Wow, that is pretty scary! I'm glad you handled it ethically and you reached out to the person who owns the keys. I don't think my stuff is that in depth, but it definitely has me thinking I need to check out my github to make sure I haven't done something similar.
RE: Seek and ye shall find. You should not publish private API keys publicly in your Github repo.