aicheck-scan
Fail the build if coding-agent credential files land in git.
aicheck agents --ci walks the checkout, an optional Docker context, and the
runner home. Checkout / context / artifacts fail on presence. Home fails
only if a file is world-readable (Claude Code on the runner is otherwise
ok). No network. The path list is
unauth.dev/loot (102 GET paths, one session,
10 August 2026).
The documented command is aicheck-scan; the package also installs aicheck
as a short alias.
Add to CI (60 seconds)
Copy examples/agents-ci.yml to
.github/workflows/agents.yml, or:
name: agent-creds
on:
pull_request:
push:
branches: [main]
jobs:
agents:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- uses: unauthdev/aicheck-scan/agents@main
Pin @main only if you accept floating. Prefer a commit SHA once you have
one you trust. Optional inputs: context (Docker build context), artifacts,
fail-home.
pip install aicheck-scan
aicheck agents --ci
aicheck agents --home "$HOME" # laptop inventory; does not fail CI
aicheck agents --ci --context . # also walk a Docker context
Exit 1 if a listed file is in the tree you asked it to fail on. JSON:
aicheck agents --ci --format json.
What it looks for
Relative paths from loot list v1, coding-agent families only:
.claude/.credentials.json, .claude.json, .claude/settings.json,
.codex/auth.json, .qwen/oauth_creds.json, .qwen/settings.json,
.qwen/.env, .kimi-code/credentials/kimi-code.json,
.kimi-code/config.toml, .grok/auth.json, .hermes/auth.json,
.config/opencode/opencode.json, .local/share/opencode/auth.json.
A random .env is not a hit. .qwen/.env is. Cite:
unauth.dev loot list v1 — observed 2026-08-10 · CC-BY 4.0.
The hosted scanner at unauth.dev names the door (open n8n, Ollama, …). It never fetches these files on a host you submit.
Live-probe leftover
The root Action uses: unauthdev/aicheck-scan@v1 still live-probes a host
you name (Ollama, n8n, vLLM, and the rest). That is the 1.2.x product. It is
not the coding-agent gate. Keep it if you already depend on it. Marketplace
listing: aicheck-scan.
Notes: docs/marketplace.md.
- uses: unauthdev/aicheck-scan@v1
with:
target: localhost
fail-grade: F
CLI equivalent: aicheck-scan example.com / aicheck scan localhost --allow-private.
Probe contract: docs/PROBES.md. Fix cards:
unauth.dev/fixes.
Inventory
Local continuous sweep of hosts you own. Nothing phones home.
aicheck inventory --targets targets.yaml --state-dir ./state --allow-private --i-own-these-targets
Target examples under examples/. Schema:
docs/schemas/inventory-report-v1.md.
Docker: docker run ghcr.io/unauthdev/aicheck:v1 … (image tracks the live-probe
CLI; aicheck agents is in the pip package from 1.3.0).
Trust
aicheck agentsdials nothing.- Live-probe traffic is read-only GETs to the host you name. No logins, no POSTs, no exploit verification.
- Optional weekly PyPI version check is opt-in (
--version-check/AICHECK_VERSION_CHECK=1). --dry-runprints every request and opens no sockets.
Full page: docs/trust.md. Security reports: SECURITY.md.
License
MIT. Dataset on unauth.dev/loot is CC-BY 4.0.
Advisory catalog: advisories.yaml / unauth.dev/advisories.
Metadata
Release files for aicheck-scan 1.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| aicheck_scan-1.3.0.tar.gz | 90.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| aicheck_scan-1.3.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 212.1 kB
Release files / aicheck_scan-1.3.0.tar.gz
| Download URL | aicheck_scan-1.3.0.tar.gz |
|---|---|
| Size | 90.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
298dfa857afc5cbbaec3f243b26a00beeeee5178f7b28321d19bf491dcab9271
|
|
BLAKE2b-256 checksum How to use checksums |
fa382f4f1d2bf097874c329fc634c8774e8a10775e1c06c5b65af8bcef72e323
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 12, 2026.
Transparency logRelease files / aicheck_scan-1.3.0-py3-none-any.whl
| Download URL | aicheck_scan-1.3.0-py3-none-any.whl |
|---|---|
| Size | 122.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
5dc0a5b869be52b1292f40015f20e5ca5eeb1a699401b5991e96317122c2201f
|
|
BLAKE2b-256 checksum How to use checksums |
bfc1e9f43ed9e1ec123523e9e030549d1858d84ea512602bb9f8e69cdaee37e5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 12, 2026.
Transparency log