Your agent wrote your API key down.

Claude Code, Codex, Cursor and every other coding agent keep a plain-text log of each session. Every key you pasted and every .env the agent read is in there. spillage finds them, tells you how they got there, cleans them out and stops the next one.

{"type":"user","cwd":"/Users/you/code/shop","message":{"content":"the deploy fails with 401, can you look?"}}
{"type":"assistant","message":{"content":[{"type":"tool_use","name":"Bash","input":{"command":"cat .env"}}]}}
{"type":"user","message":{"content":[{"type":"tool_result","content":"PORT=3000\nGITHUB_TOKEN=ghp_N7ITxKLUkX0vyOYx6tzSnWQ36xgB0O4awzF9\nDEBUG=1"}]}}
{"type":"assistant","message":{"content":"Found it. The token in .env has expired."}}
{"type":"user","message":{"content":"ok here's a fresh one, push it"}}
{"type":"summary","leafUuid":"8f2c41d0-6a1e-4c55-9d0e-5b7e2a91c3f4"}
✓ found, rotated, scrubbed
brew install maximilianfeix/tap/spillage
or pipx install git+https://github.com/maximilianfeix/spillage, then run spillage

Find it, clean it, stop the next one.

Everything runs on your machine. Keys are only ever shown as a masked prefix and a fingerprint.

spillage

Finds the keys in every agent's logs and says whether you pasted them, a tool printed them or the model repeated them, with a link to rotate each one.

spillage scrub

Redacts them in place without breaking the JSON your agent reads back when you resume a session.

spillage guard install

Blocks the next leak with hooks in Claude Code, Codex and Gemini CLI: prompts with keys, reading .env, printenv.

spillage watch

Notifies you within seconds when a key lands in any agent's log, Cursor and Aider included.

Reads the logs of

Claude Code, Codex CLI, Cursor, Gemini CLI, Cline, Roo, Kilo, OpenCode, Aider, SpecStory, Qwen Code, Goose, Crush, Continue and Copilot CLI. Plus any folder you point it at.

16,000

chat logs sit in public GitHub repos.

SpecStory and Aider save conversations inside the project, and from there they get committed. spillage repo finds them and the keys inside, and ships as a GitHub Action and a pre-commit hook.

GitHub code search, September 2026: about 16,000 SpecStory histories and 5,000 Aider histories.

What a run looks like

Animated terminal: spillage finds a GitHub token, a Stripe key and an Anthropic key, scrubs them and installs the guard hooks

Built to be trusted with your keys

No dependenciesStandard-library Python 3.9 and up. Nothing to audit but the code.

No networkNo telemetry, no update check, no key validation calls.

Few false alarmsChecksums for GitHub tokens, decodable JWTs, placeholder filtering.

56 rulesIncluding the AI stack gitleaks doesn't cover: Claude Code OAuth, Supabase, LangSmith, Pinecone.

FastAbout 240 MB of real agent history in under 4 seconds on a laptop.

MIT licensedIssues and new rules welcome.