Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
ranwhat — Flight recorder and secret scanner for AI coding agents. Reads what Claude Code, Codex, Gemini CLI and 9 more ran, and flags risky actions and leaked keys. Runs locally, no telemetry, MIT. | Kitploit
Tools/GitHubGitHub/matijamiki/ranwhat
Defensive ToolsIdentity ManagementScripting & AutomationInformation GatheringPrivacyUtilities & FrameworksSecret DetectionIncident ResponseAI SecurityLog Analysis
GitHubmatijamiki/ranwhat
195h 32m agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →

ranwhat

Flight recorder and secret scanner for AI coding agents. Reads what Claude Code, Codex, Gemini CLI and 9 more ran, and flags risky actions and leaked keys. Runs locally, no telemetry, MIT.

View RepositoryWebsite
Share

ranwhat

A flight recorder for AI agents, and a scanner for the authority they hold. AI coding agent security for Claude Code and eleven other coding agents, run on your own machine. No account, no telemetry, no dependencies.

Website and docs: https://ranwhat.com

Your coding agent has your shell, your keys and your repo. ranwhat reads what it actually ran and surfaces the handful of irreversible actions worth knowing about.

$ ranwhat watch --days 90

  ranwhat watch  · local agent flight recorder
  ----------------------------------------------------------------------------
  Read Claude Code: 4 transcripts, last 90 days

  2 critical  2 high

  * Credential material accessed   2026-09-30 18:13:00  Bash
      cat ~/.ssh/id_rsa
      -> The agent read a file whose only purpose is to hold secrets. Whatever
         it read is now in a model context you do not control.

  * Bulk or recursive deletion   2026-09-28 14:42:00  Bash
      …rm -rf '@'
      -> Recursive deletion. Recoverable only if something else was backing it
         up.

  * Package or release published   2026-09-21 11:05:00  Bash
      npm publish
      -> Something was pushed to a registry other people may install from.
         Supply-chain reach, and usually irreversible.

  * Destructive git operation   2026-09-15 17:30:00  Bash
      git push --force origin main
      -> History rewriting or branch deletion. This is the class of action
         that destroys the record of what else happened.

  ----------------------------------------------------------------------------
  Read locally. Nothing was transmitted.

Claude Code deletes the transcript of a session you have not used for longer than cleanupPeriodDays, 30 days by default. So --days 90 finds more if you raised it, if a session you resumed within that period has older actions in it, or for sessions started or last continued in Claude Desktop or Cowork, which Claude Code v2.1.248 and later keep at any age by default.

Install

Run it once, without installing anything:

uvx ranwhat check

Or put it on your path:

pipx install ranwhat
pip install ranwhat

Then ranwhat demo shows an authority scan on a bundled example.

Python 3.9+. No dependencies, and nothing is built on your machine.

Commands

ranwhat check: everything worth knowing, in one read-only pass

Runs watch and clean together and changes nothing.

On a terminal, check, watch and clean keep one status line on stderr while they read, counting transcripts through each pass: indexing secrets ((first run) the first time), checking actions, looking for secrets. Nothing is written there when stderr is not a terminal, or with --json.

ranwhat watch: audit what Claude Code and your other agents ran

Reads what Claude Code and your other coding agents already wrote to disk. No wrapper, no proxy, nothing in your critical path. Every agent below is read by default, each from where it keeps its history (the variable in brackets moves it, as it moves the agent itself); one that is not on your machine is skipped.

