
Flight recorder and secret scanner for AI coding agents. Reads what Claude Code, Codex, Gemini CLI and 9 more ran, and flags risky actions and leaked keys. Runs locally, no telemetry, MIT.
A flight recorder for AI agents, and a scanner for the authority they hold. AI coding agent security for Claude Code and eleven other coding agents, run on your own machine. No account, no telemetry, no dependencies.
Website and docs: https://ranwhat.com
Your coding agent has your shell, your keys and your repo. ranwhat reads
what it actually ran and surfaces the handful of irreversible actions worth
knowing about.
$ ranwhat watch --days 90
ranwhat watch · local agent flight recorder
----------------------------------------------------------------------------
Read Claude Code: 4 transcripts, last 90 days
2 critical 2 high
* Credential material accessed 2026-09-30 18:13:00 Bash
cat ~/.ssh/id_rsa
-> The agent read a file whose only purpose is to hold secrets. Whatever
it read is now in a model context you do not control.
* Bulk or recursive deletion 2026-09-28 14:42:00 Bash
…rm -rf '@'
-> Recursive deletion. Recoverable only if something else was backing it
up.
* Package or release published 2026-09-21 11:05:00 Bash
npm publish
-> Something was pushed to a registry other people may install from.
Supply-chain reach, and usually irreversible.
* Destructive git operation 2026-09-15 17:30:00 Bash
git push --force origin main
-> History rewriting or branch deletion. This is the class of action
that destroys the record of what else happened.
----------------------------------------------------------------------------
Read locally. Nothing was transmitted.
Claude Code deletes the transcript of a session you have not used for longer
than
cleanupPeriodDays,
30 days by default. So --days 90 finds more if you raised it, if a session
you resumed within that period has older actions in it, or for sessions
started or last continued in Claude Desktop or Cowork, which Claude Code
v2.1.248 and later
keep at any age by default.
Run it once, without installing anything:
uvx ranwhat check
Or put it on your path:
pipx install ranwhat
pip install ranwhat
Then ranwhat demo shows an authority scan on a bundled example.
Python 3.9+. No dependencies, and nothing is built on your machine.
ranwhat check: everything worth knowing, in one read-only passRuns watch and clean together and changes nothing.
On a terminal, check, watch and clean keep one status line on stderr while
they read, counting transcripts through each pass: indexing secrets
((first run) the first time), checking actions, looking for secrets.
Nothing is written there when stderr is not a terminal, or with --json.
ranwhat watch: audit what Claude Code and your other agents ranReads what Claude Code and your other coding agents already wrote to disk. No wrapper, no proxy, nothing in your critical path. Every agent below is read by default, each from where it keeps its history (the variable in brackets moves it, as it moves the agent itself); one that is not on your machine is skipped.
| Source | Location | Format |
|---|---|---|
| Claude Code | ~/.claude/projects/*/*.jsonl and each session's subagents/**/agent-*.jsonl, or the same under $CLAUDE_CONFIG_DIR/projects when set | JSONL |
| Codex (CLI, IDE extension, desktop app) | ~/.codex/sessions/YYYY/MM/DD/rollout-*.jsonl and archived_sessions/ ($CODEX_HOME); history.jsonl, shell_snapshots/ and its SQLite thread index are searched for secrets | JSONL; SQLite read only; .jsonl.zst read only, on Python 3.14 or with the zstd command |
| Gemini CLI | ~/.gemini/tmp/<project>/chats/session-*.jsonl and older session-*.json ($GEMINI_CLI_HOME) | JSONL, JSON |
| GitHub Copilot CLI | ~/.copilot/session-state/<session>/events.jsonl ($COPILOT_HOME) | JSONL |
| Qwen Code | ~/.qwen/projects/<project>/chats/*.jsonl and older tmp/<hash>/chats/session-*.json ($QWEN_RUNTIME_DIR, $QWEN_HOME) | JSONL, JSON |
| Grok Build | ~/.grok/sessions/<folder>/<session>/updates.jsonl ($GROK_HOME) | JSONL |
| Droid | ~/.factory/sessions/*.jsonl, and -<cwd>/*.jsonl and btw/*.jsonl below it ($FACTORY_HOME_OVERRIDE) | JSONL |
| Kimi Code | ~/.kimi-code/sessions/<folder>/<session>/agents/*/wire.jsonl ($KIMI_CODE_HOME) | JSONL |
| Kimi CLI | ~/.kimi/sessions/<folder>/<session>/wire.jsonl and context*.jsonl ($KIMI_SHARE_DIR) | JSONL |
| Pi | ~/.pi/agent/sessions/--<cwd>--/*.jsonl ($PI_CODING_AGENT_DIR) | JSONL |
| Muse Code | ~/.local/share/muse/sessions/YYYY/MM/DD/<session>/session.jsonl ($XDG_DATA_HOME/muse) | JSONL |
| OpenClaw | $OPENCLAW_STATE_DIR/agents/*/agent/openclaw-agent.sqlite | SQLite, read only |
Meta Muse runs in Meta's cloud and keeps nothing on your machine, so there is nothing to read; Muse Code, Meta's coding CLI, is supported. Grok Bot keeps its history in xAI's cloud, even for commands it runs on your machine; Grok Build, xAI's coding CLI, is supported. The current Amp keeps its threads on ampcode.com. Cursor is next, once its format is checked against a primary source.
Nine rules: credential access, secret-shaped strings in tool calls, package publishing, cloud resource changes, financial API calls, log tampering, destructive git, recursive deletion, and local files uploaded with curl. Each agent's tool calls are judged by the same rules; every action says which agent ran it.
ranwhat watch --days 30
ranwhat watch --source codex # one agent (repeatable)
ranwhat watch --path codex=~/work/.codex # an agent's history elsewhere
ranwhat watch --json
ranwhat sources # every agent, where it looked, what it found
--root and --state-dir still work, as the names of
--path claude-code= and --path openclaw=.
ranwhat clean: find secrets in Claude Code and other agents' transcriptsWhen an agent runs cat .env, the output is written into the transcript:
your database password, your JWT secret, your provider tokens, in plaintext,
in a file Claude Code keeps for 30 days by default.
ranwhat clean # report, then open a review session
ranwhat clean --apply # mask everything without asking
clean searches every agent's history, and masks a value only in a file
the agent lets it rewrite: a plain JSONL, JSON or text file nothing has
written to in the last two minutes. Databases (Codex's thread index,
OpenClaw's agent databases) and compressed files are read only: the report
names each one that holds a secret and how to remove it in the agent
instead.
Scanning a real history takes a while, so the session stays open on what it just found rather than making you re-scan to act on it:
ranwhat> list the findings again
ranwhat> show 3 where it appears, and what to roll it at
ranwhat> mask 3 mask just that one
ranwhat> mask all mask everything listed
ranwhat> keep 3 leave it alone
ranwhat> rotate what to rotate, grouped by provider
Each finding says which project it was found in and, when the transcript
names it, the file it was read out of, because a 64-character string is
useless without knowing which .env it escaped:
* Stripe live secret key sk_…dc 32 chars seen 8x
read from api/.env
in /Users/you/Desktop/app
Redaction is not remediation. Masking a value here does not un-expose it. It was already on disk and already sat in a model context you do not control. The rotation is the fix; masking only stops it leaking a second time. The report says so rather than implying safety.