Skip to main content

Secret Scan CLI

Scan a local directory for likely leaked credentials (AWS keys, GitHub tokens, Slack tokens, private keys, generic api_key= assignments) -- offline, no dependencies. Python 3.8+, stdlib only (re, os, argparse). No network at runtime.

Install

pip install plainkitbin-secret-scan-cli

Usage

secret-scan-cli .
secret-scan-cli path/to/repo

Exits with code 1 if any finding is present, 0 otherwise (suitable for a pre-commit hook or CI check). Matches are redacted in the output (only the first/last 4 characters are shown).

What it detects

Fixed regex patterns for: AWS access keys, GitHub personal access tokens (ghp_...), Slack tokens (xox...), PEM-style private key blocks, and a generic api_key = "..." pattern.

Limitations

Pattern-based only -- no entropy analysis, no support for credential formats outside the five patterns above, and no historical git-log scanning (working tree only). This will miss credentials that do not match a known shape. It is a lightweight local check, not a substitute for a dedicated credential-scanning service.

Free and open source (MIT license, see LICENSE). No telemetry, no network calls, no nagware.

Part of the PlainKitBin toolset.

Provided as-is with no individual support.


Built with AI assistance and automatically tested before release; released under human oversight.

Metadata

Release files for plainkitbin-secret-scan-cli 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for plainkitbin-secret-scan-cli 1.0.0
File Size Uploaded
plainkitbin_secret_scan_cli-1.0.0.tar.gz 4.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for plainkitbin-secret-scan-cli 1.0.0
File Interpreter ABI Platform
plainkitbin_secret_scan_cli-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 10.6 kB

Release files / plainkitbin_secret_scan_cli-1.0.0.tar.gz

Download URL plainkitbin_secret_scan_cli-1.0.0.tar.gz
Size 4.9 kB
Tags Source
SHA-256 checksum
How to use checksums
24d086de6dfa21d4eaf31015bdc688717dedb40068a0875575bf46a5c0b56110
BLAKE2b-256 checksum
How to use checksums
37b663b6da19a5100a6ebf5d1c2cc766b2e7aaec82681e1bb35e03ef1b7190d7
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.3

Release files / plainkitbin_secret_scan_cli-1.0.0-py3-none-any.whl

Download URL plainkitbin_secret_scan_cli-1.0.0-py3-none-any.whl
Size 5.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
4511b997a22eaa3f4a548031a20ab1344a2b2643f216c2d4c1397603cdf3cb6d
BLAKE2b-256 checksum
How to use checksums
f5ba696ce17988c528d81e09dd44483853b6cef08700201326eb3a7b8befbcee
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.12.3

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page