Docs menuLeak sweep

Docs / Leak sweep

Leak sweep

Find the secrets agents left behind, and how exposed each one is.

Where it reads

Agents leave secrets behind. A key pasted into a prompt stays in the transcript. A token written into an MCP config stays in that file. flanner curb sweep looks in the places agents keep things, and says how exposed each secret is.

flanner curb sweep
  • Claude Code transcripts
  • Codex sessions and prompt history
  • CLAUDE.md and AGENTS.md, your own and the project's
  • Skills
  • MCP configs, Claude Code settings and Codex config
  • Shell history: bash, zsh, fish and PowerShell
  • The project's .env files
  • flanner's own plans and memories

--dir names the project folder to sweep, beside the agents' own files. It is this folder if left out. Two things are not read: plans kept in a folder other than .plans, and files over 64 MB, which are counted under “Not checked”.

It needs an extra

Detection is Kingfisher, an open-source secret scanner. It comes as an optional extra, and it scans offline. Install it into the same Python environment flanner runs in:

pip install 'flanner[sweep]'

Exposure classes

Each secret counts once, in its worst class.

A

Sent to a model provider

It is in a transcript, so it has already left this machine. Rotate it now.

B

Readable by an agent

Some agent launch here can read the file through a channel no control covers, by the same check flanner curb map makes. Rotate it, or move it where no agent can read it.

C

On disk but blocked

No agent launch here can read it today.

Only counts are printed: secrets by class, and where they were found by kind of file. --json gives the same counts. No command prints a secret's value, and no value is kept.

flanner curb show --sweep

Opens each finding's type, file and line in a window on this machine's screen. Never the value. Nothing from the window is printed.

Asking the issuer

A found key may be long dead. --validate asks each secret's own issuer whether it still works. It works on sweep and on show --sweep.

Curb asks you first, on every run, and the default answer is no. A yes sends each secret found to the issuer its type names, and nowhere else. flanner never receives it.

Without --validate, nothing leaves the machine.

What is kept

A redacted copy of each report is kept on this machine for 30 days. It holds the counts and, for each finding, its class, the kind of file, the rule that matched and two fingerprints. Never a value, a file name or a location.

A fingerprint is a keyed digest: an HMAC-SHA256 under a key made on this device, cut to 16 bytes. It can be matched again on this device and cannot be reversed. The key is kept in the OS keychain, or in a user-only file where there is none, and never leaves the device.

flanner curb forget

Deletes what Curb keeps on this machine: the stored reports, the tester's decoys and its proofs, the action log, the fingerprint key. It asks first; --yes skips the question. Older fingerprints can no longer be matched afterwards.

Settings backups are asked about separately, because they are the only undo for a fix. With --yes, add --backups to delete them too.

Scrubbing a file

Rotate a leaked secret first. Scrubbing hides a secret on this machine. It cannot unsend one. Once the old value is dead, this takes its copies out of one file:

flanner curb scrub FILE --dry-run

Checks that the file can be scrubbed, and says how many secrets on how many lines. Changes nothing.

flanner curb scrub FILE

Replaces each secret the sweep finds in FILE with a placeholder of the same length. Asks your operating system for a yes first.

flanner curb show --sweep shows which files hold a secret. Scrubbing needs the same extra as the sweep.

The file is swapped in with one rename, and only if every check passes. Each changed line must still parse the way it did: a line of JSON, a whole JSON, TOML or YAML file, or an assignment in a .env file. No copy of the secret may remain, even an escaped one. And the file must not have changed since Curb read it. If any check fails, the file is left exactly as it was.

There is no undo. No backup is kept, because a backup would be another copy of the secret. This is the one change Curb makes that it cannot put back, which is why an approval is asked for each file.