Audit a project for leaked secrets (grep patterns across working tree AND git history), set up .env/.gitignore correctly, and run rotation when a key has leaked. Use when the user says "did I leak a key", "secret scan", "set up my .env", "I committed my API key", or before making a repo public. Don't use for checking what ships in the deployed client bundle — use vercel-deploy-check.