Sekreets – GitHub에서 유출된 AI API 키를 실시간으로 검색
hackernews
|
|
📰 뉴스
#anthropic
#mistral
#openai
#perplexity
#머신러닝/연구
#gemini
원문 출처: hackernews · Genesis Park에서 요약 및 분석
요약
GitHub의 공개 이벤트 스트림을 실시간으로 모니터링하여 AI API 키가 유출되는 것을 탐지하는 보안 도구 'Sekreets'가 공개되었다. 이 도구는 OpenAI, Anthropic, Google, NVIDIA, xAI 등 25개 이상의 AI 제공자의 키를 탐지하며, 샌논 엔트로피 분석과 정규표현식 패턴을 결합해 오탐을 최소화한다. 계정 생성이나 API 토큰 없이 웹 스캐너를 통해 즉시 사용할 수 있으며, 발견된 키는 마스킹 처리된 후 저장소 위치와 파일 경로와 함께 제공한다.
본문
[sekreets](https://sekreets.vercel.app/)[Home](https://sekreets.vercel.app/)[Scanner](https://sekreets.vercel.app/secrets)[](https://sekreets.vercel.app/leaderboard) [](https://github.com/sekreets) # AI keys left in plain sight. We find them first. Sekreets continuously hunts GitHub's public event stream for accidentally committed AI API keys — across 25+ providers — and surfaces them before bad actors do. Open ScannerHow it works sekreets scanner $ sekreets scan --provider openai → Connecting to GitHub event stream… ✓ Stream connected → Scanning pushed commits… FOUND sk-proj-•••••••••••••••••••••• user/my-cool-project · src/config.ts:14 entropy: 4.82 provider: OpenAI → Scanning next event… OpenAIAnthropicGoogle GeminiGroqPerplexityHuggingFaceReplicateTogether AIMistralCohereElevenLabsDeepSeekxAI / GrokNVIDIA NIMOpenRouterStability AIFireworks AIVoyage AIAzure OpenAIAWS BedrockAI21 LabsAssemblyAIDeepInfraCerebrasVertex AIOpenAIAnthropicGoogle GeminiGroqPerplexityHuggingFaceReplicateTogether AIMistralCohereElevenLabsDeepSeekxAI / GrokNVIDIA NIMOpenRouterStability AIFireworks AIVoyage AIAzure OpenAIAWS BedrockAI21 LabsAssemblyAIDeepInfraCerebrasVertex AI 25+Providers 25+Patterns Entropy + RegexDetection Real-timeScan Speed Capabilities ## Everything you need to find leaks fast Built on top of GitHub's real-time event stream with battle-tested detection logic. ### Real-time Scanning Continuously scans GitHub's public event stream for newly pushed files containing AI API keys. ### 25+ AI Providers Detects keys from OpenAI, Anthropic, Google, Groq, xAI, NVIDIA and 20+ more with entropy scoring. ### Precise Detection Shannon entropy analysis combined with regex patterns reduces false positives to near-zero. ### Responsible Design Keys are masked in the UI. Exact repo location and file path are shown for responsible disclosure. ### Live Dashboard Provider breakdown, scan statistics, and real-time job monitoring in a single view. ### Direct Links Every finding links directly to the exact file and line in the GitHub repository. right now ## Every second you wait, someone loses a key. No account. No setup. No API token required. Just open the scanner and watch real leaked AI keys surface from GitHub's public event stream — live, masked, and ready for responsible disclosure. [sekreets](https://sekreets.vercel.app/) Built with [habibthadev](https://www.habibthadev.tech/) For educational & defensive research only.
Genesis Park 편집팀이 AI를 활용하여 작성한 분석입니다. 원문은 출처 링크를 통해 확인할 수 있습니다.
공유