Skip to main content

Repository Security Scanner

CI Python 3.8+ License: MIT PyPI Stars

A Python-based security tool that analyzes Git repositories for malicious code, backdoors, obfuscation, and suspicious patterns before you clone them. It provides risk scoring and actionable recommendations.

The scanner performs static analysis on repository files, detecting:

  • Crypto miner patterns
  • Backdoor signatures
  • Data exfiltration code
  • Obfuscation techniques
  • Dangerous function calls
  • Vulnerable dependencies
  • High-entropy (encrypted/obfuscated) files
  • Hardcoded secrets and API keys
  • Insecure Dockerfile patterns

Why?

Cloning a repo to audit it is already too late — postinstall scripts, Makefiles, and CI configs run before you ever open the code. This tool scans before git clone completes, so you know what you're pulling in before it can touch your machine.

Built because existing tools (gitleaks, trufflehog) focus on secrets, and SAST tools (semgrep, bandit) focus on your code. Neither answers the question: "is this random GitHub repo safe to run?"


Quick Start

# Clone the repository
git clone https://github.com/MR-UNKNOWN8014/repo-security-scanner.git
cd repo-security-scanner

# Install dependencies
./setup.sh          # Linux/macOS
setup.bat           # Windows

# Scan a repository
python run_scanner.py https://github.com/user/repo.git

1. Installation:

Needs Python 3.8 or Higher to work.

1.2 Linux / macOS

# Linux/Mac
chmod +x setup.sh

# Windows
./setup.sh

The installer will:

  • Verify Python version
  • Install all required dependencies
  • Create the run script

[!TIP] If Python is not in your PATH, the installer will prompt you to install Python 3.8+ from python.org.

1.3 Manual Installation

# Create virtual environment (optional)
python -m venv venv

# Linux/Mac
source venv/bin/activate 

# Windows
venv\Scripts\activate

# Install dependencies
pip install -r requirements.txt

1.4 Install as a Package

The project also ships a pyproject.toml, so it can be installed as an editable package instead of running the scripts directly:

pip install -e .

# now available as a command anywhere in the venv
repo-scanner https://github.com/user/repo.git

2. Usage

2.1 Basic Commands

# Scan remote repository
python run_scanner.py https://github.com/user/repo.git

# Scan local repository
python run_scanner.py /path/to/local/repo

# Quick scan (limited files)
python run_scanner.py https://github.com/user/repo.git --mode quick

# Thorough scan with detailed output
python run_scanner.py https://github.com/user/repo.git --mode thorough --detailed

# Export report to JSON
python run_scanner.py https://github.com/user/repo.git --output report.json

# Check every pinned dependency against OSV.dev's live vulnerability database
python run_scanner.py https://github.com/user/repo.git --check-vulns

2.2 Command Line Arguments

Option Short Description Default
--mode -m Scan mode: quick, balanced, thorough, smart (detail below on types) balanced
--output -o Export report to JSON or CSV file None
--verbose -v Display detailed scan progress False
--detailed -d Show detailed breakdown in report False
--format - Report format: simple, multi, categories, detailed, all (detail below on types) all
--keep-repo - Keep cloned repository after scanning False
--auto-decision - Automatically decide based on risk score False
--check-vulns - Query OSV.dev for live known vulnerabilities in every pinned dependency (sends dependency names/versions to a third-party service) False

2.3 Scan Modes

Mode Description Files Scanned
Quick Fast scanning with size limits Files < 1MB, max 10,000
Balanced Moderate coverage with good speed All valid files
Thorough Complete scanning All files without limits (will take some time if too many files or big size)
Smart Prioritizes executable/script files Scripts, binaries, executables

[!TIP] Use --mode quick for CI/CD pipelines and --mode thorough for security audits.

2.4 Ignoring Known False Positives

Drop a .reposecurityignore file in the root of the repository being scanned to skip specific files or paths, one glob pattern per line:

# skip test fixtures with fake credentials
tests/fixtures/*
*.sample.env

Lines starting with # and blank lines are ignored. Patterns match against both the file's path relative to the repo root and its filename.


3. Report Formats

The scanner supports four report formats, plus an "all" option that displays them sequentially.

3.1 Simple Format

Single percentage score with status bar and risk level.

============================================================
  REPOSITORY: awesome-project
  RISK SCORE: 23.5%  [████████░░░░░░░░░░░░]   LOW RISK
============================================================

3.2 Multi-Factor Format

Breaks down risk into four categories with individual scores.

============================================================
  REPOSITORY: awesome-project
  
  MULTI-FACTOR ANALYSIS
  Code Quality:  76.3%  [██████████░░░░░░]
  Security:      76.5%  [██████████░░░░░░]
  Obfuscation:   16.5%  [██░░░░░░░░░░░░░░]
  Malicious:     11.8%  [█░░░░░░░░░░░░░░░]
  
  OVERALL: 23.5%  LOW RISK
============================================================

3.3 Categories Format

Displays risk category with file breakdown and recommendation.

