
경량의 크로스 플랫폼 CLI 도구로, 파일시스템을 스캔하여 노출된 비밀, API 키, 토큰을 감지합니다. 최대 성능과 제로 종속성을 위해 Go로 빌드되었습니다.
여우의 교활함으로 노출된 비밀을 사냥하세요!
가볍고 크로스 플랫폼인 CLI 도구로, 파일 시스템을 스캔하여 노출된 비밀, API 키, 토큰을 탐지합니다. 최대 성능과 제로 의존성을 위해 Go로 제작되었습니다.
# macOS Apple Silicon (M1/M2/M3)
curl -L -o kyubisweep https://github.com/tanmayshahane/kyubisweep/releases/latest/kyubisweep-darwin-arm64
chmod +x kyubisweep
# 실행!
./kyubisweep --path /path/to/your/project
# Go 1.21+ 설치 확인
go version
# 클론 및 빌드
git clone https://github.com/tanmayshahane/kyubisweep.git
cd kyubisweep
go build -o kyubisweep ./cmd/sweep/main.go
# 실행!
./kyubisweep --path .
사용법:
kyubisweep [옵션]
옵션:
--path <디렉터리> 스캔할 경로 (기본값: 현재 디렉터리)
--verbose 상세 출력 활성화
--all 모든 심각도 수준 표시 (기본값: HIGH만)
--all-files 텍스트 기반 파일뿐만 아니라 모든 파일 스캔
--ext <확장자> 추가로 스캔할 확장자 (쉼표로 구분)
--json 결과를 JSON 파일로 출력
--no-report 보고서 파일 저장 안 함
--quiet 최소 출력, 요약만 표시
--move-to <경로> 비밀이 있는 파일을 격리 디렉터리로 이동
--help 도움말 표시
예제:
kyubisweep --path ./my-project
kyubisweep --path . --all # 모든 심각도 표시
kyubisweep --path . --ext log,dat # 사용자 정의 확장자 추가
kyubisweep --path . --move-to ./vault # 민감한 파일 격리
kyubisweep --path . --json # JSON으로 내보내기
╔══════════════════════════════════════════════════════════════════════════╗
║ 🛡️ KYUBISWEEP 보안 위생 점수표 ║
╚══════════════════════════════════════════════════════════════════════════╝
🚨 심각한 문제 발견
📊 위험 분해
─────────────────────────────────────────
🚨 심각 9 ████████████████░░░░
🔴 높음 2 ███░░░░░░░░░░░░░░░░░
🟡 중간 0 ░░░░░░░░░░░░░░░░░░░░
🔵 낮음 0 ░░░░░░░░░░░░░░░░░░░░
🔍 발견 상세
─────────────────────────────────────────
위험 유형 위치
[심각] AWS Access Key ID ~/project/.env:5
[심각] PostgreSQL 연결 ~/project/config.yaml:12
[높음] Stripe Secret Key ~/project/payment.js:42
📁 스캔 대상: ~/my-project
📄 분석된 파일: 2.9K
⏱️ 소요 시간: 1.2s
graph TD
subgraph "Initialization (Main Goroutine)"
A[Start CLI] --> B{Parse Flags};
B -->|--path| C[Init Walker];
B -->|--move-to| D[Init Quarantine Mgr];
C --> E[Create Jobs Channel];
E --> F[Create Results Channel];
end
subgraph "Producer (Goroutine 1)"
G[Walker] -->|Finds Files| E;
style G fill:#f9f,stroke:#333,stroke-width:2px
style E fill:#ccf,stroke:#333,stroke-width:2px,stroke-dasharray: 5 5
end
subgraph "Worker Pool (Goroutines 2...N)"
E -->|Read File Path| H[Worker 1];
E -->|Read File Path| I[Worker 2];
E -->|Read File Path| J[Worker N];
H -->|Read Content| K{Analyzer};
I -->|Read Content| K{Analyzer};
J -->|Read Content| K{Analyzer};
K -- No Secret --> L((Discard));
K -- Secret Found --> M[Send Finding];
M --> F;
style K fill:#ff9,stroke:#333,stroke-width:2px
end
subgraph "Consumer & Wrap up (Main Goroutine)"
F -->|Collect Findings| N[Reporter / Table UI];
style F fill:#ccf,stroke:#333,stroke-width:2px,stroke-dasharray: 5 5
N --> O{Quarantine Requested?};
O -- Yes --> P[Move Files to Vault];
O -- No --> Q[Exit];
P --> Q;
end
%% Add a WaitGroup visual helper
H -.-> WG[sync.WaitGroup];
I -.-> WG;
J -.-> WG;
WG -.->|All Done| F;
| 카테고리 | 예시 |
|---|---|
| 클라우드 자격 증명 | AWS Access Keys, Google API Keys, Azure tokens |
| 결제 시스템 | Stripe API keys (live & test) |
| 개발자 도구 | GitHub PATs, NPM tokens, Heroku API keys |
| 통신 | Slack tokens, Discord bot tokens, Twilio keys |
| 데이터베이스 | PostgreSQL, MongoDB, MySQL 연결 문자열 |
| 암호화 | RSA/SSH/PGP 개인 키 |
| 일반 | 비밀번호, API 키, Bearer 토큰 |
kyubisweep/
├── cmd/
│ └── sweep/
│ └── main.go # CLI entry point + worker pool
├── pkg/
│ ├── analyzer/
│ │ └── analyzer.go # Entropy + regex detection
│ ├── scanner/
│ │ └── walker.go # Concurrent directory walker
│ ├── reporter/
│ │ └── reporter.go # Security Scorecard output
│ ├── quarantine/
│ │ └── manager.go # Secure file relocation
│ └── common/
│ └── colors.go # Shared ANSI color utilities
├── reports/ # Generated scan reports
├── build/ # Cross-compiled binaries
├── go.mod # Go module definition
├── build.sh # Cross-platform build script
└── README.md
# 빌드 스크립트 실행 가능하게 설정
chmod +x build.sh
# 모든 플랫폼용 빌드
./build.sh
# 출력:
# build/kyubisweep-darwin-arm64 (macOS Apple Silicon)
# build/kyubisweep-darwin-amd64 (macOS Intel)
# build/kyubisweep-linux-amd64 (Linux 64-bit)
# build/kyubisweep-linux-arm64 (Linux ARM)
# build/kyubisweep-windows-amd64.exe (Windows 64-bit)
즉시 보안해야 할 비밀을 찾았나요? --move-to를 사용하여 파일을 옮기세요:
./kyubisweep --path . --move-to ./secure_vault
안전 기능:
기여를 환영합니다! 자유롭게 풀 리퀘스트를 제출해 주세요.
MIT 라이선스 - 여러분의 프로젝트에서 자유롭게 사용하세요!
🦊 API 키를 한두 번 실수로 커밋한 개발자들이 제작했습니다.