EnvFinder is a security research tool that helps identify accidentally exposed configuration files (.env files) in public github repositories to support responsible disclosure and defensive analysis.
- Clone the Repository
git clone https://github.com/RealGalaxyCat/env-finder- Go into the project directory
cd env-finder- Add an
.envfile and setGITHUB_PATto your personal access token
ℹ️ How do I generate a PAT?
Click on your Github avatar in the top right corner → Settings → Developer Settings → Personal access tokens → Tokens (classic) → Generate new token → select a classic tokenGITHUB_PAT=<your_pat>
- Start the service
docker compose upThis tool is intended for ethical security research and defensive analysis only.
Users are responsible for complying with:
- GitHub Terms of Service
- Applicable laws and regulations
- Responsible disclosure practices
Do not use this tool to access systems without authorization.
