
trufflehog
Find, verify, and analyze leaked credentials

Find, verify, and analyze leaked credentials

A tool for secrets management, encryption as a service, and privileged access management

Searches through git repositories for high entropy strings and secrets, digging deep into commit history

Sandbox for AI coding agents. Runs Copilot CLI, Claude Code, OpenCode, Gemini CLI, Antigravity, Pi, goose or a plain shell inside a kernel-level…

A modern git based age-encrypted secrets manager for teams.

Invisible infrastructure for Dracon developer workspaces: git sync, system guard, and warden encryption utilities.

Pluggable linting tool to prevent committing credential.

High-performance secrets scanner. CLI, Go library, Burp Suite extension, and Chrome extension. 487 detection rules with live credential validation.

Git diff for SBOMs—compare CycloneDX, SPDX, and Syft documents, detect tampering, and gate CI.

An SSH Agent that provides SSH keys stored in Bitwarden Secrets Manager

Multi-source secret scanner detecting API keys, passwords, and PII across Git repos, S3 buckets, filesystems, Confluence, JIRA, Slack, and Google…

Fast, open-source static analysis tool for detecting hardcoded secrets like passwords, API keys, and tokens in git repositories, files, and stdin…

Containerized secret scanning tool that detects exposed credentials, API keys, and tokens in Git repositories using regex and entropy-based…

CI component for Gitleaks SAST tool that scans git repositories for hardcoded secrets, API keys, and tokens with custom and remote configuration…

AI-first security scanner. NEW in v2026.7: Claude Code compromise detection — vet .claude/ hooks, permissions & skills before you clone — plus an…

Detects GlassWorm supply chain attack payloads by scanning VS Code extensions, npm/PyPI packages, and git repos for invisible Unicode payloads,…

A Rust CLI tool that recursively discovers Git repositories, captures state changes, generates diffs, extracts code elements with full snippets, and…

Nosey Parker is a command-line tool that finds secrets and sensitive information in textual data and Git history.