============================================================
  REPOSITORY: awesome-project
  
  [LOW] RISK
  
  Risk Level:    [LOW]
  Score:         23.5%
  Findings:      12 issues found
  Files:         0 high, 3 medium, 9 low
  Recommendation: REVIEW BEFORE CLONING
============================================================

3.4 Detailed Format

Complete report including all findings and statistics.

============================================================
  REPOSITORY: awesome-project
  
  [LOW] RISK
  
  Risk Level:    [LOW]
  Score:         23.5%
  Findings:      12 issues found
  Files:         0 high, 3 medium, 9 low
  Recommendation: REVIEW BEFORE CLONING
============================================================

FILE BREAKDOWN:
  Safe:        45
  Low Risk:    9
  Medium Risk: 3
  High Risk:   0

STATISTICS:
  Total Files:     57
  Scan Duration:   4.32s
  Findings Found:  12

TOP FINDINGS:
  1. [MEDIUM] encoding: Multiple base64 strings: 8
  2. [MEDIUM] vulnerable_dependency: NPM package 'lodash': Prototype pollution vulnerabilities
  3. [LOW] dangerous_function: Dangerous function: eval
  4. [LOW] network: Network activity: HTTP request

4. Risk Scoring

4.1 Risk Levels

Score Level Recommendation
0-9 SAFE Safe to clone
10-24 LOW RISK Review before cloning
25-49 MEDIUM RISK Exercise caution
50-74 HIGH RISK Avoid cloning
75-100 CRITICAL Do not clone

4.2 Scoring Factors

Factor Maximum Points Description
Malicious Patterns 100 Crypto miners, backdoors, exfiltration
Dangerous Functions 100 eval, exec, system, subprocess
Entropy Analysis 20 High entropy indicates encryption/obfuscation
Base64 Encoding 10 Large base64 strings may contain payloads
File Size 10 Large files may contain hidden payloads
Vulnerable Dependencies 15 per package (20 if confirmed via --check-vulns) Known vulnerable packages
Secret Detection 80 per secret Hardcoded API keys, tokens, passwords, private keys
Dockerfile Issues 3-20 per finding Unpinned images, root user, curl-pipe-bash, hardcoded secrets

5. Detection Capabilities

5.1 Malicious Pattern Categories

Category Example Patterns
Crypto Miners cryptonight, stratum, xmrig, mining, cpuminer
Backdoors socket.bind, socket.connect, base64.b64decode
Data Exfiltration requests.post, discord webhook, smtplib, telegram
Obfuscation base64, zlib, exec(decode), String.fromCharCode
Shell Commands subprocess, os.system, popen, eval
Network Activity socket, requests, urllib, websocket, ftp
File Operations os.remove, shutil.rmtree, file.write, os.chmod

5.2 Language-Specific Detection

Language Detected Functions
Python exec, eval, compile, import, os.system, subprocess.call, subprocess.Popen, os.popen
JavaScript eval, Function, setTimeout, setInterval, document.write, innerHTML
Bash exec, eval, source, export, alias
PHP eval, system, exec, passthru, shell_exec, assert
Ruby eval, exec, system, ``, IO.popen, Open3
Go os/exec, syscall, reflect, unsafe
Rust std::process, std::fs, unsafe, std::mem
Java Runtime.exec, ProcessBuilder, System.load, Class.forName

5.3 Vulnerable Dependency Detection

Offline (default): checks pinned versions of the packages below against a known-bad floor. A package is only flagged if the pinned version is actually below the fixed version; unpinned or unparseable version specs are skipped rather than guessed at.

Package Manager Checked Packages
npm crypto-js, node-fetch, axios, lodash, request
pip requests, urllib3, paramiko, cryptography, pyyaml

Online (--check-vulns): additionally queries the OSV.dev API for every pinned dependency in requirements.txt/package.json, not just the packages above, against its live vulnerability database. Off by default since it sends dependency names and versions to a third-party service.

5.4 Secret Detection

Scans every text file for hardcoded credentials: AWS/GitHub/GitLab/Slack/Google/Stripe/Twilio/SendGrid keys, private key blocks, JWTs, and generic api_key/secret/token/password assignments. Matches are reported with a file and line number but the value itself is redacted (AKIA************WXYZ), never printed in full. Known placeholder values (EXAMPLE, changeme, <your_key_here>, etc.) are filtered out so docs and templates don't trip it. Any confirmed secret pushes that file's risk score into the CRITICAL range on its own.

Add real fixtures containing fake secrets you need to keep to .reposecurityignore (see 2.4) to suppress them.

