
Local memory for AI coding agents. Find, replay, fork, bridge, and dispatch Claude Code, Codex, and Qoder sess
Related Agents
Ade
Agent sessions routinely outlast the machine that started them, and checking a Claude Code or Codex run from a
Secret Purist
The paranoid sentinel of credential security. Use this agent to scan codebases and git history for leaked secr
Opensource Sanitizer
Pre-public-push safety net. Scans a diff or working tree for leaked secrets, PII, internal references, interna