The catalog · Dev tools

Promptleak

Find the secret in the prompt

Next.js + PostgresDifficulty 2/5Suggested $25/moTeams shipping agents
Smoke-tested to a running MVP, or we fix it. No card to start.
83
UIQ score
GO
Build Promptleak · free to start, no card
1
Pick a scored ideaEach idea is graded 0 to 100 with the full case that earned the number, so you build on evidence.
2
Build it with your agentA ten-phase kit feeds your coding agent one prompt at a time, from empty folder to a running MVP.
3
Launch and get paidShip it live, then the launch kit helps you land the first users who prove it.

Problem

Secrets end up in prompts. An engineer pastes a config to debug, an agent reads an env file and includes it in context, a log captures the lot. The key is now in a third party's logs, and rotating it requires knowing it happened, which nobody does.

Why now

Agents read local files as a matter of course now, which means the path from a project's .env to a third party's logs is one careless tool call. That path did not exist before 2025, and it is now the default shape of a coding session.

Solution

It sits on the way out. Prompts and tool outputs are scanned for credential shapes before they leave the machine, and a match is blocked and reported rather than logged. The engineer finds out at the moment it would have leaked.

Who it is for

Any team whose agents can read the filesystem, which is now most of them. The person who feels it is the engineer who realised that the path from a project's env file to a third party's logs is a single careless tool call. They cannot rotate what they do not know leaked, and that is the part that keeps them up: the failure is silent by design.

What you could earn from Promptleak

Say you build Promptleak and charge your own customers $25 a month, the price the score suggests. The numbers below are the revenue that would come from them. This is money you earn, never a fee you pay UpgradIQ, and we never take a cut. It is arithmetic off the price, not a promise the customers arrive on their own.

10customers paying you $25/mo$250/moyou earn · $3,000 a year
50customers paying you $25/mo$1,250/moyou earn · $15,000 a year
100customers paying you $25/mo$2,500/moyou earn · $30,000 a year

See what Promptleak produces

It sits on the way out. Prompts and tool outputs are scanned for credential shapes before they leave the machine, and a match is blocked and reported rather than logged. The engineer finds out at the moment it would have leaked.

Promptleak · egress scan
TimeSourceDetectedMatchAction
09:14agent · OpenAIAWS access keyAKIA...7F2QBlocked
09:22tool outputStripe secretsk_live...9cBlocked
09:31agent · log lineBearer tokeneyJhb...a1Blocked
09:40agent · OpenAINonecleanAllowed
3 blocked before egress0 leaked
Scanned on the way out · blocked and reported, never loggedSee the rules

Your build kit for Promptleak

Start the build and the kit opens two steps in, then drip-feeds the rest one phase at a time. Every phase is a copy-paste prompt for your agent with its own verification before the next unlocks, so Promptleak moves from an empty folder to a running MVP without you ever holding the whole plan in your head.

Progress saves across every device, and the workspace always reopens on the exact step you left, so a build that runs over several weeks survives them instead of dying in a browser tab you eventually close.

Idea and stack are already checked, so you open at 2 of 10
10phases to MVP
2/5difficulty
Next.jsprimary stack
Promptleak · build kit
Idea chosenDone
Stack selectedDone
3Scaffold the stackNext up
4Data model and sign-inLocked
5Core feature, end to endLocked
6Monetization wiringLocked
7Test and hardenLocked
8Polish and deployLocked
9Launch-day toolkitLocked
10First 10 usersLocked

How you actually build it

Connect your coding agent once. It pulls the current phase straight from your kit over MCP: the exact prompt, the outcome to aim for, and the check to run before it moves on. You review and ship, it does the typing.

No copy-paste juggling, no thread to lose. The kit stays the single source of truth, and your agent works through it one phase at a time, verifying its own work at each step before the next phase is unlocked.

Start free, run phase 1Free account, no card. The first phase prompt unlocks the moment you start, right in your workspace.
agent · MCP
$ get_current_phase promptleak
Phase 3 of 10: Scaffold the stack
Outcome: The project builds, runs locally, and its health route answers 200.
Check: Run the dev server. `curl` the health route and show the 200. Run the build and show it passing with zero type errors. Confirm `.env` is gitignored: `git status` must not list it.
building · scaffolding Next.js, the data layer, the health check
dev server up · /api/health returns 200 · build passes
$ mark_phase_complete scaffold
Done · 30% complete · next: Data model and sign-in
phase 4 unlocked · the agent asks for the next prompt

Take the context file, free

This is the AGENTS.md that keeps your coding agent on scope for the entire build: what Promptleak is, who it is for, the stack, the non-goals, and the rules it must follow. Copy it into your project now, no account needed, and your agent is briefed before you write a line.

