Zum Hauptinhalt springen
tsecurity.de LIVE
Echtzeit-Radar & Feeds
Alle RSS Feeds
👥 Community & Social
Sichere ProgrammierungRate Limiting: The Traffic Cop Your API Needs(20.09.2026 um 14:51 Uhr)
Sichere ProgrammierungI Built the MVP First. Then I Wrote the README.(20.09.2026 um 14:51 Uhr)
Sichere ProgrammierungHow to add a loading screen with a progress bar in Godot 4(20.09.2026 um 14:52 Uhr)
Sichere ProgrammierungCanada is about to break your scheduler(20.09.2026 um 14:59 Uhr)
Sichere ProgrammierungWhat Does an AI Automation Agency Actually Do?(20.09.2026 um 15:00 Uhr)
Sichere ProgrammierungRate Limiting: The Traffic Cop Your API Needs(20.09.2026 um 14:51 Uhr)
Sichere ProgrammierungI Built the MVP First. Then I Wrote the README.(20.09.2026 um 14:51 Uhr)
Sichere ProgrammierungHow to add a loading screen with a progress bar in Godot 4(20.09.2026 um 14:52 Uhr)
Sichere ProgrammierungCanada is about to break your scheduler(20.09.2026 um 14:59 Uhr)
Sichere ProgrammierungWhat Does an AI Automation Agency Actually Do?(20.09.2026 um 15:00 Uhr)
Intelligence View
⚡ tsecurity.de Intelligence

The API keys you almost shipped to prod — and the free scanner I built to catch them

Reagiere als Erste:r — dein Feedback zählt!

I'm a solo maker shipping small apps, often with AI writing most of the code. The thing that kept me up at night: right before launch it's really easy to leave a live API key or an obvious vulnerability sitting in the codebase — especially when you didn't hand-write every line and you're moving fast.

So I built a small tool to catch that before it goes public. It's called presec.

What it does

You paste your code (or drop a zip), and it runs two passes on the server:

  1. Regex rules scan for exposed secrets — AWS, Stripe sk_live_, OpenAI / Anthropic keys, Google, GitHub tokens, private keys, hardcoded passwords, committed .env files, etc. Public-intent keys like Stripe pk_ or a Supabase anon JWT get classified as false positives so the tool doesn't cry wolf.
  2. Selected snippets go to an LLM to flag critical vulnerabilities and return the top 3 prioritized fixes with code.

You get one report: risk summary → exposed secrets (masked) → critical vulns → top 3 fixes. ~1 minute, free, no login.

It's an assistive check, not a full security audit — I'm clear about that in the tool itself. It's for catching the obvious, embarrassing stuff before strangers see it.

The leaks it keeps catching

  • Admin / service-role keys in the repo. A Supabase service_role key (anything that bypasses row-level security) in your code is game over — whoever has it owns your DB.
  • The classic committed .env. It's .gitignored… except that one time it wasn't.
  • Hardcoded password= / secret= left over from "I'll fix it later."
  • Public vs secret confusion — people panic over a pk_ (it's fine, it's public) while a real sk_live_ sits two lines down.

Funny aside: when I scanned presec's own repo, it flagged the example -----BEGIN PRIVATE KEY----- string in my README as a critical leak. So example patterns in docs are a false-positive category I still need to handle. Dogfooding works.

Stack

Next.js (App Router) + Tailwind + Supabase. The LLM call is server-side only (keys never touch the client), secrets are masked before storage, and results expire on a short TTL.

I'd love your take

I'm trying to figure out whether this is actually useful to other people or just to anxious me:

Does this solve a real pain for you? Would you pay for it (and if so, how much)? And — what's the most embarrassing thing you've almost shipped? 🙂

Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten The API keys you almost shipped to prod — and the free scanner I built to catch them

Thematisch verwandte Begriffe: keys, almost, shipped, prod · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Zum Aktualisieren ziehen
ZERO-DAY CVE-2026-93956 | A flaw has been found in olivier-ls PHP-FTS up to 1.1.2. Affected by thi…
Advisory →
TTS Reader • tsecurity.de Voice
tsecurity.de Icon
tsecurity.de App
Offline-Lesen, Eilmeldungen & 0ms Ladezeit

Installiere tsecurity.de direkt auf deinen Home-Bildschirm für das ultimative Vollbild-Magazinerlebnis ohne Browser-Leisten.

Nächster Beitrag
Themen-Radar & Intelligence Matrix
Echtzeit-Taxonomie nach Angriffsvektoren & Plattformen
Community Radar & Live Chat
Sentinel Bot online • Live-Stream
Dein Cluster: Security Explorer
Match:
lädt…
Verbindung zum Community-Stream wird aufgebaut...
Bearbeitungsmodus — Senden überschreibt deine Nachricht
Community-Puls — was gerade passiert
lädt…
Aktivitäten deiner Analysten
lädt…
Neues Thema oder Eilmeldung einreichen

Reiche interessante Links, Zero-Days oder Debatten ein. Die Community entscheidet per Upvote über die Veröffentlichung.

Heiß diskutierte Einreichungen
🔖 Gespeicherte Artikel
📂 Keine gespeicherten Artikel vorhanden.
Zurück Ziehen Vor
Links: vorheriger Artikel Rechts: nächster Artikel unten: schließen
News NIS-2 Frühwarnung Tier-1 Intel ⏱️ 3 Min vor 10 Min
Artikeldaten werden geladen...

Zurück: vorheriger Vor: nächster
↗ Original-Quelle
Social Reaktionen Deine Reaktion zählt
Einstufung & Relevanz-Poll 0 Stimmen
In sozialen Netzwerken teilen 1-Klick