npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

leakward

v0.1.14

Published

Protect your projects from AI-tool secret leaks — catches .claude/, .cursor/, and hidden credentials before npm publish or git push

Readme

leakward

Stop AI coding tools from leaking your secrets.

Claude Code, Cursor, Copilot, and Windsurf write fast — and regularly sneak API keys, session tokens, and crypto seed phrases into your public repos and npm packages. leakward catches them before npm publish or git push.

npm install -g @rimenko-dev/leakward
leakward

aiguard is a deprecated alias: npm i -g @rimenko-dev/aiguard and the aiguard command still work.

npm version License: MIT


Real-world findings

We scanned 50,000 public GitHub repositories for AI tool artifacts. Results:

| Metric | Count | |--------|-------| | Files analyzed | 362 | | Unique secrets found | 138 | | Crypto seed phrases (12-word mnemonics) | 45 | | Database connection strings | 40 | | Generic API keys | 22 | | Plaintext passwords | 16 | | Anthropic API keys | 3 | | AWS access keys | 2 | | SSH private keys | 4 |

The #1 leak vector: CLAUDE.md. Developers paste credentials into Claude Code's context file so the AI can reference them — then commit it to a public repo. We found over 63 CLAUDE.md variants containing live secrets.

45 crypto seed phrases were exposed in project files. That's 45 wallets — potentially drained.


The problem

Your AI assistant stores credentials in hidden folders:

| Tool | Folder | What's stored | |------|--------|---------------| | Claude Code | .claude/ | API keys, MCP server tokens, CLAUDE.md context | | Cursor | .cursor/ | OAuth tokens, MCP configs, API keys | | Windsurf | .windsurf/ | Auth tokens, workspace credentials | | Aider | .aider/ | Model API keys, git credentials | | Continue | .continue/ | LLM provider keys, embeddings tokens | | Codeium | .codeium/ | Authentication tokens | | GitHub Copilot | .github/copilot/ | Auth tokens | | Trae | .trae/ | Session credentials | | Roo | .roo/, .roo-cline/ | Model keys |

These folders are not excluded by default from npm publish or git push. One missing .npmignore line, or a CLAUDE.md with a seed phrase committed to a public repo, and secrets are exposed — forever cached by GitHub.


What it catches

AI tool folders in your publish

.claude/, .cursor/, .windsurf/, and 9 more — if any are included in your npm tarball or git commit, publish is blocked.

Known AI context files with secrets

CLAUDE.md, mcp.json, settings.local.json — scanned and blocked if published. Even when excluded from publish, leakward shows you which specific secrets are inside, so you know the blast radius if your ignore config ever breaks.

Secrets in published files — 55+ patterns

| Category | Services | |----------|----------| | AI providers | Anthropic, OpenAI, xAI/Grok, Gemini, Groq, HuggingFace, Replicate, Mistral, Together AI | | Cloud | AWS, GCP service accounts, Azure, DigitalOcean, Cloudflare | | Source control | GitHub (classic / OAuth / Actions / fine-grained PAT), GitLab, npm tokens | | Payments | Stripe, PayPal, Braintree | | Messaging | Slack, Discord, Telegram bots, Twilio | | Email | SendGrid, Mailgun, Resend, Postmark | | Databases | PostgreSQL, MySQL, MongoDB, Redis, Supabase, PlanetScale, Neon, Pinecone | | Hosting | Vercel, Netlify, Heroku, Railway, Fly.io | | Monitoring | Sentry, Datadog | | Crypto | BIP39 12/24-word mnemonics (any format), Ethereum private keys, Bitcoin WIF | | Keys | RSA / EC / SSH private keys, JWT secrets | | Base64 | Encoded secrets — decoded and matched against known prefixes | | Catch-all | Any PASSWORD=, SECRET=, TOKEN=, or *_KEY= (e.g. ENCRYPTION_KEY, STRIPE_KEY) longer than 8 chars — quoted values may contain spaces |

Git history scan

Catches secrets that were committed in the past — even if they were deleted later. GitHub caches all commits forever.

leakward --history

Usage

# Scan current directory (blocks npm publish / git push)
leakward

# Scan a specific project
leakward /path/to/project

# Scan git history for past leaks
leakward --history

# Combine both
leakward /path/to/project --history

Exit codes:

  • 0 — clean or warnings only
  • 1 — CRITICAL or HIGH findings (publish blocked)

Suppressing false positives

Intentional secret-shaped fixtures (tests, docs that quote a pattern) can be silenced without turning the detector off.

Same-line marker — put leakward:allow on the line that would otherwise match (typically in a comment). aiguard:allow and gitleaks:allow are accepted as aliases, so existing comments work as-is. The marker is pinpoint: it does not suppress a match on the next line or in another file.

const demo = "AKIAABCDEFGHIJKLMNOP"; // leakward:allow gitleaks:allow — fixture, not a real key

.leakwardignore — a gitignore-style list of paths/globs at the project root. Matching files are not scanned at all (CLI and the Claude Code Write/Edit hook use the same rules). .aiguardignore is accepted as a deprecated alias.

# .leakwardignore
test/fixtures/
docs/examples/*.env

Example output:

leakward — AI secret leak scanner
Project: /my-package

🚨 CRITICAL — publish blocked (1):
   CLAUDE.md
   This file contains API keys and tokens — it will be included in your npm package!

