gotr00t0day / KeyReaper
PublicExtract and assess exposed Google Cloud (AIza) API keys from web pages. Built for bug bounty hunters and security researchers.
KeyReaper scans websites for exposed Google Cloud credentials and assesses their access to various services like maps, AI, and vision for security research.
How It Works
You notice some websites might have accidentally left secret access codes visible to anyone.
Download the straightforward scanning tool to your computer.
Prepare a single web address or a list of pages you want the tool to examine.
Hit start and watch it comb through the pages and connected files for hidden codes.
Get a clean list of all found codes right away.
Test each code against popular services like maps, AI, and search to see the risks.
Review which codes were found and exactly what powerful features they can reach.
Save your report and share it with site owners to fix the exposure and earn rewards.
Star Growth
Repurpose is a Pro feature
Generate ready-to-use prompts for X threads, LinkedIn posts, blog posts, YouTube scripts, and more -- with full repo context baked in.
Unlock RepurposeSimilar repos coming soon.