- frontier.yaml: 15 dorks covering Tier 1/2 providers (OpenAI, Anthropic, Google AI, Azure OpenAI, AWS Bedrock, xAI, Cohere, Mistral, Groq, Together, Replicate) - specialized.yaml: 10 dorks covering Tier 3 providers (Perplexity, Voyage, Jina, AssemblyAI, Deepgram, ElevenLabs, Stability, HuggingFace) - Extend loader to accept YAML list format in addition to single-dork mapping, enabling multi-dork files for Wave 2+ plans - Mirror all YAMLs into dorks/github/ (user-visible) and pkg/dorks/definitions/github/ (go:embed target)
106 lines
3.6 KiB
YAML
106 lines
3.6 KiB
YAML
- id: openai-github-envfile
|
|
name: "OpenAI Project Key in .env files"
|
|
source: github
|
|
category: frontier
|
|
query: 'sk-proj- extension:env'
|
|
description: "Finds OpenAI project keys exposed in committed .env files"
|
|
tags: [openai, env, tier1]
|
|
- id: openai-github-pyfile
|
|
name: "OpenAI Project Key in Python files"
|
|
source: github
|
|
category: frontier
|
|
query: 'sk-proj- extension:py'
|
|
description: "Finds OpenAI project keys hard-coded in Python source"
|
|
tags: [openai, python, tier1]
|
|
- id: openai-github-jsonfile
|
|
name: "OpenAI Project Key in JSON files"
|
|
source: github
|
|
category: frontier
|
|
query: 'sk-proj- extension:json'
|
|
description: "Finds OpenAI project keys in JSON configs and fixtures"
|
|
tags: [openai, json, tier1]
|
|
- id: anthropic-github-envfile
|
|
name: "Anthropic API Key in .env files"
|
|
source: github
|
|
category: frontier
|
|
query: 'sk-ant-api03- extension:env'
|
|
description: "Finds Anthropic Claude API keys exposed in committed .env files"
|
|
tags: [anthropic, env, tier1]
|
|
- id: anthropic-github-pyfile
|
|
name: "Anthropic API Key in Python files"
|
|
source: github
|
|
category: frontier
|
|
query: 'sk-ant-api03- extension:py'
|
|
description: "Finds Anthropic Claude API keys hard-coded in Python source"
|
|
tags: [anthropic, python, tier1]
|
|
- id: google-ai-github-envfile
|
|
name: "Google AI Studio Key in .env files"
|
|
source: github
|
|
category: frontier
|
|
query: 'AIzaSy extension:env "GOOGLE_API_KEY"'
|
|
description: "Finds Google Generative AI / Gemini keys in .env files"
|
|
tags: [google, gemini, env, tier1]
|
|
- id: google-ai-github-jsonfile
|
|
name: "Google Generative Language Key in JSON"
|
|
source: github
|
|
category: frontier
|
|
query: 'AIzaSy extension:json "generativelanguage"'
|
|
description: "Finds Gemini keys adjacent to generativelanguage.googleapis.com references"
|
|
tags: [google, gemini, json, tier1]
|
|
- id: azure-openai-envfile
|
|
name: "Azure OpenAI Key in .env files"
|
|
source: github
|
|
category: frontier
|
|
query: 'AZURE_OPENAI_KEY extension:env'
|
|
description: "Finds Azure OpenAI deployment keys in .env files"
|
|
tags: [azure, openai, env, tier1]
|
|
- id: aws-bedrock-envfile
|
|
name: "AWS Bedrock Access Key in .env files"
|
|
source: github
|
|
category: frontier
|
|
query: 'AKIA extension:env "bedrock"'
|
|
description: "Finds AWS access keys adjacent to Bedrock references in .env files"
|
|
tags: [aws, bedrock, env, tier1]
|
|
- id: xai-envfile
|
|
name: "xAI Grok Key in .env files"
|
|
source: github
|
|
category: frontier
|
|
query: 'xai- extension:env'
|
|
description: "Finds xAI Grok API keys in .env files"
|
|
tags: [xai, grok, env, tier2]
|
|
- id: cohere-envfile
|
|
name: "Cohere API Key in .env files"
|
|
source: github
|
|
category: frontier
|
|
query: 'COHERE_API_KEY extension:env'
|
|
description: "Finds Cohere API keys in .env files"
|
|
tags: [cohere, env, tier2]
|
|
- id: mistral-envfile
|
|
name: "Mistral API Key in .env files"
|
|
source: github
|
|
category: frontier
|
|
query: 'MISTRAL_API_KEY extension:env'
|
|
description: "Finds Mistral platform keys in .env files"
|
|
tags: [mistral, env, tier2]
|
|
- id: groq-envfile
|
|
name: "Groq API Key in .env files"
|
|
source: github
|
|
category: frontier
|
|
query: 'gsk_ extension:env'
|
|
description: "Finds Groq API keys (gsk_ prefix) in .env files"
|
|
tags: [groq, env, tier2]
|
|
- id: together-envfile
|
|
name: "Together AI API Key in .env files"
|
|
source: github
|
|
category: frontier
|
|
query: 'TOGETHER_API_KEY extension:env'
|
|
description: "Finds Together.ai inference keys in .env files"
|
|
tags: [together, env, tier2]
|
|
- id: replicate-envfile
|
|
name: "Replicate API Token in .env files"
|
|
source: github
|
|
category: frontier
|
|
query: 'r8_ extension:env'
|
|
description: "Finds Replicate API tokens (r8_ prefix) in .env files"
|
|
tags: [replicate, env, tier2]
|