leakhound
leakhound is a fast local credential and secret scanner. It is a single C++17
binary with no external dependencies.
Build
With CMake:
cmake -S . -B build
cmake --build build --config Release
On Windows with the MSVC command prompt:
build.bat
The batch file runs:
cl /std:c++17 /O2 /W4 /EHsc src\leakhound.cpp /Fe:leakhound.exe
Usage
leakhound [options] <path>...
--json machine-readable output (one JSON object, findings array)
--no-entropy disable entropy heuristics (pattern rules only)
--max-size N skip files larger than N bytes (default 2 MiB)
--quiet suppress per-finding lines, print summary only
-h, --help usage
Paths may be files or directories. Directories are scanned recursively, while
common generated or dependency directories such as .git, node_modules,
vendor, dist, build, target, __pycache__, .venv, and venv are
skipped.
Default output:
HIGH aws-access-key path/to/file.txt:12 AKIA12...CDEF
Summary: files scanned=4, files skipped=1, HIGH=1, MEDIUM=0, LOW=0, wall time=3ms
JSON output:
leakhound --json .
Rules
| Rule ID | Severity | Pattern |
|---|---|---|
aws-access-key |
HIGH | AKIA[0-9A-Z]{16} |
github-token |
HIGH | gh[pousr]_[A-Za-z0-9]{36,} |
slack-token |
HIGH | xox[baprs]-[A-Za-z0-9-]{10,} |
stripe-live-key |
HIGH | sk_live_[A-Za-z0-9]{16,} |
private-key-pem |
HIGH | PEM private key header lines |
google-api-key |
HIGH | AIza[0-9A-Za-z_-]{35} |
npm-token |
HIGH | npm_[A-Za-z0-9]{36} |
jwt |
MEDIUM | JWT-shaped three-part token |
generic-assignment |
MEDIUM | Secret-like key assigned to a quoted non-placeholder value |
high-entropy-token |
LOW | High-entropy mixed-case token heuristic |
The entropy heuristic tokenizes each line into runs of
[A-Za-z0-9+/=_-] from 24 to 128 characters, then flags tokens with Shannon
entropy greater than 4.5 bits per character that contain at least one digit and
mixed case. Use --no-entropy to disable this tier.
Exit Codes
| Code | Meaning |
|---|---|
| 0 | Scan completed with no findings |
| 1 | Scan completed with findings |
| 2 | Usage or IO error |
Tests
python tests/run_tests.py
The test runner builds temporary fixtures, runs the scanner, checks exit codes,
validates JSON output, verifies redaction and placeholder rejection, and checks
binary, directory, and max-size skipping. If no compiler is available, set
LEAKHOUND_BIN to an existing scanner binary.
Metadata
Release files for leakhound 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| leakhound-0.1.0.tar.gz | 13.4 kB | Details |
Built distributions (wheels)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| leakhound-0.1.0-py3-none-win_amd64.whl | Python 3 | none | Windows x86-64 | Details |
| leakhound-0.1.0-py3-none-manylinux_2_28_x86_64.whl | Python 3 | none | Linux glibc 2.28+ x86-64 | Details |
| leakhound-0.1.0-py3-none-macosx_14_0_arm64.whl | Python 3 | none | macOS 14.0+ ARM64 | Details |
Total release size: 269.9 kB
Release files / leakhound-0.1.0.tar.gz
| Download URL | leakhound-0.1.0.tar.gz |
|---|---|
| Size | 13.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
6ad4c88d564c978ef9f605c8e970bf1dd9ab83622e24d4b8db42a007ff39d35d
|
|
BLAKE2b-256 checksum How to use checksums |
a825a2407bc8585347dc608c53f723a2166a6f6d6e30f59801c82d6dd64b469b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 23, 2026.
Transparency logRelease files / leakhound-0.1.0-py3-none-win_amd64.whl
| Download URL | leakhound-0.1.0-py3-none-win_amd64.whl |
|---|---|
| Size | 67.7 kB |
| Tags | Python 3 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
2e8906a16b8093f77a72e045b80d3a03e71004e8368799325b93ac7da40cb3db
|
|
BLAKE2b-256 checksum How to use checksums |
9444276ff0cf6097e7cf063a98863f3cc3f4aba16e78be793a3438b8702b132a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 23, 2026.
Transparency logRelease files / leakhound-0.1.0-py3-none-manylinux_2_28_x86_64.whl
| Download URL | leakhound-0.1.0-py3-none-manylinux_2_28_x86_64.whl |
|---|---|
| Size | 140.2 kB |
| Tags | Linux glibc 2.28+ x86-64 Python 3 |
|
SHA-256 checksum How to use checksums |
f468507e4372cbf3fedb7962c814aab763d6e81ab00389d92664cb00426ec217
|
|
BLAKE2b-256 checksum How to use checksums |
7c4c1d184d5c6f0c5b9605329b2c97050f94e7b96f2d4c5ae2a357bd2c7cf47b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 23, 2026.
Transparency logRelease files / leakhound-0.1.0-py3-none-macosx_14_0_arm64.whl
| Download URL | leakhound-0.1.0-py3-none-macosx_14_0_arm64.whl |
|---|---|
| Size | 48.7 kB |
| Tags | Python 3 macOS 14.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
ac562e9402667685debca63f998c3543d570446b4860b7299714b83cde27f569
|
|
BLAKE2b-256 checksum How to use checksums |
8057470a014885540f2b481d94258899cc703716255e0ec824c0e2e0fd14d0a4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jul 23, 2026.
Transparency log