Skip to main content

blackhole-sec

A small offline toolkit I actually use: check sketchy links, keep passwords in an encrypted vault, strip photo metadata before posting, and pack directories into encrypted .bhb files instead of zip.

No accounts. No network calls. Nothing leaves your machine.

Full write-ups for each tool live here: https://satin-networks.github.io/blackhole-sec/

pip install blackhole-sec
blackhole check "http://secure-paypal-login.tk/free-nitro"
blackhole vault init
blackhole shred analyze photo.jpg
blackhole bundle create ./mydir ./backup.bhb

The four tools

Paste a Discord / email lure and get a straight answer. Everything runs locally, the URL is never fetched.

blackhole check "http://secure.paypal.com.evil.tk/login?redirect=http://evil.com"
# MALICIOUS 68/100 (HIGH) hxxp[:]//secure[.]paypal[.]com[.]evil[.]tk/login...
#   +18 brand_impersonation: brand=paypal host=secure.paypal.com.evil.tk
#   +10 suspicious_tld: .tk
#   ...

blackhole check -f urls.txt --json > report.json
echo "http://paypal-secure.tk/login" | blackhole check --file -

Scoring is plain and explainable: each signal adds points, 0-20 is BENIGN, 21-49 SUSPICIOUS, 50+ MALICIOUS. Output is defanged (hxxp[://]) so you can't click it by accident. Batch mode and --threshold fit nicely in scripts.

2. vault - passwords on your own disk

One encrypted file, one master password. Argon2id turns your master into a key, AES-256-GCM does the rest. I never store the master anywhere.

blackhole vault init --vault ~/.blackhole/vault.db
blackhole vault set github --username alice --generate 24
blackhole vault get github --show
blackhole vault list
blackhole vault audit
blackhole vault gen --length 24
blackhole vault rm old-forum --yes
blackhole vault passwd

The file is chmod 0600. Every command locks when it finishes. audit calls out reused, short, and stale passwords with a 0-100 score.

Lose the master and the vault is gone - there is no reset, by design.

3. shred - clean it before you post it

Photos carry GPS, camera model, and timestamps. analyze shows what's in there, clean writes a *.cleaned copy with it stripped (your original stays untouched), verify passes or fails for scripts, and shred overwrites and deletes for real.

blackhole shred analyze photo.jpg
blackhole shred clean photo.jpg
blackhole shred verify photo.cleaned.jpg; echo $?
blackhole shred shred secret.txt --passes 7 --yes

4. bundle - encrypted archives that aren't zip

I got tired of zip passwords cracking in minutes and filenames leaking even with AES. .bhb packs a directory to tar.gz and encrypts the whole blob. Filenames, sizes, everything is hidden. Only blackhole opens it.

blackhole bundle create ./photos ./photos.bhb
blackhole bundle create ./photos ./photos.bhb --no-password  # writes photos.bhb.key
blackhole bundle extract ./photos.bhb ./restored --password
blackhole bundle list ./photos.bhb --password
blackhole bundle verify ./photos.bhb --password; echo $?

Wrong password or a tampered file just refuses to open. Extraction rejects absolute paths, .., and symlinks.

blackhole intake "http://evil.tk/login" ./photo.jpg  # link + file in one go
blackhole intake "http://evil.tk/login" ./photo.jpg --json

Colors are on when your terminal supports them and off when piped. Force it either way with --no-color or the NO_COLOR env var.

Install

Python 3.11 or newer. Pick one:

# with pip
pip install blackhole-sec

# without touching pip yourself (venv + links handled for you)
curl -fsSL https://raw.githubusercontent.com/Satin-networks/blackhole-sec/main/scripts/install.sh | bash

From source:

pip install -e ".[dev]"

Depends on click, rich, cryptography, argon2-cffi and Pillow. That's it.

Upgrade later with blackhole upgrade (or the scripts/update.sh one-liner). Remove with the scripts/uninstall.sh one-liner; your vault file is left alone.

Layout

src/blackhole_sec/
  check/    link scoring, no network
  vault/    encrypted store + generator
  shred/    metadata + secure delete
  bundle/   .bhb create / extract
  cli.py    everything wired together
tests/      offline fixtures, no network
docs/       longer write-ups for each tool

Security notes

Short version is in SECURITY.md. The honest version:

  • Standard primitives only (Argon2id, AES-GCM, secrets). Nothing home-rolled.
  • check never touches the network. Input capped at 2048 chars.
  • Secrets live in 0600 files. Keys are wiped best-effort after use.
  • Not audited. Don't bet your life on any single tool, including this one.

Found something? Open a private advisory with version, OS, and steps. Please don't post vault files or bundles anywhere public.

License

MIT - see LICENSE. Built by Satin Networks alongside wisp, our local WireGuard manager.

Metadata

Release files for blackhole-sec 0.2.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for blackhole-sec 0.2.0
File Size Uploaded
blackhole_sec-0.2.0.tar.gz 33.0 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for blackhole-sec 0.2.0
File Interpreter ABI Platform
blackhole_sec-0.2.0-py3-none-any.whl Python 3 none any Details

Total release size: 63.1 kB

Release files / blackhole_sec-0.2.0.tar.gz

Download URL blackhole_sec-0.2.0.tar.gz
Size 33.0 kB
Tags Source
SHA-256 checksum
How to use checksums
86e0d41e60f24de97905db5644a858e900b4f3ccbeecd742ee49883b6cf1e3fe
BLAKE2b-256 checksum
How to use checksums
e8cdb63a416ff56605ba1c28eed0b377ec5c6d750c3e9902f610a44ca153b3bd
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.5

Release files / blackhole_sec-0.2.0-py3-none-any.whl

Download URL blackhole_sec-0.2.0-py3-none-any.whl
Size 30.1 kB
Tags Python 3
SHA-256 checksum
How to use checksums
84da057d88d9da6b7d0f95b5f9135ee77732a4e340ed6a13fcfdb3b21567c2db
BLAKE2b-256 checksum
How to use checksums
0ac4acb39da8e4d92621ffe18905828fdbdea3f3a7c7aa65357dc87f603eba93
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.5

Release history Release notifications | RSS feed

0.2.2

2 release files

0.2.1

2 release files

This release

0.2.0 This release

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page