Sept. 22, 2026
Leakhound: the secrets your Mac is quietly keeping
Blog · 22 September 2026 · Product
Most leaked credentials were never stolen. They were simply left lying around — in a forgotten .env, in a note on the Desktop, in a shell history. Leakhound is our new menu-bar app for macOS that goes looking for them before somebody else does.
Why we built it
We write software for a living, and over the years we have watched the same small accidents happen again and again. A private key copied out of ~/.ssh "just for a minute". A password list saved as a text file because the password manager was two clicks away. A production token pasted into a scratch file during a late debugging session.
None of that is carelessness. It is what work looks like under time pressure. The problem is that these files stay. They outlive the project, the laptop is handed on, a backup ends up in the wrong place — and a key that was meant to live for an afternoon is still valid two years later.
What changed: the assistants
Something new has been added in the last two years. Coding assistants read your files, run shell commands and keep every session on disk. That is what makes them useful. It also means a second copy of your secrets now exists in a chat history you never think about.
Leakhound analyses these local files and shows, per tool, how much it stores, which sensitive files it read and what it ran. It looks for secrets that ended up in histories and logs, for risky agent commands, for permissions that were set far too wide, and for MCP servers loaded unchecked over plain HTTP.
It also reads the instruction files — CLAUDE.md, AGENTS.md, .cursorrules and their relatives — for prompt injection: hidden Unicode characters, instructions tucked into HTML comments, text written to steer an assistant rather than a human. Supported today are Claude Code, Claude Desktop, Cursor, VS Code / Copilot, Windsurf, OpenAI Codex CLI, ChatGPT Desktop, Gemini CLI, Continue, opencode, Ollama and LM Studio.
Eight categories, one score
Beyond AI traces, Leakhound checks plaintext passwords, API keys and tokens, SSH and private keys, malicious scripts, autostart items, credential files, and the network side: which services are listening, which processes talk to the outside, and whether they are signed.
After the first full scan it keeps watching. File changes are picked up through FSEvents and rechecked within seconds; a full scan repeats on a schedule you set. New critical and high findings arrive as a notification, and the menu-bar icon changes colour.
A finding you can act on
An alarm without a next step is just noise. Every finding carries a severity, the file and line, a masked snippet, a plain-language explanation of why it matters, and a concrete recommendation. Wrong file permissions on keys and credential files are fixed with one click. Findings in test and example folders are rated low automatically, so dummy keys don't drown out the real ones.
Because the dashboard shows where your secrets live, it is locked behind Touch ID — and locks again when the screen locks or the Mac sleeps.
Nothing leaves your Mac
This is the part we care about most. File contents, paths, findings and scan results never leave the device. Nothing is sent to an AI service; the AI data is analysed locally. During the trial, Leakhound makes no network requests at all.
With a licence there is exactly one: a daily check that sends the licence key, a hashed device identifier and the Mac's name to treeinspired.com. That is the complete list, and it is spelled out in our privacy policy.
Try it
Fourteen days with every feature, no card and no account. After that, Leakhound Pro is USD/CHF/EUR 29 per year for up to three Macs. It needs macOS 15 Sequoia or later and speaks 34 languages.