Skip to main content

Scan AI chat histories for leaked secrets. Find out what you've accidentally shared with AI providers.

Project description

🔍 CitrusGlaze Scan

How many secrets have you leaked to AI? Find out in 15 seconds.

We scanned one developer's AI chat history. 169 secrets in 30 days. AWS keys, private keys, database passwords — all sent to AI providers in prompts.

100% local. No data leaves your machine. Zero dependencies.

Install & Run

pip3 install citrusglaze-scan
python3 -m citrusglaze_scan

Or with pipx (no install needed):

pipx run citrusglaze-scan

That's it. Results in 15 seconds.

What It Finds

Severity What Examples
🔴 Critical Cloud credentials, private keys, DB passwords AKIA..., -----BEGIN RSA PRIVATE KEY-----, postgresql://admin:pass@prod
🟠 High API tokens, service keys ghp_..., sk-proj-..., sk_live_..., xoxb-...
🟡 Medium JWTs, generic secrets eyJ..., high-entropy strings

200+ detection patterns covering AWS, OpenAI, Anthropic, GitHub, Stripe, Slack, Google, Azure, database URIs, private keys, and more.

What It Scans

Tool What we check
Claude Code ~/.claude/ conversations and project histories
Cursor ~/.cursor/ and ~/Library/Application Support/Cursor/
GitHub Copilot ~/Library/Application Support/GitHub Copilot Chat/
Continue.dev ~/.continue/ sessions
Windsurf ~/.windsurf/ and ~/.codeium/
Aider ~/.aider/ chat logs
Shell history ~/.zsh_history, ~/.bash_history, ~/.zshrc

CLI Options

python3 -m citrusglaze_scan                      # All tools, last 30 days
python3 -m citrusglaze_scan --tool claude        # Only Claude Code
python3 -m citrusglaze_scan --days 7             # Last 7 days
python3 -m citrusglaze_scan --days 0             # All time
python3 -m citrusglaze_scan --json               # Machine-readable output
python3 -m citrusglaze_scan --verbose            # Show file paths
python3 -m citrusglaze_scan --path /some/dir     # Scan any directory

Privacy

  • Zero network calls. Never connects to the internet.
  • No telemetry. Nothing collected or transmitted.
  • Secrets are redacted in output — first 4 chars shown, rest masked.
  • Open source. Read every line: GitHub

Stop Future Leaks

This scanner finds secrets after they've been sent. To catch them before they reach AI providers:

CitrusGlaze is a local MITM proxy that scans every AI request in real-time. 210+ secret patterns. Blocks critical secrets. Redacts the rest. Works with 39+ AI tools.

Read the State of AI Traffic Report — what 26,000+ intercepted AI requests reveal about leaked secrets.

Install CitrusGlaze — 5-minute setup, no cloud, data never leaves your machine.

Zero Dependencies

Python standard library only. No pip dependencies. Works on Python 3.9+.

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

citrusglaze_scan-0.1.1.tar.gz (42.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

citrusglaze_scan-0.1.1-py3-none-any.whl (42.1 kB view details)

Uploaded Python 3

File details

Details for the file citrusglaze_scan-0.1.1.tar.gz.

File metadata

  • Download URL: citrusglaze_scan-0.1.1.tar.gz
  • Upload date:
  • Size: 42.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/6.2.0 CPython/3.9.6

File hashes

Hashes for citrusglaze_scan-0.1.1.tar.gz
Algorithm Hash digest
SHA256 97edb80231de9689fd427f5dad80b38051b2169382567f3b7081e8df5daeb4b8
MD5 e4406b3ceb4fabacb62367813b3e1d21
BLAKE2b-256 7c05aea5d18e29af661fdd31150b3d578e6895393c56cb87547e9fa5a6d25e4c

See more details on using hashes here.

File details

Details for the file citrusglaze_scan-0.1.1-py3-none-any.whl.

File metadata

File hashes

Hashes for citrusglaze_scan-0.1.1-py3-none-any.whl
Algorithm Hash digest
SHA256 d8666af971e7fa9d14b30680872e7fdcd6197ca4bdde6467416fa291016f6387
MD5 5b7bdeb5636b2fc3f7bd15cb493ce16f
BLAKE2b-256 40bb53e5f850417cde33baa716506e2a0298ff9ee0b0978cbbe70272e7731673

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page