I will do a security audit of your code for exposed api keys and secrets
AI Agent Developer, Custom Automation, Web Apps and Internal Tools
About this Gig
Find out whether the app you built fast shipped with a key inside it before someone else does. Send a zip or a repository export and you get one report listing every exposed API key, password, token and service secret by file, line and type, with the value masked every time, plus the same check of the version history, since a secret deleted from the code is still in the history. It is a focused audit of your code for exposed secrets, not a penetration test: nothing is run against your live systems and nothing is changed. Delivered in three days, no revisions on the report, one round of questions answered in the thread. If you want the findings fixed or a wider audit, message me and I will say what I can do and quote it. AI tools are part of the scan and I say so plainly; the report lists each finding by file, line and secret type with values masked, so you can verify every line against your own code.
My Portfolio
FAQ
What do I need to send you?
A zip of the codebase or a repository export. No access to your accounts, servers or hosting is needed or requested.
Will you see my secrets?
The scan reads them to find them. The report masks every value, and your files are removed from my working folder after acceptance.
Is this a penetration test?
No. It is a scan of the code you supply for exposed credentials. Nothing is run against your live systems.
Can you fix what you find?
Not in this package. A fix is scoped in a message first, and rotating the credential is something you do on your side.
