Your coding agent may have saved your API keys in plain text. Here is how to find and remove them
Coding agents read .env files as a matter of course, and the tools write what the agent saw to disk: prompt histories, session transcripts, local databases. An API key that passed through a session can stay there in plain text for months. Where the keys go Coding agents read .env files as a matter of course. Every tool then stores what it saw in its own format. Claude Code writes JSONL files…
Coding agents automatically read .env files, capturing prompt histories, session transcripts, and local databases. These agents then store the information in various formats, storing API keys in plain text for extended periods. Each tool, such as Claude Code, Codex, Cursor, Cline, Gemini CLI, OpenCode, and Aider, maintains its own copy of the keys.
Over time, these files remain unchanged and are copied across folder syncs and backups. No existing cleanup tools were found to address the issue, so the author developed a solution called "agentleaks." This tool, a single Go binary with three commands, scans the history of 13 tools and checks them against 64 rules. The results are presented in a table, revealing the provider, tool, file, line or database record, and a masked preview of the key, without printing the full secret.
The fix command removes the keys directly from the files, ensuring JSON strings remain valid and SQLite rows are updated in a transaction. A backup of the original file is created before making changes, preserving the file's modification time. The tool installs hooks into each agent's configuration, preventing the next read of .env or ~/.aws/credentials files.
Additionally, guard mode is enabled, refusing to allow the next read of .env or ~/.aws/credentials. A demo of the tool was run on a throwaway home directory with fake keys, not real history. The Go code and rule list are available on GitHub, and users can submit requests for additional support for tools or key formats not currently covered.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.