Item logo image for GitSentinel

GitSentinel

ExtensionDeveloper Tools
Item media 5 (screenshot) for GitSentinel
Item media 1 (screenshot) for GitSentinel
Item media 2 (screenshot) for GitSentinel
Item media 3 (screenshot) for GitSentinel
Item media 4 (screenshot) for GitSentinel
Item media 5 (screenshot) for GitSentinel
Item media 1 (screenshot) for GitSentinel
Item media 1 (screenshot) for GitSentinel
Item media 2 (screenshot) for GitSentinel
Item media 3 (screenshot) for GitSentinel
Item media 4 (screenshot) for GitSentinel
Item media 5 (screenshot) for GitSentinel

Overview

Detect exposed secrets (API keys, tokens, credentials) in GitHub repositories — local, no server.

GitSentinel scans GitHub repositories, pull-request diffs and CI logs for exposed secrets — before attackers find them. Everything runs locally in your browser. Nothing leaves your device. **Scan anywhere on GitHub** - One-click full-repo scan from the popup or side panel, plus automatic scanning of the visible page - PR diff scanner: checks only added (+) lines in pull requests, including "resolved later" detection - CI log scanner: catches secrets echoed into Actions logs (5 MB safety cap, cached) - Paste Guard warns before you paste a secret into github.com 20+ secret types, calibrated Covers access keys, tokens, private keys and connection strings from major cloud and SaaS providers Context-aware detection: tuned to ignore hashes, lockfiles and config noise — no alert fatigue **Remediate, don't just detect** - Per-secret Fix-It guides: rotate, gitignore (full repo-relative path), refactor to env, purge history with git filter-repo - Security checklist per finding type - Accept-risk baseline: triage once, hidden from future scans until you unaccept **Built for real workflows** - Masked by default, click-to-reveal with 30-second auto re-mask - Full-text search + severity filters across findings - Release & star tracking for saved repos, exposure-age estimates, version history - JSON/CSV/SARIF export, JSON/HTML import **Your secrets stay yours** - Findings are stored masked only — raw values never touch chrome.storage - No account, no servers, no analytics, no tracking - The only network calls are to GitHub's public API (repo content you already have access to) plus an optional metadata relay you deploy yourself - Optional PAT increases the API budget from 60 to 5,000 req/h and unlocks private repos **How to use it** 1. Open any GitHub repo and click Scan, or let the side panel scan the visible page 2. Review findings grouped by severity — masked by default 3. Follow the Fix-It guide: rotate the credential, then purge it from history **Trademark notice**: GitHub is a registered trademark of GitHub, Inc. This extension is an independent, unofficial tool — not affiliated with, endorsed by, or sponsored by GitHub, Inc.

Details

  • Version
    1.6.10
  • Updated
    October 6, 2026
  • Offered by
    iacob.iuliann
  • Size
    146KiB
  • Languages
    English (United States)
  • Developer
    Email
    iacob.iuliann@gmail.com
  • Non-trader
    This developer has not identified itself as a trader. For consumers in the European Union, please note that consumer rights do not apply to contracts between you and this developer.

Privacy

Manage extensions and learn how they're being used in your organization

GitSentinel has disclosed the following information regarding the collection and usage of your data. More detailed information can be found in the developer's privacy policy.

GitSentinel handles the following:

Authentication information
Web history
Website content

This developer declares that your data is

  • Not being sold to third parties, outside of the approved use cases
  • Not being used or transferred for purposes that are unrelated to the item's core functionality
  • Not being used or transferred to determine creditworthiness or for lending purposes
Google apps