Abstract
Keyleak Detector is an open-source Cybersecurity & Ethical Hacking project. Runtime leak detector for modern web apps — finds exposed API keys, validates BaaS misconfigurations (Supabase/Firebase RLS), and catches secrets in JS bundles. Chrome extension + CLI. Runtime leak detector for modern web apps. Finds exposed API keys, validates BaaS misconfigurations (Supabase RLS, Firebase Security Rules), and catches secrets in JavaScript bundles -- with a Chrome extension for real-time detection. It is built using Python, Firebase, JavaScript. Key capabilities include: Real-time BaaS detection: Probes Supabase/Firebase access and correlates anonymous Convex query results without invoking Convex functions; TEST button: Validates keys against 14 providers (Gemini, OpenAI, Anthropic, GitHub, Stripe, Groq, etc.); JWT decoder: Click TEST on any JWT to see decoded claims with severity flags. The complete source code is publicly available on GitHub under the MIT License, making it a useful reference for students building a Cybersecurity & Ethical Hacking mini project or final-year project.
1. Introduction
Runtime leak detector for modern web apps. Finds exposed API keys, validates BaaS misconfigurations (Supabase RLS, Firebase Security Rules), and catches secrets in JavaScript bundles -- with a Chrome extension for real-time detection.
Static scanners find hardcoded secrets in source code. KeyLeak finds the ones that only appear at runtime -- and then proves they're exploitable.
2. Objective
Runtime leak detector for modern web apps — finds exposed API keys, validates BaaS misconfigurations (Supabase/Firebase RLS), and catches secrets in JS bundles. Chrome extension + CLI.
This project demonstrates how Python, Firebase, JavaScript can be applied to a real-world Cybersecurity & Ethical Hacking problem.
3. Key Features / Modules
- Real-time BaaS detection: Probes Supabase/Firebase access and correlates anonymous Convex query results without invoking Convex functions
- TEST button: Validates keys against 14 providers (Gemini, OpenAI, Anthropic, GitHub, Stripe, Groq, etc.)
- JWT decoder: Click TEST on any JWT to see decoded claims with severity flags
- Finding grouping: Same key in multiple scripts = one card with clickable source URLs
- AIza classification: Distinguishes Google Maps keys (expected) from Gemini AI keys (leaked)
- 87 vendor CDN suppression: No false positives from Google Analytics, PostHog, Segment, etc.
- 200+ first-party domains: Google, Microsoft, AWS, Apple, Meta, Anthropic, Stripe -- their own keys on their own sites are never flagged
4. Technology Stack
5. System Requirements
General requirements for this technology stack — check the README for exact versions.
- Python 3.8 or later
- pip / virtualenv for dependencies
- VS Code, PyCharm or Jupyter Notebook
- Node.js (LTS) and npm
- A modern web browser
- VS Code or any code editor
- Git (to clone the repository)
6. Installation & Setup
git clone https://github.com/Amal-David/keyleak-detector.git
cd keyleak-detector# Scan a single page
keyleak browser-scan https://your-app.vercel.app --html > report.html
# Scan with BaaS validation (tests Supabase RLS, Firebase rules)
keyleak browser-scan https://your-app.vercel.app --baas-validate --html > report.html
# Full Site Scan — subdomain enumeration (subfinder/amass if installed + crt.sh + DNS) + multi-page crawl
keyleak site-scan example.com --depth 3 --max-pages 100 --max-subdomains 50 --baas-validate --html > report.html
# A deep scan auto-installs subfinder if it's missing (brew → pinned `go install`), then uses it;
# pass --no-auto-install (or set KEYLEAK_NO_AUTO_INSTALL=1) to stay on crt.sh + DNS only.
# amass is also auto-used if present. `keyleak doctor` reports which enumerators are active.
# Scan local files for secrets
keyleak local . --fail-on high
# Output formats: --json, --sarif, --markdown, --htmlgit clone https://github.com/Amal-David/keyleak-detector.git
cd keyleak-detector
docker compose up -dpoetry install
poetry run playwright install chromium
poetry run python app.pypython3.12 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txt
pip install -e .
python -m playwright install chromium
python app.pyFull setup instructions are in the project README.
7. Future Enhancements
Suggested extensions you can add to make this your own project.
- Add logging and alert notifications (email / Telegram)
- Write a threat model document for the tool
- Package it with Docker for safe lab testing
8. Viva / Review Questions
Common questions examiners ask for projects in this domain.
- Which threat or attack does this project defend against?
- What detection or protection technique is used and what are its limits?
- How are false positives and false negatives handled?
- Which cryptographic algorithms or security standards are involved?
- What legal and ethical rules apply when testing a tool like this?
9. Source Code & License
This project is developed by Amal-David and published on GitHub under the MIT License. Please follow the license terms and credit the original author when you use or modify this code.
Want to build this as your internship project?
Work on a Cybersecurity & Ethical Hacking project like this with mentor guidance, weekly reviews and an internship certificate from Training Trains, Erode — online or offline.
Apply for Cybersecurity & Ethical Hacking Internship