Skip to main content

blackhole-sec

A small offline toolkit I actually use: check sketchy links, keep passwords in an encrypted vault, strip photo metadata before posting, and pack directories into encrypted .bhb files instead of zip.

No accounts. No network calls. Nothing leaves your machine.

Full write-ups for each tool live here: https://satin-networks.github.io/blackhole-sec/

pip install blackhole-sec
blackhole check "http://secure-paypal-login.tk/free-nitro"
blackhole vault init
blackhole shred analyze photo.jpg
blackhole bundle create ./mydir ./backup.bhb

The four tools

Paste a Discord / email lure and get a straight answer. Everything runs locally, the URL is never fetched.

blackhole check "http://secure.paypal.com.evil.tk/login?redirect=http://evil.com"
# MALICIOUS 68/100 (HIGH) hxxp[:]//secure[.]paypal[.]com[.]evil[.]tk/login...
#   +18 brand_impersonation: brand=paypal host=secure.paypal.com.evil.tk
#   +10 suspicious_tld: .tk
#   ...

blackhole check -f urls.txt --json > report.json
echo "http://paypal-secure.tk/login" | blackhole check --file -

Scoring is plain and explainable: each signal adds points, 0-20 is BENIGN, 21-49 SUSPICIOUS, 50+ MALICIOUS. Output is defanged (hxxp[://]) so you can't click it by accident. Batch mode and --threshold fit nicely in scripts.

2. vault - passwords on your own disk

One encrypted file, one master password. Argon2id turns your master into a key, AES-256-GCM does the rest. I never store the master anywhere.

blackhole vault init --vault ~/.blackhole/vault.db
blackhole vault set github --username alice --generate 24
blackhole vault get github --show
blackhole vault list
blackhole vault audit
blackhole vault gen --length 24
blackhole vault rm old-forum --yes
blackhole vault passwd

The file is chmod 0600. Every command locks when it finishes. audit calls out reused, short, and stale passwords with a 0-100 score.

Lose the master and the vault is gone - there is no reset, by design.

3. shred - clean it before you post it

Photos carry GPS, camera model, and timestamps. analyze shows what's in there, clean writes a *.cleaned copy with it stripped (your original stays untouched), verify passes or fails for scripts, and shred overwrites and deletes for real.

blackhole shred analyze photo.jpg
blackhole shred clean photo.jpg
blackhole shred verify photo.cleaned.jpg; echo $?
blackhole shred shred secret.txt --passes 7 --yes

4. bundle - encrypted archives that aren't zip

I got tired of zip passwords cracking in minutes and filenames leaking even with AES. .bhb packs a directory to tar.gz and encrypts the whole blob. Filenames, sizes, everything is hidden. Only blackhole opens it.

blackhole bundle create ./photos ./photos.bhb
blackhole bundle create ./photos ./photos.bhb --no-password  # writes photos.bhb.key
blackhole bundle extract ./photos.bhb ./restored --password
blackhole bundle list ./photos.bhb --password
blackhole bundle verify ./photos.bhb --password; echo $?

Wrong password or a tampered file just refuses to open. Extraction rejects absolute paths, .., and symlinks.

blackhole intake "http://evil.tk/login" ./photo.jpg  # link + file in one go
blackhole intake "http://evil.tk/login" ./photo.jpg --json

Colors are on when your terminal supports them and off when piped. Force it either way with --no-color or the NO_COLOR env var.

Install

Python 3.11 or newer. Pick one:

# with pip
pip install blackhole-sec

# without touching pip yourself (venv + links handled for you)
curl -fsSL https://raw.githubusercontent.com/Satin-networks/blackhole-sec/main/scripts/install.sh | bash

# system-wide, so `sudo blackhole ...` works too
curl -fsSL https://raw.githubusercontent.com/Satin-networks/blackhole-sec/main/scripts/install.sh | sudo bash

From source:

pip install -e ".[dev]"

Depends on click, rich, cryptography, argon2-cffi and Pillow. That's it.

Upgrade later with blackhole upgrade (or the scripts/update.sh one-liner). Remove with the scripts/uninstall.sh one-liner; your vault file is left alone.

Layout

src/blackhole_sec/
  check/    link scoring, no network
  vault/    encrypted store + generator
  shred/    metadata + secure delete
  bundle/   .bhb create / extract
  cli.py    everything wired together
tests/      offline fixtures, no network
docs/       longer write-ups for each tool

Security notes

Short version is in SECURITY.md. The honest version:

  • Standard primitives only (Argon2id, AES-GCM, secrets). Nothing home-rolled.
  • check never touches the network. Input capped at 2048 chars.
  • Secrets live in 0600 files. Keys are wiped best-effort after use.
  • Not audited. Don't bet your life on any single tool, including this one.

Found something? Open a private advisory with version, OS, and steps. Please don't post vault files or bundles anywhere public.

License

MIT - see LICENSE. Built by Satin Networks alongside wisp, our local WireGuard manager.

Metadata

Release files for blackhole-sec 0.2.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for blackhole-sec 0.2.1
File Size Uploaded
blackhole_sec-0.2.1.tar.gz 33.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for blackhole-sec 0.2.1
File Interpreter ABI Platform
blackhole_sec-0.2.1-py3-none-any.whl Python 3 none any Details

Total release size: 63.5 kB

Release files / blackhole_sec-0.2.1.tar.gz

Download URL blackhole_sec-0.2.1.tar.gz
Size 33.3 kB
Tags Source
SHA-256 checksum
How to use checksums
2e8406d3c08b70968b4a272bdf50b6335dbe5d01de982df2effb30bc60c68c9e
BLAKE2b-256 checksum
How to use checksums
57116ca2fc994f4b1516946c7d030aa856a46a787e45a70206675049d7c247cb
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.5

Release files / blackhole_sec-0.2.1-py3-none-any.whl

Download URL blackhole_sec-0.2.1-py3-none-any.whl
Size 30.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
91889de734cc2aad45915e1305339ed2838b56286d3ec4081f553fafc8975eaf
BLAKE2b-256 checksum
How to use checksums
7d60e173301fe8d77c28493ca2a5a4c21a1514f31621a9628c6f3dbe2df5b481
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.13.5

Release history Release notifications | RSS feed

0.2.2

2 release files

This release

0.2.1 This release

2 release files

0.2.0

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page