GitSentinel
Overview
Detect exposed secrets (API keys, tokens, credentials) in GitHub repositories — local, no server.
GitSentinel scans GitHub repositories, pull-request diffs and CI logs for exposed secrets — before attackers find them. Everything runs locally in your browser. Nothing leaves your device. **Scan anywhere on GitHub** - One-click full-repo scan from the popup or side panel, plus automatic scanning of the visible page - PR diff scanner: checks only added (+) lines in pull requests, including "resolved later" detection - CI log scanner: catches secrets echoed into Actions logs (5 MB safety cap, cached) - Paste Guard warns before you paste a secret into github.com 20+ secret types, calibrated Covers access keys, tokens, private keys and connection strings from major cloud and SaaS providers Context-aware detection: tuned to ignore hashes, lockfiles and config noise — no alert fatigue **Remediate, don't just detect** - Per-secret Fix-It guides: rotate, gitignore (full repo-relative path), refactor to env, purge history with git filter-repo - Security checklist per finding type - Accept-risk baseline: triage once, hidden from future scans until you unaccept **Built for real workflows** - Masked by default, click-to-reveal with 30-second auto re-mask - Full-text search + severity filters across findings - Release & star tracking for saved repos, exposure-age estimates, version history - JSON/CSV/SARIF export, JSON/HTML import **Your secrets stay yours** - Findings are stored masked only — raw values never touch chrome.storage - No account, no servers, no analytics, no tracking - The only network calls are to GitHub's public API (repo content you already have access to) plus an optional metadata relay you deploy yourself - Optional PAT increases the API budget from 60 to 5,000 req/h and unlocks private repos **How to use it** 1. Open any GitHub repo and click Scan, or let the side panel scan the visible page 2. Review findings grouped by severity — masked by default 3. Follow the Fix-It guide: rotate the credential, then purge it from history **Trademark notice**: GitHub is a registered trademark of GitHub, Inc. This extension is an independent, unofficial tool — not affiliated with, endorsed by, or sponsored by GitHub, Inc.
0 out of 5No ratings
Details
- Version1.6.10
- UpdatedOctober 6, 2026
- Offered byiacob.iuliann
- Size146KiB
- LanguagesEnglish (United States)
- Developer
Email
iacob.iuliann@gmail.com - Non-traderThis developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.
Privacy
GitSentinel has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.
GitSentinel handles the following:
This developer declares that your data is
- Not being sold to third parties, outside of the approved use cases
- Not being used or transferred for purposes that are unrelated to the item's core functionality
- Not being used or transferred to determine creditworthiness or for lending purposes