Find the API keys your coding agents spilled into their logs.

- Year
- 2026
- Role
- Author
- Stack
- Python, SARIF, GitHub Actions, Homebrew
Overview
Claude Code, Codex, Gemini CLI, Cursor and the rest keep every conversation on disk as plain text – including each .env they read. Spillage finds the keys, explains how they leaked, and scrubs them.
Coding agents log everything: every file they read, every command output, every key pasted in “just to test”. Spillage reads the logs of thirteen agents, tells you which keys leaked and how – you pasted it, a tool printed it, the model repeated it – and links to the page where each one is rotated.
It scrubs the logs without breaking `--resume`, installs hooks that block the next leak, and fits into CI with HTML, JSON, Markdown and SARIF reports, a GitHub Action and a pre-commit hook.
- 56
- detection rules
- 13
- agents supported
- 0
- dependencies
- 0
- network calls

Implementation
01
Rules that know each key
56 rules match the exact shape of each provider's keys. GitHub tokens are checked against their CRC32 checksum, JWTs must decode, and known placeholders are skipped – so reports stay free of noise.
02
Provenance, not just matches
Each finding records whether the user typed the key, a tool printed it or the model repeated it – which decides what to fix.
03
Scrubbing that keeps sessions alive
Secrets are replaced in place with stable redaction markers, keeping the log format intact so agents can still resume the conversation.
Technical challenges
A tool you point at your secrets
Standard library only, no network access, secrets only ever shown masked. Zero dependencies is a security feature here, not a style choice.
Thirteen log formats
Every agent stores sessions differently – JSONL, SQLite, nested JSON. Each gets a small reader that yields the same event shape.
Architecture
Readers turn each agent's storage into one stream of events; rules run over the events; reporters render findings.
brew install maximilianfeix/tap/spillage
spillage # scan every agent on this machine
spillage scrub # redact in place, --resume keeps working
spillage --sarif > spillage.sarif