AI Leak Checker

Catches API keys and secrets before you send them to ChatGPT

Visit Website
May 16, 2026 I shipped a Chrome extension in December and told nobody about it for 5 months

I'm a QA engineer. No computer science degree, no formal development background. I've spent most of my career breaking other people's software rather than building my own.

But over the last year I've been learning to build with AI tooling, and just after Christmas I actually shipped something to the Chrome Web Store. A real extension, with 200+ unit tests, TypeScript, the works. I've been using it myself every day since.

And then I told absolutely nobody about it for five months.

The extension is called AI Leak Checker. It scans what you type into ChatGPT and Claude in real time and warns you before you hit send if it detects something sensitive — API keys, AWS credentials, GitHub tokens, .env file contents, PII, that kind of thing. Everything runs locally, nothing leaves your browser, fully open source.

The reason I built it is embarrassingly simple. I kept watching developers — including myself — paste things into AI chat windows at speed without really thinking about what was in there. A config snippet with a real token. An error log with database credentials in the stack trace. There's no native protection for any of it.

So I built one.

The reason I didn't tell anyone for five months is less simple. Imposter syndrome mostly. I'm not a "real" developer and I used AI heavily to build it, and I had this fear of being called out by someone more technical who'd want me to explain exactly how something worked under the hood. I also kept thinking the UI wasn't polished enough, the feature set wasn't complete enough, Gemini support wasn't done yet.

What finally got me to post about it was honestly someone asking me a simple question: is this good enough that a stranger would find it useful? And the answer was yes. It was always yes.

So here I am. Five months late.

Currently free, Gemini support coming soon, Stripe integration is next on the list. If you're a developer who's ever felt that split-second panic after hitting send on a prompt — this is for you.

Chrome Web Store: https://chromewebstore.google.com/detail/ffdmphfcipjmoochiafeihceiodehjcc GitHub: https://github.com/laypal/ai-leak-checker

Honest feedback welcome. Especially the brutal kind.

Comment

About

I kept seeing developers paste .env files and API keys into AI chats without thinking. No native warning exists for any of it. I'm a QA engineer who built this to scratch my own itch.