Skip to main content

Scan AI chat histories for leaked secrets. Find out what you've accidentally shared with AI providers.

Project description

🔍 CitrusGlaze Scan

How many secrets have you leaked to AI? Find out in 15 seconds.

We scanned one developer's AI chat history. 169 secrets in 30 days. AWS keys, private keys, database passwords — all sent to AI providers in prompts.

100% local. No data leaves your machine. Zero dependencies.

Install & Run

pip3 install citrusglaze-scan
python3 -m citrusglaze_scan

Or with pipx (no install needed):

pipx run citrusglaze-scan

That's it. Results in 15 seconds.

What It Finds

Severity What Examples
🔴 Critical Cloud credentials, private keys, DB passwords AKIA..., -----BEGIN RSA PRIVATE KEY-----, postgresql://admin:pass@prod
🟠 High API tokens, service keys ghp_..., sk-proj-..., sk_live_..., xoxb-...
🟡 Medium JWTs, generic secrets eyJ..., high-entropy strings

200+ detection patterns covering AWS, OpenAI, Anthropic, GitHub, Stripe, Slack, Google, Azure, database URIs, private keys, and more.

What It Scans

Tool What we check
Claude Code ~/.claude/ conversations and project histories
Cursor ~/.cursor/ and ~/Library/Application Support/Cursor/
GitHub Copilot ~/Library/Application Support/GitHub Copilot Chat/
Continue.dev ~/.continue/ sessions
Windsurf ~/.windsurf/ and ~/.codeium/
Aider ~/.aider/ chat logs
Shell history ~/.zsh_history, ~/.bash_history, ~/.zshrc

CLI Options

python3 -m citrusglaze_scan                      # All tools, last 30 days
python3 -m citrusglaze_scan --tool claude        # Only Claude Code
python3 -m citrusglaze_scan --days 7             # Last 7 days
python3 -m citrusglaze_scan --days 0             # All time
python3 -m citrusglaze_scan --json               # Machine-readable output
python3 -m citrusglaze_scan --verbose            # Show file paths
python3 -m citrusglaze_scan --path /some/dir     # Scan any directory

Privacy

  • Zero network calls. Never connects to the internet.
  • No telemetry. Nothing collected or transmitted.
  • Secrets are redacted in output — first 4 chars shown, rest masked.
  • Open source. Read every line: GitHub

Stop Future Leaks

This scanner finds secrets after they've been sent. To catch them before they reach AI providers:

CitrusGlaze is a local MITM proxy that scans every AI request in real-time. 210+ secret patterns. Blocks critical secrets. Redacts the rest. Works with 39+ AI tools.

Read the State of AI Traffic Report — what 26,000+ intercepted AI requests reveal about leaked secrets.

Install CitrusGlaze — 5-minute setup, no cloud, data never leaves your machine.

Zero Dependencies

Python standard library only. No pip dependencies. Works on Python 3.9+.

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

citrusglaze_scan-0.1.3.tar.gz (42.3 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

citrusglaze_scan-0.1.3-py3-none-any.whl (42.3 kB view details)

Uploaded Python 3

File details

Details for the file citrusglaze_scan-0.1.3.tar.gz.

File metadata

  • Download URL: citrusglaze_scan-0.1.3.tar.gz
  • Upload date:
  • Size: 42.3 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.9.6

File hashes

Hashes for citrusglaze_scan-0.1.3.tar.gz
Algorithm Hash digest
SHA256 150075c3a3dd17094929dbade055f6027e0f430ae46237715d3e0572f0026234
MD5 0aa470f587a142a3f6e7568b89e96868
BLAKE2b-256 dfddf355b479e9e92f77669d01ec962675a5600dd66b74a275af7b5c7cabc0ba

See more details on using hashes here.

File details

Details for the file citrusglaze_scan-0.1.3-py3-none-any.whl.

File metadata

File hashes

Hashes for citrusglaze_scan-0.1.3-py3-none-any.whl
Algorithm Hash digest
SHA256 6261bdc652f5d9b7b7f239407388191ab71f9713f0851f68d9f8fbe93f15651c
MD5 935a3b30d016284fa050c346dab9da16
BLAKE2b-256 56ffa3a774b9d991dae83c149dff636143f59e3c0e92e9165e159f06a16fc8c2

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page