SourceLocationFormat
Claude Code~/.claude/projects/*/*.jsonl and each session's subagents/**/agent-*.jsonl, or the same under $CLAUDE_CONFIG_DIR/projects when setJSONL
Codex (CLI, IDE extension, desktop app)~/.codex/sessions/YYYY/MM/DD/rollout-*.jsonl and archived_sessions/ ($CODEX_HOME); history.jsonl, shell_snapshots/ and its SQLite thread index are searched for secretsJSONL; SQLite read only; .jsonl.zst read only, on Python 3.14 or with the zstd command
Gemini CLI~/.gemini/tmp/<project>/chats/session-*.jsonl and older session-*.json ($GEMINI_CLI_HOME)JSONL, JSON
GitHub Copilot CLI~/.copilot/session-state/<session>/events.jsonl ($COPILOT_HOME)JSONL
Qwen Code~/.qwen/projects/<project>/chats/*.jsonl and older tmp/<hash>/chats/session-*.json ($QWEN_RUNTIME_DIR, $QWEN_HOME)JSONL, JSON
Grok Build~/.grok/sessions/<folder>/<session>/updates.jsonl ($GROK_HOME)JSONL
Droid~/.factory/sessions/*.jsonl, and -<cwd>/*.jsonl and btw/*.jsonl below it ($FACTORY_HOME_OVERRIDE)JSONL
Kimi Code~/.kimi-code/sessions/<folder>/<session>/agents/*/wire.jsonl ($KIMI_CODE_HOME)JSONL
Kimi CLI~/.kimi/sessions/<folder>/<session>/wire.jsonl and context*.jsonl ($KIMI_SHARE_DIR)JSONL
Pi~/.pi/agent/sessions/--<cwd>--/*.jsonl ($PI_CODING_AGENT_DIR)JSONL
Muse Code~/.local/share/muse/sessions/YYYY/MM/DD/<session>/session.jsonl ($XDG_DATA_HOME/muse)JSONL
OpenClaw$OPENCLAW_STATE_DIR/agents/*/agent/openclaw-agent.sqliteSQLite, read only

Meta Muse runs in Meta's cloud and keeps nothing on your machine, so there is nothing to read; Muse Code, Meta's coding CLI, is supported. Grok Bot keeps its history in xAI's cloud, even for commands it runs on your machine; Grok Build, xAI's coding CLI, is supported. The current Amp keeps its threads on ampcode.com. Cursor is next, once its format is checked against a primary source.

Nine rules: credential access, secret-shaped strings in tool calls, package publishing, cloud resource changes, financial API calls, log tampering, destructive git, recursive deletion, and local files uploaded with curl. Each agent's tool calls are judged by the same rules; every action says which agent ran it.

ranwhat watch --days 30
ranwhat watch --source codex                # one agent (repeatable)
ranwhat watch --path codex=~/work/.codex    # an agent's history elsewhere
ranwhat watch --json
ranwhat sources                             # every agent, where it looked, what it found

--root and --state-dir still work, as the names of --path claude-code= and --path openclaw=.

ranwhat clean: find secrets in Claude Code and other agents' transcripts

When an agent runs cat .env, the output is written into the transcript: your database password, your JWT secret, your provider tokens, in plaintext, in a file Claude Code keeps for 30 days by default.

ranwhat clean               # report, then open a review session
ranwhat clean --apply       # mask everything without asking

clean searches every agent's history, and masks a value only in a file the agent lets it rewrite: a plain JSONL, JSON or text file nothing has written to in the last two minutes. Databases (Codex's thread index, OpenClaw's agent databases) and compressed files are read only: the report names each one that holds a secret and how to remove it in the agent instead.

Scanning a real history takes a while, so the session stays open on what it just found rather than making you re-scan to act on it:

ranwhat> list           the findings again
ranwhat> show 3         where it appears, and what to roll it at
ranwhat> mask 3         mask just that one
ranwhat> mask all       mask everything listed
ranwhat> keep 3         leave it alone
ranwhat> rotate         what to rotate, grouped by provider

Each finding says which project it was found in and, when the transcript names it, the file it was read out of, because a 64-character string is useless without knowing which .env it escaped:

* Stripe live secret key   sk_…dc  32 chars  seen 8x
      read from api/.env
      in         /Users/you/Desktop/app

Redaction is not remediation. Masking a value here does not un-expose it. It was already on disk and already sat in a model context you do not control. The rotation is the fix; masking only stops it leaking a second time. The report says so rather than implying safety.

Download Tool