Are there any tools that can scan all the users of an org for such credential leaks?
You should better review stuff that you publish. That includes commit review, package contents review before publishing them, config files review, logs review before sharing them.
If you have an org — it would better to educate your devs more and make each commit go through an independent review. Also, don't forget about checking package contents.
Naturally anyone can become dependent on anything designed to assist them. I'm not really passionated about either direction really.