Skip to main content

Scan AI chat histories for leaked secrets. Find out what you've accidentally shared with AI providers.

Project description

🔍 CitrusGlaze Scan

How many secrets have you leaked to AI? Find out in 15 seconds.

We scanned one developer's AI chat history. 169 secrets in 30 days. AWS keys, private keys, database passwords — all sent to AI providers in prompts.

100% local. No data leaves your machine. Zero dependencies.

Install & Run

pip install citrusglaze-scan
citrusglaze-scan

That's it. Results in 15 seconds.

What It Finds

Severity What Examples
🔴 Critical Cloud credentials, private keys, DB passwords AKIA..., -----BEGIN RSA PRIVATE KEY-----, postgresql://admin:pass@prod
🟠 High API tokens, service keys ghp_..., sk-proj-..., sk_live_..., xoxb-...
🟡 Medium JWTs, generic secrets eyJ..., high-entropy strings

200+ detection patterns covering AWS, OpenAI, Anthropic, GitHub, Stripe, Slack, Google, Azure, database URIs, private keys, and more.

What It Scans

Tool What we check
Claude Code ~/.claude/ conversations and project histories
Cursor ~/.cursor/ and ~/Library/Application Support/Cursor/
GitHub Copilot ~/Library/Application Support/GitHub Copilot Chat/
Continue.dev ~/.continue/ sessions
Windsurf ~/.windsurf/ and ~/.codeium/
Aider ~/.aider/ chat logs
Shell history ~/.zsh_history, ~/.bash_history, ~/.zshrc

CLI Options

citrusglaze-scan                      # All tools, last 30 days
citrusglaze-scan --tool claude        # Only Claude Code
citrusglaze-scan --days 7             # Last 7 days
citrusglaze-scan --days 0             # All time
citrusglaze-scan --json               # Machine-readable output
citrusglaze-scan --verbose            # Show file paths
citrusglaze-scan --path /some/dir     # Scan any directory

Privacy

  • Zero network calls. Never connects to the internet.
  • No telemetry. Nothing collected or transmitted.
  • Secrets are redacted in output — first 4 chars shown, rest masked.
  • Open source. Read every line: GitHub

Stop Future Leaks

This scanner finds secrets after they've been sent. To catch them before they reach AI providers:

CitrusGlaze is a local MITM proxy that scans every AI request in real-time. 210+ secret patterns. Blocks critical secrets. Redacts the rest. Works with 39+ AI tools.

Read the State of AI Traffic Report — what 26,000+ intercepted AI requests reveal about leaked secrets.

Install CitrusGlaze — 5-minute setup, no cloud, data never leaves your machine.

Zero Dependencies

Python standard library only. No pip dependencies. Works on Python 3.9+.

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

citrusglaze_scan-0.1.0.tar.gz (55.8 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

citrusglaze_scan-0.1.0-py3-none-any.whl (41.6 kB view details)

Uploaded Python 3

File details

Details for the file citrusglaze_scan-0.1.0.tar.gz.

File metadata

  • Download URL: citrusglaze_scan-0.1.0.tar.gz
  • Upload date:
  • Size: 55.8 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.9.6

File hashes

Hashes for citrusglaze_scan-0.1.0.tar.gz
Algorithm Hash digest
SHA256 ecbe623e8a5c202bec1a296a5c3896ea805671204841bf2d7646e76af75ded64
MD5 da1048bf6d217da10080575648af328d
BLAKE2b-256 60799a201a0fbc272a9b7d323c9d8638e2d25f354d681538fd68741cd1de6b94

See more details on using hashes here.

File details

Details for the file citrusglaze_scan-0.1.0-py3-none-any.whl.

File metadata

File hashes

Hashes for citrusglaze_scan-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 fdc30f983b53ca0a46b054fac3822e37a8e991f7e10b604bfadd2418837e1708
MD5 9845aa94ecea1462ad4ccee5822cfab8
BLAKE2b-256 bc70c5835d338f2e19d73c471a51b1ffda125a659b9a85bb93fe9acb4bf32594

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page