Continuum Labs, early access

Did my coding agent leak my API keys?

Not built yet. We are setting this up by hand for a first small group, and this page is how we find out who wants it. There is nothing to buy.

Coding agents save transcripts and settings files to disk. A key you pasted once can sit in one of those files, get committed, and end up in a public repo or a published package.

The usual secret scanners look at your code. Most do not know where an agent keeps its own files, and none of them look at the bundle your users download.

We are setting up a scan that covers all of it. It is not a product yet. We are doing it by hand for a first small group.

What we would set up

What people are saying

Posts we read on October 7, 2026. Upvotes as of that day.

“a committed Claude Code settings.local.json leaked my API key and burned 121,000 credits in a day”

r/vibecoding

“I scanned 46,500 npm packages and found 428 with .claude/settings.local.json inside.”

r/vibecoding

Get early access

Leave your email and we will write to you, by hand, when the first group starts. Tell us what you are running if you want. We read every note.

No payment, no newsletter. One email from a person when the first group starts. Privacy

Who is behind this

Continuum is Matt Turley's studio. We build and look after software for small businesses and founders, and we run our own business on AI agents, which is where these ideas come from. Questions: hello@uxcontinuum.com. Other things we are testing.