⚠️  HIGH RISK — publish blocked (2):
   CLAUDE.md
   Anthropic API key: sk-ant-***...agAA
   CLAUDE.md
   Crypto mnemonic (BIP39 seed): abandon ability ***...*** 

💡 WARNINGS (1):
   .env
   Excluded from publish but contains 2 secrets: AWS Access Key ID, Generic secret in env

❌ Publish blocked: 1 critical + 2 high findings.
Add to .npmignore:
  .claude
  .cursor
  .env
  *.local

Use as a pre-publish hook

Add to your package.json to block every npm publish automatically:

{
  "scripts": {
    "prepublishOnly": "leakward"
  }
}

Use as a global Claude Code hook

Install once, protect all projects automatically.

Runs before every git commit, git push, and npm publish in any Claude Code session — no per-project setup needed.

Add to ~/.claude/settings.json:

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "bash \"$HOME/.claude/bin/leakward-guard.sh\"",
            "timeout": 15
          }
        ]
      }
    ]
  }
}

Save this as ~/.claude/bin/leakward-guard.sh (chmod +x):

#!/bin/bash
CMD=$(python3 -c "
import json, sys
try:
    data = json.load(sys.stdin)
    print(data.get('command', ''))
except:
    pass
" 2>/dev/null)

if ! echo "$CMD" | grep -qE '^\s*(git\s+(push|commit|tag)\b|npm\s+publish\b)'; then
    exit 0
fi

if command -v leakward &>/dev/null; then
    leakward "$(pwd)" 2>&1
    exit $?
elif command -v aiguard &>/dev/null; then
    aiguard "$(pwd)" 2>&1
    exit $?
else
    npx --yes @rimenko-dev/leakward "$(pwd)" 2>&1
    exit $?
fi

Use as a pre-commit hook (git)

# In your project root:
echo '#!/bin/sh\nleakward .' > .git/hooks/pre-commit
chmod +x .git/hooks/pre-commit

Note: leakward shells out to npm pack --dry-run internally to get npm's exact publish list (secrets in dist/ or in README.md/package.json otherwise slip through), which adds roughly 0.3–1.5s per run. That's on every commit if you use it as a pre-commit hook. If that's noticeable on a large repo with frequent commits, a pre-push hook (same one-liner, just in .git/hooks/pre-push) still catches everything before a secret leaves your machine, at a fraction of the invocation count.


Severity levels

| Level | Meaning | Blocks publish? | |-------|---------|-----------------| | 🚨 CRITICAL | AI secret file will be included in the package | ✅ Yes | | ⚠️ HIGH | Known secret pattern found in a publishable file | ✅ Yes | | 💡 WARN | Risk exists locally (excluded file contains secrets, missing .npmignore) | ❌ No |


How it works

For npm projects (has package.json):

  1. Resolves exactly which files npm publish would include — respects files field and .npmignore (including wildcard patterns like *.env, *.local)
  2. Scans only those files — no false positives from files that won't be published
  3. Reports ALL instances of each secret per file (not just the first)
  4. Blocks publish on CRITICAL or HIGH findings

For non-npm projects (Go, Python, Rust, etc.):

  1. Scans all non-gitignored files
  2. Reports findings before git push

Publish scan vs. real-time write hook: "Reports ALL instances" above describes the leakward CLI (the npm publish / git push scan) — it always enumerates every match of every secret pattern in a file. The separate real-time hook (claude-hook/leakward-hook.js, triggered by Claude Code on every Write/Edit/MultiEdit/NotebookEdit) works differently: it's built to interrupt the write the instant it confirms a real secret, so it blocks and reports on the first HIGH/CRITICAL match it finds and stops there — it does not enumerate every secret that might be in the same write. It does still walk past earlier look-alike matches of the same pattern that fail validation (e.g. a benign word list that isn't a real BIP39 seed) so a genuine secret sitting right after one is never missed — that thoroughness affects what it's able to detect, not how many findings it prints once it decides to block.

Crypto mnemonic validation: Candidate phrases are validated against the full official BIP39 wordlist (2048 words). At least 90% of words must be real BIP39 words — ordinary English sentences are not flagged.

Base64 detection: Strings labeled as keys/tokens are decoded from Base64, then the decoded value is checked against all known secret prefixes (sk-ant-, AKIA, sk_live_, etc.).

What it does NOT scan:

  • Environment variables (runtime values, not in files)
  • Binary files, images, PDFs
  • Files larger than 5 MB (skipped for performance — flagged with a warning, not silently ignored)
  • Non-standard secret formats with no known prefix
  • Lines marked leakward:allow / aiguard:allow / gitleaks:allow, and paths listed in .leakwardignore / .aiguardignore

Recommended .npmignore

.claude
.cursor
.windsurf
.continue
.aider
.codeium
.env
.env.*
*.local
CLAUDE.md

Install

npm install -g @rimenko-dev/leakward

Or run without installing:

npx @rimenko-dev/leakward

The previous package name still installs the same scanner:

npm install -g @rimenko-dev/aiguard
aiguard --help

Contributing

Pull requests welcome. To add new secret patterns, edit src/patterns.js — each entry needs a name and a regex with the g flag. Patterns that need post-match validation (like BIP39 mnemonics) can add a validate(match) function.


License

MIT — github.com/RimenKo/leakward