Leakhound app icon

Leakhound

Finds leaked secrets on your Mac — before someone else does.

A menu-bar app that keeps watching your home folder for API keys, plaintext passwords, unprotected SSH keys, malicious scripts, suspicious autostart items and what AI coding assistants leave behind. 100 % local — nothing leaves your Mac.

macOS 15 Sequoia or later · 34 languages · No account needed

Your Mac's quiet watchdog.

Runs in the menu bar, rechecks what changes, and tells you in plain words what to do.

Live monitoring

After the first full scan, Leakhound follows file changes via FSEvents and rechecks only what changed. A full scan repeats every 1 to 24 hours.

45 checks, 7 categories

Passwords, API keys and tokens, SSH keys, malicious scripts, autostart items, credential files and AI traces — each rated low to critical.

AI trace analysis

Finds secrets in Claude Code, Cursor or Copilot histories, risky agent permissions, and prompt injection hidden in CLAUDE.md or .cursorrules.

Explains and fixes

Every finding says why it matters and what to do. Wrong file permissions on keys and credential files are fixed with one click.

Touch ID lock

Findings show where your secrets live, so the dashboard is locked with Touch ID or your login password — and locks again when the screen locks or the Mac sleeps.

Widget & notifications

A desktop widget shows your security score and open findings. New critical and high findings arrive as a notification right away.

What it finds

The things that should never lie around.

Leakhound looks where developers, admins and everyday users actually leave secrets — in project folders, dotfiles, Downloads and on the Desktop.

Plaintext passwords

Password lists that belong in a password manager.

  • Files with entries like “Password: …” or credentials in URLs
  • File names that suggest a password list

API keys & tokens

Keys that let anyone act in your name — often at your cost.

  • AWS, GitHub, GitLab, Slack, Anthropic, OpenAI, Stripe live, Google, Hugging Face, npm and SendGrid keys, JSON Web Tokens
  • .env files with real values for SECRET, TOKEN, PASSWORD or API_KEY

SSH & private keys

The keys to your servers.

  • Private keys without a passphrase or readable by others
  • Keys outside ~/.ssh, an open ~/.ssh folder
  • Disabled host-key checking, agent forwarding, authorized_keys entries

Malicious scripts

Typical techniques of macOS malware and stealers.

  • curl … | sh, decoded Base64 being executed, remote eval, reverse shells
  • Fake password dialogs via AppleScript, redefined sudo, keychain dumps
  • Gatekeeper quarantine removal, PATH hijacking, disabled shell history

Autostart

Programs that start themselves at every login.

  • LaunchAgents and LaunchDaemons that start from /tmp, /Users/Shared or hidden folders
  • Autostart items that run shell one-liners or unsigned programs

Credential files

Tools that keep logins in plain text.

  • AWS, .netrc, git credentials, Docker, npm, PostgreSQL, PyPI, GitHub CLI, Kubernetes
  • Passwords and tokens in your shell history
  • Credential files readable by other users

AI traces

What coding assistants saw, ran and stored.

  • Secrets in AI histories and logs, sensitive files an agent read
  • Risky commands, access outside the project, keys in MCP configs
  • Bypass modes, unchecked MCP servers, prompt injection
AI traces

Your AI assistant remembers more than you think.

Coding agents read your .env, run shell commands and keep every session on disk — often with secrets in clear text. Leakhound analyses these local files and shows how much each tool stores, which sensitive files it read and what it ran.

  • Secrets that ended up in chat histories and logs
  • Risky agent commands: sudo, recursive deletes, chmod 777, force pushes, file uploads
  • Far-reaching permissions: bypassPermissions, YOLO mode, all shell commands allowed, hooks that load remote code
  • MCP servers started from /tmp, loaded unchecked via npx, or over plain http
  • Prompt injection in CLAUDE.md, AGENTS.md, GEMINI.md, .cursorrules & co.: hidden Unicode characters, suspicious instructions, instructions hidden in HTML comments
  • A timeline of Claude Code's file reads, writes, commands and web requests
Claude CodeClaude DesktopCursorVS Code / CopilotWindsurf / CodeiumOpenAI Codex CLIChatGPT DesktopGemini CLIContinueopencodeOllamaLM Studio
Critical

Secret stored in AI history

~/.claude/projects/…/session.jsonl · line 214
OPENAI_API_KEY=sk-••••••••••••

What to do: rotate the key, then delete the affected history or clean up AI data regularly.

Findings you can act on

Not just an alarm. A next step.

Each finding comes with a severity, the file and line, a masked snippet, a plain-language explanation of the risk and a concrete recommendation. Show it in Finder, fix permissions with one click, or ignore what you know is fine.

Findings in test and example folders are automatically rated low, so dummy keys don't drown out the real ones.

