Paths, bytes, hashes, redacted pattern matches, policy decisions, and reopened output contents.
LOCAL ARCHIVE X-RAY
Your repo has a .env shadow.
LOCAL PARSER STARTING
Inspect what an archive contains before a coding tool can. Source bytes never leave this tab.
Open the evidence
No saved auditPreparing deterministic sample…
ZIP paths normalized2 MB text inspection capSHA-256 evidence
Exposure surface
No archiveFILES
BYTES
FINDINGS
CRITICAL
critical
history/context
metadata
retained
Redacted evidence
Run the sample or select a ZIP to inspect real archive bytes.
CLAIM BOUNDARY
Archive evidence is not network proof.
Repo Exposure Lab proves what exists inside the ZIP you provide, which paths match sensitive classes, and what the generated copy excludes. It does not inspect an installed coding tool, observe traffic, or establish what any vendor uploads.
High-entropy candidates and broad credential assignments can be false positives; inspect the path and rule.
Network destinations, request payloads, retention, model training, and product-version behavior need traffic or product telemetry.
Does a clean ZIP prove nothing was uploaded?
Choose the claim you can defend.