5.5 Dockerfile Scanning

Any Dockerfile, Dockerfile.*, or *.dockerfile is additionally checked for:

Check What it catches
Unpinned base image FROM image:latest or no tag at all
Root user No USER instruction, or an explicit USER root
ADD vs COPY ADD used for a local file instead of COPY (ADD's extra behavior is only needed for URLs/archives)
Pipe to shell curl | bash, wget | sh, etc.
Insecure TLS curl -k, --no-check-certificate
Hardcoded secret ENV/ARG setting a PASSWORD/SECRET/TOKEN/API_KEY directly

6. Project Structure

repo-security-scanner/
├── setup.sh                 # Linux/macOS installer
├── setup.bat                # Windows installer
├── requirements.txt         # Python dependencies
├── pyproject.toml          # Packaging (pip install -e .)
├── README.md                # Documentation
├── LICENSE                  # MIT License
├── .gitignore              # Git ignore file
├── run_scanner.py          # Entry point
├── main.py                 # CLI entry point (main())
│
├── .github/
│   └── workflows/
│       └── tests.yml       # CI: runs the test suite on push/PR
│
├── tests/                   # Unit tests (unittest)
│   ├── test_entropy_calculator.py
│   ├── test_pattern_matcher.py
│   ├── test_dependency_checker.py
│   ├── test_file_utils.py
│   ├── test_scoring.py
│   ├── test_secret_detector.py
│   └── test_dockerfile_scanner.py
│
└── repo_scanner/           # Main package
    ├── __init__.py
    ├── config.py           # Configuration and constants
    ├── cli/                # Command-line interface
    │   ├── __init__.py
    │   └── arguments.py    # Argument parsing
    │
    ├── scanner/            # Core scanning modules
    │   ├── __init__.py
    │   ├── core.py         # Scanner orchestrator
    │   ├── file_analyzer.py # Individual file analysis
    │   ├── pattern_matcher.py # Pattern detection engine
    │   ├── dependency_checker.py # Dependency scanning (offline + OSV.dev)
    │   ├── entropy_calculator.py # Entropy analysis
    │   ├── secret_detector.py # Credential/API key/token detection
    │   └── dockerfile_scanner.py # Dockerfile security linting
    │
    ├── report/             # Report generation
    │   ├── __init__.py
    │   ├── formatter.py    # Output formatting
    │   └── exporters.py    # JSON/CSV export
    │
    ├── models/             # Data models
    │   ├── __init__.py
    │   └── scan_result.py  # Result data structures
    │
    └── utils/              # Utility functions
        ├── __init__.py
        ├── file_utils.py   # File operations, .reposecurityignore
        └── git_utils.py    # Git operations

7. Troubleshooting

Problem Check Solution
Python not found Python installed? Install Python 3.8+ from python.org
ModuleNotFoundError Dependencies installed? Run pip install -r requirements.txt
Git clone failed Git installed? Install Git from git-scm.com
Permission denied File permissions? chmod +x setup.sh (Linux/macOS)
Scan takes too long Large repository? Use --mode quick or --mode smart
Report not generated Output path valid? Check write permissions for output directory
High entropy warnings False positives? Review the file manually, may be legitimate. Add it to .reposecurityignore to suppress it going forward

8. Future Enhancements

  • Secret detection - API keys, passwords, tokens, credentials
  • Dockerfile scanning - insecure base images, root user, secrets in ENV/ARG, curl-pipe-bash
  • Git history analysis - scan commit history for secrets and keys
  • License checker - detect incompatible or restrictive licenses
  • Binary signature analysis - verify binaries from trusted sources
  • Database of known malicious repositories
  • Package registry scanning (PyPI, npm, RubyGems)

9. Contributing and Bugs

9.1 Pull Request Process

  1. Fork the repository
  2. Create a feature branch: git checkout -b feature/AmazingFeature
  3. Run the test suite locally: python -m unittest discover -s tests -v
  4. Commit your changes: git commit -m 'Add some AmazingFeature'
  5. Push to the branch: git push origin feature/AmazingFeature
  6. Submit a Pull Request

9.2 Reporting Issues

When reporting issues on GitHub, include:

  • Description of the issue
  • Steps to reproduce
  • Expected behavior
  • Actual behavior
  • Environment (OS, Python version)
  • Logs or screenshots (if applicable)

This all so I can work on those bugs and make the tool better.

Metadata

Release files for repo-security-scanner 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for repo-security-scanner 0.1.0
File Size Uploaded
repo_security_scanner-0.1.0.tar.gz 34.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for repo-security-scanner 0.1.0
File Interpreter ABI Platform
repo_security_scanner-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 65.1 kB

Release files / repo_security_scanner-0.1.0.tar.gz

Download URL repo_security_scanner-0.1.0.tar.gz
Size 34.4 kB
Tags Source
SHA-256 checksum
How to use checksums
aecf0e51b6a17d9d7e0abfd56c79bcfc3943a9bb53f20195c704fd4f6b7a6f4e
BLAKE2b-256 checksum
How to use checksums
112cb52bedc41976acf98b76c2babaf01ebb6db947fbbc59b377d31936a6890c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 17, 2026.

Transparency log

Release files / repo_security_scanner-0.1.0-py3-none-any.whl

Download URL repo_security_scanner-0.1.0-py3-none-any.whl
Size 30.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
bbe34aa4c8bd79caa29c80306cafa2b1206c0359c007c85dd274f9821239e58b
BLAKE2b-256 checksum
How to use checksums
2a242a90e806c0e2164eef43ac533ecf698eeb166c6c19b2bb85f0d9051f92f4
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 17, 2026.

Transparency log

Release history Release notifications | RSS feed

0.3.0

2 release files

0.2.0

2 release files

0.1.1

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page