High

Private key readable by others

~/.ssh/id_ed25519

The file permissions allow other users or groups to read the private key.

Set permissions to 600Show in FinderIgnore
Medium

SSH key without passphrase

~/.ssh/id_rsa

Recommendation: set a passphrase with ssh-keygen -p and store it in the macOS keychain.

How it works

Everything happens on your Mac.

Leakhound never uploads files, findings or scan results. Secrets are shown masked, even to you.

1

Choose what to scan

Pick the places — your home folder, Desktop, Documents, Downloads, iCloud Drive — and the categories to check. Add your own exclusions any time.

2

First full scan

Leakhound walks the selected folders in parallel, skipping ~/Library, node_modules, .git, build folders and caches. It takes a few minutes the first time.

3

Watch and notify

From then on, changed files are rechecked within seconds and a full scan runs on your schedule. New critical or high findings trigger a notification.

Full Disk Access — optional, and why

macOS protects Desktop, Documents, Downloads and iCloud Drive. Without Full Disk Access, macOS asks you once for each folder you selected — nothing else is touched.

Granting Full Disk Access in System Settings covers all folders at once and additionally lets Leakhound check autostart items and some AI data. You can grant or revoke it at any time.

What stays, what goes

  • File contents, paths, findings and scan results never leave your Mac
  • Nothing is sent to AI services — AI data is analysed locally
  • No account; no network requests at all during the trial
  • With a license: a daily license check sends only the license key, a hashed device ID and the Mac's name to treeinspired.com (privacy policy)

Try everything. Then decide.

14 days with every feature, no card and no account. After that, one simple yearly price.

Free trial

14 days

Every feature, from the first launch.

  • All 45 checks in 7 categories
  • AI trace analysis
  • Live monitoring, widget, notifications
  • No card, no account, no network requests
Download trial

Secure payment by Stripe. Your license key appears right after payment and on every invoice email.
Already subscribed? Manage subscription · Refund on request within 14 days of your first purchase · Terms

Questions & answers

Does Leakhound upload my files or findings?

No. Every scan runs on your Mac. File contents, findings, paths and scan results never leave the device, and secrets are shown masked in the app. The only network request is the license check: when you activate a license and about once a day afterwards, Leakhound sends the license key, a hashed device identifier and the Mac's name to treeinspired.com. During the trial it makes no network requests at all.

Why does Leakhound ask for Full Disk Access?

It is optional. Without it, macOS asks separately before Leakhound may read Desktop, Documents, Downloads or iCloud Drive, and you only grant the folders you selected. With Full Disk Access, all folders are covered at once and Leakhound can additionally check autostart items and some AI data.

What happens after the 14-day trial?

The trial includes every feature and needs no card and no account. After 14 days you need a Leakhound Pro subscription to keep scanning: 29 per year (USD, CHF or EUR, shown in your local currency at checkout), for up to 3 Macs.

How do I get and enter my license key?

After payment, the confirmation page shows your license key, and it is also printed on every Stripe invoice email. Enter it in Leakhound to activate the Mac.

How do I cancel?

Anytime in the Stripe customer portal: Manage subscription. The cancellation takes effect at the end of the paid year. Within 14 days of your first purchase you can ask for a refund at info@treeinspired.com.

Can I move my license to another Mac?

Yes. A license works on up to 3 Macs at the same time. Deactivate it on one Mac in Leakhound to free the slot for another.

Which AI tools does Leakhound check?

Claude Code, Claude Desktop, Cursor, VS Code / GitHub Copilot, Windsurf / Codeium, OpenAI Codex CLI, ChatGPT Desktop, Gemini CLI, Continue, opencode, Ollama and LM Studio. Leakhound only reads their local files; it never sends anything to an AI service.

Is Leakhound an antivirus?

No. Leakhound finds exposed secrets and risky configurations using known patterns and flags typical malware techniques in scripts and autostart items. It complements, but does not replace, an antivirus or EDR product or a professional security audit.

Which languages does Leakhound speak?

34 languages, including English, German, French, Italian, Spanish, Portuguese, Dutch, the Nordic languages, Polish, Czech, Turkish, Russian, Ukrainian, Arabic, Hebrew, Hindi, Japanese, Korean and Chinese. The app follows your macOS language.

Why is Leakhound not in the Mac App Store?

A scanner that reads your whole home folder and watches it live does not fit inside the App Store sandbox. Leakhound is distributed directly, signed with treeinspired GmbH's Developer ID and notarized by Apple.

Find out what's lying around.

Free for 14 days. No card, no account.

Unzip and move Leakhound to Applications. It lives in your menu bar.

Notarized & signed by treeinspired GmbH · macOS 15 or later