{"slug": "show-hn-i-found-api-keys-in-my-coding-agent-history-so-i-built-agent-scrub", "title": "Show HN: I found API keys in my coding agent history so I built Agent Scrub", "summary": "A developer released Agent Scrub, a macOS 14+ menu-bar tool that scans and redacts plaintext API keys, tokens, and other secrets stored in the local conversation history of AI coding agents including Claude Code, Codex, Gemini CLI, Cursor, GitHub Copilot, Windsurf, Cody, Cline, Aider, Continue, and Pi. Agent Scrub performs all scanning and redaction locally with no data uploaded, only touching conversation-related files such as prompts, transcripts, tool output, and saved memory while deliberately leaving credential and configuration files like Codex auth.json, Continue config.yaml, and project .env files untouched. The unsigned app is distributed as a universal Apple Silicon/Intel build via GitHub Releases and requires an xattr command to clear the macOS quarantine flag before launch.", "body_md": "Find and remove secrets stored in AI coding-agent history files.\n\nAI coding tools such as Claude Code, Codex, Cursor, and others store local conversation history, including prompts, transcripts, and tool output. These files can sometimes contain API keys, tokens, and other secrets in plaintext.\n\nAgent Scrub scans these local history files, identifies potential secrets, and can redact them in place. All scanning and redaction happens locally. No data is uploaded.\n\nAgent Scrub can detect and redact multiple copies of the same secret across an agent's history.\n\n- Claude Code\n- Codex\n- Gemini CLI\n- Cursor\n- GitHub Copilot\n- Windsurf\n- Cody\n- Cline\n- Aider\n- Continue\n- Pi\n- VS Code forks that use the same chat storage format\n\nAgent Scrub only scans conversation-related files, including:\n\n- Prompts\n- Transcripts\n- Tool output\n- Saved memory\n\nIt does not scan or modify configuration or credential files. Examples of files it will **not** touch:\n\n- Codex `auth.json`\n- Continue `config.yaml`\n- Project `.env` files\n- Editor secret storage\n- Other files used by tools to store active credentials\n\nThis separation is intentional. A secret stored in a transcript is an additional copy of that secret. Removing the transcript copy does not affect the credential the tool uses for authentication. Agent Scrub only redacts copies found in conversation history — it does not modify active credentials.\n\nIf you want to inspect the potential impact of a leaked credential, you can also use\n[geiger](https://github.com/puck-security/geiger), a read-only tool for checking what a credential may have\naccess to.\n\nRequires macOS 14 or later.\n\nDownload the latest `AgentScrub-*.zip` from [GitHub Releases](https://github.com/thesubtlety/agent-scrub/releases/latest), unzip it, then run:\n\n```\nxattr -dr com.apple.quarantine AgentScrub.app\nopen AgentScrub.app\n```\n\nAgent Scrub is currently unsigned, so macOS may quarantine the downloaded app. The `xattr` command removes\nthat quarantine flag. You can also right-click the app and choose **Open → Open**.\n\nRelease builds are universal and support both Apple Silicon and Intel Macs.\n\nRequires Xcode 16 and Swift 6.\n\n```\n./tools/app/bundle.sh\nopen .build/AgentScrub.app\n```\n\nOn first launch, Agent Scrub may request access to Keychain and local files.\n\nAgent Scrub creates a random per-install key and stores it in your login Keychain. This key is used to\nfingerprint detected secrets so Agent Scrub's own database does not need to store secret values in plaintext.\nIt only accesses its own Keychain item. Choosing **Always Allow** prevents repeated Keychain prompts.\n\nAgent Scrub needs permission to read the local history files created by supported coding agents. macOS may show permission prompts for locations such as Documents, Desktop, or Downloads; these are required if agent history is stored there. All processing remains local.\n\nAgent Scrub runs from the macOS menu bar. It scans on launch and continues monitoring supported history locations for changes.\n\n**Overview** — detected secrets grouped by type, project, and application, along with lifetime totals.\n\n**Discovered secrets** — each detected secret and the files where copies were found. Available actions:\n\n- **Reveal** — show the detected value.\n- **Decode JWT** — inspect the contents of a detected JWT.\n- **Redact now** — replace detected copies with a`[REDACTED:…]` marker.\n- **Always redact** — automatically redact the secret if it appears again.\n- **Not a secret / Keep** — dismiss the finding or leave it unchanged.\n\n**Coverage** — files or locations that could not be scanned and the reason they were skipped. You can also\nexclude folders that you do not want Agent Scrub to scan.\n\nRedaction modifies the original history files and cannot be undone automatically. Before and after writing a change, Agent Scrub re-checks and re-parses the affected file. Files that appear to be actively written by an agent are skipped temporarily and retried after the session ends.\n\nAgent Scrub can only remove local copies that still exist on your Mac. It cannot remove data that has already been sent to a provider or copied into backups.\n\n`hgctl` provides command-line access to the same operations — scanning, redaction, verification, policies,\nand enforcement. Write operations are dry runs by default unless `--yes` is provided.\n\n```\nswift run hgctl scan\n```\n\nAgent Scrub does not make network connections. All scanning, state, and redaction remain on your Mac.\n\nApplication state is stored in `~/Library/Application Support/History Guard` (detected findings and your\nkeep/redact decisions), the fingerprinting key in your login Keychain, and excluded folders in application\npreferences. To remove Agent Scrub completely, delete:\n\n- The Agent Scrub application\n- `~/Library/Application Support/History Guard`\n- The `io.adversis.history-guard` Keychain item\n\nBuild and test:\n\n```\nswift build && swift test\n```\n\nTo publish a release:\n\n```\ngit tag v1.0.0\ngit push --tags\n```\n\nPushing a version tag triggers CI to build the universal `.app` and publish it to GitHub Releases.", "url": "https://wpnews.pro/news/show-hn-i-found-api-keys-in-my-coding-agent-history-so-i-built-agent-scrub", "canonical_source": "https://github.com/thesubtlety/agent-scrub", "published_at": "2026-10-02 22:53:12+00:00", "updated_at": "2026-10-02 23:06:17.293290+00:00", "lang": "en", "topics": ["ai-tools", "ai-agents", "developer-tools", "ai-safety"], "entities": ["Agent Scrub", "Claude Code", "Codex", "Cursor", "GitHub Copilot", "Gemini CLI", "Windsurf", "geiger"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/show-hn-i-found-api-keys-in-my-coding-agent-history-so-i-built-agent-scrub", "markdown": "https://wpnews.pro/news/show-hn-i-found-api-keys-in-my-coding-agent-history-so-i-built-agent-scrub.md", "text": "https://wpnews.pro/news/show-hn-i-found-api-keys-in-my-coding-agent-history-so-i-built-agent-scrub.txt", "jsonld": "https://wpnews.pro/news/show-hn-i-found-api-keys-in-my-coding-agent-history-so-i-built-agent-scrub.jsonld"}}