Did my coding agent leak my API keys?
Coding agents save transcripts and settings files to disk. A key you pasted once can sit in one of those files, get committed, and end up in a public repo or a published package.
The usual secret scanners look at your code. Most do not know where an agent keeps its own files, and none of them look at the bundle your users download.
We are setting up a scan that covers all of it. It is not a product yet. We are doing it by hand for a first small group.
What we would set up
- Your repo and its full history.
- Your coding agent’s transcripts and settings files (for example .claude/settings.local.json).
- The built front-end bundle, where a key can end up in every visitor’s browser. This is the one people miss, because the repo can be clean while the build pulls the key in from a local file.
- For anything found, where it is and the link to rotate it.
- A pre-commit hook, installed for you, so it does not happen again.
What people are saying
Posts we read on October 7, 2026. Upvotes as of that day.
“a committed Claude Code settings.local.json leaked my API key and burned 121,000 credits in a day”
“I scanned 46,500 npm packages and found 428 with .claude/settings.local.json inside.”
Get early access
Leave your email and we will write to you, by hand, when the first group starts. Tell us what you are running if you want. We read every note.
Who is behind this
Continuum is Matt Turley's studio. We build and look after software for small businesses and founders, and we run our own business on AI agents, which is where these ideas come from. Questions: hello@uxcontinuum.com. Other things we are testing.