Skip to main content

blackhole-sec

A small offline toolkit I actually use: check sketchy links, keep passwords in an encrypted vault, strip photo metadata before posting, and pack directories into encrypted .bhb files instead of zip.

No accounts. No network calls. Nothing leaves your machine.

Full write-ups for each tool live here: https://satin-networks.github.io/blackhole-sec/

pip install blackhole-sec
blackhole check "http://secure-paypal-login.tk/free-nitro"
blackhole vault init
blackhole shred analyze photo.jpg
blackhole bundle create ./mydir ./backup.bhb

The four tools

Paste a Discord / email lure and get a straight answer. Everything runs locally, the URL is never fetched.

blackhole check "http://secure.paypal.com.evil.tk/login?redirect=http://evil.com"
# MALICIOUS 68/100 (HIGH) hxxp[:]//secure[.]paypal[.]com[.]evil[.]tk/login...
#   +18 brand_impersonation: brand=paypal host=secure.paypal.com.evil.tk
#   +10 suspicious_tld: .tk
#   ...

blackhole check -f urls.txt --json > report.json
echo "http://paypal-secure.tk/login" | blackhole check --file -

Scoring is plain and explainable: each signal adds points, 0-20 is BENIGN, 21-49 SUSPICIOUS, 50+ MALICIOUS. Output is defanged (hxxp[://]) so you can't click it by accident. Batch mode and --threshold fit nicely in scripts.

2. vault - passwords on your own disk

One encrypted file, one master password. Argon2id turns your master into a key, AES-256-GCM does the rest. I never store the master anywhere.

blackhole vault init --vault ~/.blackhole/vault.db
blackhole vault set github --username alice --generate 24
blackhole vault get github --show
blackhole vault list
blackhole vault audit
blackhole vault gen --length 24

The file is chmod 0600. Every command locks when it finishes. audit calls out reused, short, and stale passwords with a 0-100 score.

Lose the master and the vault is gone - there is no reset, by design.

3. shred - clean it before you post it

Photos carry GPS, camera model, and timestamps. analyze shows what's in there, clean writes a *.cleaned copy with it stripped (your original stays untouched), verify passes or fails for scripts, and shred overwrites and deletes for real.

blackhole shred analyze photo.jpg
blackhole shred clean photo.jpg
blackhole shred verify photo.cleaned.jpg; echo $?
blackhole shred shred secret.txt --passes 7 --yes

4. bundle - encrypted archives that aren't zip

I got tired of zip passwords cracking in minutes and filenames leaking even with AES. .bhb packs a directory to tar.gz and encrypts the whole blob. Filenames, sizes, everything is hidden. Only blackhole opens it.

blackhole bundle create ./photos ./photos.bhb
blackhole bundle create ./photos ./photos.bhb --no-password  # writes photos.bhb.key
blackhole bundle extract ./photos.bhb ./restored --password

Wrong password or a tampered file just refuses to open. Extraction rejects absolute paths, .., and symlinks.

blackhole intake "http://evil.tk/login" ./photo.jpg  # link + file in one go

Install

Python 3.11 or newer.

pip install blackhole-sec
pip install -e ".[dev]"  # hacking on it

Depends on click, rich, cryptography, argon2-cffi, Pillow, pyyaml and pydantic. That's it.

Layout

src/blackhole_sec/
  check/    link scoring, no network
  vault/    encrypted store + generator
  shred/    metadata + secure delete
  bundle/   .bhb create / extract
  cli.py    everything wired together
tests/      offline fixtures, no network
docs/       longer write-ups for each tool

Security notes

Short version is in SECURITY.md. The honest version:

  • Standard primitives only (Argon2id, AES-GCM, secrets). Nothing home-rolled.
  • check never touches the network. Input capped at 2048 chars.
  • Secrets live in 0600 files. Keys are wiped best-effort after use.
  • Not audited. Don't bet your life on any single tool, including this one.

Found something? Open a private advisory with version, OS, and steps. Please don't post vault files or bundles anywhere public.

License

MIT - see LICENSE. Built by Satin Networks alongside wisp, our local WireGuard manager.

Metadata

Release files for blackhole-sec 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for blackhole-sec 0.1.0
File Size Uploaded
blackhole_sec-0.1.0.tar.gz 24.6 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for blackhole-sec 0.1.0
File Interpreter ABI Platform
blackhole_sec-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 48.5 kB

Release files / blackhole_sec-0.1.0.tar.gz

Download URL blackhole_sec-0.1.0.tar.gz
Size 24.6 kB
Tags Source
SHA-256 checksum
How to use checksums
c2a15e6215c39a36a06034551e35814d13530661b9895bcf331061146fa863d0
BLAKE2b-256 checksum
How to use checksums
e4ffb4885c71aed1005ddc445f738d1a41dbf502993c56d49d0f9acc822b71e3
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.5

Release files / blackhole_sec-0.1.0-py3-none-any.whl

Download URL blackhole_sec-0.1.0-py3-none-any.whl
Size 23.9 kB
Tags Python 3
SHA-256 checksum
How to use checksums
22d39ad55502e41a3f70dd62e6b525edda42518f72ccde469b338384c6b0ec74
BLAKE2b-256 checksum
How to use checksums
9178a8344ed927fccc124acdf1a9a2061a77d1d4f5689b308f492c5225b17015
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.5

Release history Release notifications | RSS feed

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

0.1.1

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page