exposure_check

shallow

app.openkrill/site-check · Verify this server

Checks what a site or app you own leaks publicly. Use it when the user asks what an attacker could find on a domain, host or app they own, for example "is anything on my domain example.com exposed?", "does my app leak a .env file or API keys in its JavaScript?", "check my server app.example.com for leaked admin or debug pages" or "run a leak check on my own site". Pass the domain, host or app page address; a bare IP address is refused. The first call returns ownership_not_proven with the DNS TXT record or the file to publish. Once that is live it returns exposed or clean, the top three risks with a fix for each, and the evidence: subdomains from certificate transparency that point at a missing target, leaked files such as a git folder or .env (never their contents), API keys in the page's own scripts (type, place and a six-character prefix only), public source maps, admin paths by status, development servers, default install pages and the https redirect. Every answer carries an ownership note. It sends GET requests only, to a fixed list of paths and at most 30 per run, does not crawl, does not try to sign in and does not scan ports. Do not use it on a target the user does not own, to look up a person, user name or email address, or for private or local addresses.

100.0/100

1 trials · measured 1 day ago

exposure_check scores 100.0/100 on Vouch's measured behaviour index, from 1 real invocation trials against app.openkrill/site-check, measured 6 Oct 2026 under methodology v0.2.0. Every measured component scored 100.

Component breakdown

ComponentWeightValue
Reliability35%not applicable
Schema integrity25%100.0
Failure behaviour15%not applicable
Latency15%not applicable
Concurrency10%not applicable

Tool details

Transport
remote
Credential class
self-provisionable
Input schema
not declared
Output schema
not declared
Side-effect classification
unclassified

Score history

DayScoreTierMethodology
2026-10-06100.0shallowv0.2.0

Probe evidence

ProbeOutcomes
schema_integritypass: 1

Raw request/response logs are not archived yet — the outcome counts above are drawn directly from every recorded trial.

Embed this score

Available for every tool, scored or not — not a verification perk. Always links back to this page.

Vouch score: exposure_check
[![Vouch score](https://vouch.tools/api/tools/80909688-a0a3-4ce1-bc29-ce420ed49d7b/badge.svg)](https://vouch.tools/tools/80909688-a0a3-4ce1-bc29-ce420ed49d7b)
exposure_check — Vouch