Bash outnumbers Read 10 to 1
1,344 Bash calls against 137 Reads. Everything that leaked through cat .env, printenv, git diff or curl carries no file path at all.
A scanner reading tool inputs never sees any of it.
Your coding agents logged every file they read and every command they ran, in plaintext, forever. spilled is a command-line scanner that finds the credentials sitting in those logs and tells you which ones still work, so you know exactly what to rotate.
Three steps, about a second, nothing to configure.
npx spilled in any terminal. No install, no signup, no API key. It reads only local files and makes no network calls.They parse Read(file_path=...) calls. Measured across 41 real sessions, that misses most of it.
1,344 Bash calls against 137 Reads. Everything that leaked through cat .env, printenv, git diff or curl carries no file path at all.
A scanner reading tool inputs never sees any of it.
Both ledgers are extracted: what the agent asked for, and what came back, including the parallel toolUseResult payload most parsers skip.
Content is then attributed back to your files.
A secret that leaked in July and was rotated in August is history. One still sitting in HEAD is an emergency.
The high-entropy sweep ships disabled. That is a decision, not a gap.
--paranoid.Agent transcript directories grow without bound and have no default cap. Reported cases reach multi-gigabyte sessions and disks filled entirely.
Shows total by agent, biggest sessions, and what is reclaimable.
Flags override attempts, role reassignment, prompt extraction, hidden HTML comments, pipe-to-shell and exfiltration instructions found in tool output.
A hijacked run completes successfully, so tests never catch it. The transcript is the only evidence.