Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
agent-sweep — Find and redact secrets in AI coding agent histories (Claude Code, and more). | Kitploit
Tools/GitHubGitHub/ishannaik/agent-sweep
Data ExfiltrationForensicsData RecoverySecret DetectionSupply Chain SecurityIncident Response
GitHubishannaik/agent-sweep

agent-sweep

Find and redact secrets in AI coding agent histories (Claude Code, and more).

View Repository
57381923 days agoReviewed by Kitploit

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

AgentSweep

AgentSweep

Find and redact secrets in your AI coding agent's local history. Fully offline.

PyPI version PyPI downloads CI License: MIT Python 3.11+ Offline GitHub Stars Visitors

Prevention: Don't paste API keys into cloud-backed AI agents at all — the key transits the provider's servers before it ever hits your disk.

If you already did: agentsweep removes the remaining local attack vector — supply-chain malware and compromised packages that scan your disk for credentials. Your files never leave your machine.


29 agents supported: Claude Code · Codex · OpenCode · Cursor · Windsurf · Aider · Cline · Kilo Code · Roo Code · PearAI · Trae · Void · Gemini CLI · Qwen Code · Continue · Open Interpreter · GitHub Copilot Chat · OpenClaw · Hermes · Goose · Warp · Grok CLI · Kiro CLI · Zed · Codebuff · Plandex · Junie · Mentat · JetBrains AI

Experimental sources (Warp, Grok CLI, Kiro CLI, Zed, Codebuff, Plandex, Qwen Code, PearAI, Trae, Void, Junie, Mentat, JetBrains AI) have storage paths/formats derived from research but not yet verified against a real install. Scanning is safe — a wrong path simply finds nothing — but they may under-report until confirmed. They're tagged (experimental) in the picker and print a notice on scan.

191 detection rules — AWS, GitHub, Stripe, OpenAI, Anthropic, Google, Slack, Discord, HuggingFace, JWT, PEM keys, DB URLs, BIP-39 seed phrases, and many more

Alpha — every destructive step is gated, backed up, and reversible with one command

The problem

Claude Code (and every other AI coding CLI) stores your full conversation history as plain-text JSONL on disk — under ~/.claude/projects/ for Claude Code, ~/.codex/sessions/ for OpenAI Codex. Anything you paste — an AWS key, a .env file, a database URL — sits in clear text indefinitely. A typical dev's history accumulates dozens of secrets over months, often without them realizing.

agentsweep scans that history, tells you what leaked, and can redact the secret values in place while preserving the JSONL structure byte-for-byte. It also tells you which keys to rotate, with the right revocation URL for each provider.

Scope of protection: agentsweep itself is fully local and offline — it reads and writes only files on your machine and makes zero network calls. It removes one attack vector: secrets sitting in local history files. It does not affect what your AI provider already received: when you paste a key into Claude Code, Cursor, or any cloud-backed agent, that key already transited the provider's servers before it hit disk. If that concerns you, consider a locally-hosted model (Ollama, LM Studio, OpenCode) where nothing leaves your machine at all — agentsweep pairs especially well with local-model setups.

Why this matters right now

Supply chain attacks are accelerating. In 2024–2025 a wave of malicious npm and PyPI packages — sha256-universal, shailulid, hundreds of typosquats — were caught doing one thing: exfiltrating developer credentials off the machine that installed them. They target environment variables, .env files, shell history, SSH keys, and now AI agent history files.

AI coding assistants have created a new category of credential exposure that didn't exist two years ago:

  • You paste a production API key into Claude Code to debug something → it's now in ~/.claude/projects/*/conversations/*.jsonl forever
  • A compromised npm package runs postinstall → scans common paths → finds your JSONL history → exfiltrates 50 API keys in one request
  • You rotate the key you used in public but forget the dozen others in your history
  • Meanwhile your history grows: every .env you asked an AI to help with, every DB URL you shared for debugging, every token you pasted for a one-liner

AI agent history is the new .bash_history — except it contains full context, not just commands. The attack tooling already knows this. agentsweep exists to clean up before it's exploited.

Quick start

pip install uv                  # get uv (skip if you already have it)
uv tool install agentsweep      # install — adds `agentsweep` and `asweep` to PATH
asweep                          # run — interactive menu guides you through everything

That's it. No virtualenv to activate, no PATH fiddling — uv tool install gives the command its own isolated environment.

How it works

agentsweep runs a fixed 5-stage pipeline. scan stops after stage 3; fix continues through redaction.

flowchart LR
    A("🔍 DISCOVER\nwalk history dirs\nstream file list") --> B("⚡ SCAN\nAho-Corasick pre-filter\n191 regex rules + BIP-39")
    B --> C{"secrets\nfound?"}
    C -- "none" --> D("✅ CLEAN\nexit 0")
    C -- "found" --> E("📋 FINDINGS\nshow report\nexit 1")
    E -. "scan only" .-> F("⚠️ ROTATE\nkeys still live")
    E -- "type REDACT" --> G("✏️ REDACT\natomic write · .bak backup\npost-write JSON validation")
    G --> H("🔑 ROTATE\nper-provider\nrevocation links")

    style A fill:#1e3a5f,color:#fff,stroke:#2d5986
    style B fill:#1e3a5f,color:#fff,stroke:#2d5986
    style C fill:#4a3728,color:#fff,stroke:#7a5c3f
    style D fill:#1a4731,color:#fff,stroke:#2d7a52
    style E fill:#4a3a1e,color:#fff,stroke:#7a6030
    style F fill:#4a2020,color:#fff,stroke:#8b3a3a
    style G fill:#1e3a5f,color:#fff,stroke:#2d5986
    style H fill:#2d1e4a,color:#fff,stroke:#5a3a8b

Every write is protected by 8 safety invariants — atomic replace, mandatory .bak backup, symlink rejection, mtime/process gates, and post-write JSONL validation. agentsweep undo restores from backups.

Install

Recommended — isolated, no venv conflicts:

uv tool install agentsweep      # one-time install
uv tool upgrade agentsweep      # update to latest

Try without installing (always runs latest):

uvx agentsweep@latest

Classic pip:

pip install agentsweep
pip install --upgrade agentsweep

Don't have uv? pip install uv or see astral.sh/uv. Requires Python 3.11+.

Usage

Interactive mode

Run with no arguments in a terminal and you get the full experience — banner, numbered menu, typed confirmations before anything destructive, and one-key undo (restores the .bak backups). Any interactive scan that finds secrets ends with an offer to redact them on the spot (type REDACT to confirm):

agentsweep

Scripting is unaffected: any flag, or a piped/redirected stream, skips the menu entirely and behaves exactly as documented below.

Verbs

Download Tool