AGENTS.md · promptleak
# Promptleak

Find the secret in the prompt

## What this is
It sits on the way out. Prompts and tool outputs are scanned for credential shapes before they leave the machine, and a match is blocked and reported rather than logged. The engineer finds out at the moment it would have leaked.

## The problem it solves
Secrets end up in prompts. An engineer pastes a config to debug, an agent reads an env file and includes it in context, a log captures the lot. The key is now in a third party's logs, and rotating it requires knowing it happened, which nobody does.

## Who it is for
Any team whose agents can read the filesystem, which is now most of them. The person who feels it is the engineer who realised that the path from a project's env file to a third party's logs is a single careless tool call. They cannot rotate what they do not know leaked, and that is the part that keeps them up: the failure is silent by design.

## Stack
Next.js + Postgres

## Non-goals
Do not build features outside the core job above. This product exists to do one
thing well. Every extra feature is a reason it does not ship.


## Rules for the agent
- Build one phase at a time. Do not run ahead into later phases.
- Validate input at every boundary where data enters.
- Never put a permission or plan check in client code.
- Ask before adding a dependency that a few lines would cover.
- If something is ambiguous, say so rather than inventing a requirement.

---
Context file from UpgradIQ · idea promptleak · prompts kit-v4

Then start free to get the ten-phase kit and run the first prompt.

The path to a running MVP

Phases 1-4

Foundation

Scaffold the stack, then wire the data model and sign-in. It is the skeleton Promptleak stands on, and it goes up in an evening rather than a lost week of config.

Phases 5-6

The product

Build the core feature end to end, then wire how it charges. This is where Promptleak finally turns into something that a stranger will actually pay you for.

Phases 7-10

Ship it

Test and harden, deploy it live, then open the launch-day toolkit that lands the first ten users who prove it.

Is Promptleak for you?

A good fit if
  • You want revenue reasonably soon, not a science project
  • You can give it evenings and a couple of weekends
  • You can reach Teams shipping agents
You have read the free case, the hard part4 of 7 sections done

The 3 sections that decide whether you should actually build it, plus the full kit, are one click away.

Pro

3 more sections decide whether you build Promptleak

You have the case and the plan. Pro opens how it makes money, the one risk that kills it, and the build notes, plus the 10-phase kit that takes Promptleak to a running MVP, on this idea and all 200.

How it makes money

Main risk

Build notes

What is free here, and what Pro unlocks

The problem, timing, solution and buyerFree
How it makes money, priced and modelledPro
The full UIQ 83 and all eight sub-scoresFree
The one risk most likely to kill itPro
Stack, difficulty and suggested priceFree
The 10-phase kit to a running MVPPro

Frequently asked

Is Promptleak actually validated?

It scored UIQ 83 with a GO verdict, weighed across eight sub-scores on the same rubric as every idea. GO means 75 and above, so demand and buildability were judged, not guessed.

What stack does it use?

Promptleak is built on Next.js + Postgres, chosen because a coding agent can carry most of it. You are not fighting infrastructure, you are shipping the feature that matters.

How long to a running MVP?

The kit is ten phases, drip-fed one at a time so you always know the single next step. An evening and a weekend for the lighter builds, a few focused weeks for the deeper ones.

What does the $25 a month mean?

It is the price the model suggests Promptleak could charge its own customers, not a fee to us. It is here so the money question is answered before you build, not after.

Which agent do I need?

Any capable coding agent: Claude Code, Cursor, Lovable, or Bolt. Every phase is a copy-paste prompt with its own check, so the agent does the typing and you keep the judgement.

What is free versus Pro?

The whole case above is free: the problem, timing, solution, buyer, and the full score. Pro adds how it makes money, the one risk that could kill it, and the full kit that carries Promptleak from an empty folder to a running MVP.

More like Promptleak

All 25 Dev tools ideas
3 more sections

Build Promptleak, not just read about it

You have the problem, the timing, the solution and the buyer. A plan opens how it makes money, the risk that kills it, and the kit that takes it to a running MVP.

Start building Promptleak
Today's idea is free, no account