Repository Security Scanner
Scan a Git repository for malware, backdoors, and sketchy dependencies before you clone it. Static analysis, OSV.dev vulnerability checks, secret detection, entropy analysis, and Dockerfile linting in a single Python CLI.
The scanner flags:
- Crypto miner patterns
- Backdoor signatures
- Data exfiltration code
- Obfuscation techniques
- Dangerous function calls
- Vulnerable dependencies
- High-entropy (encrypted or obfuscated) files
- Hardcoded secrets and API keys
- Insecure Dockerfile patterns
Why?
Cloning a repo to audit it is already too late. Postinstall scripts, Makefiles, and CI configs run before you ever open the code. This tool scans before git clone completes, so you know what you are pulling in before it touches your machine.
Existing tools split the problem. gitleaks and trufflehog focus on secrets. semgrep and bandit focus on your own code. Neither answers the question you actually have when you find a random repo: is this safe to run?
How it compares
| Tool | Secrets | Malware | Deps | Entropy | Pre-clone |
|---|---|---|---|---|---|
| gitleaks | Yes | No | No | No | No |
| trufflehog | Yes | No | No | No | Partial |
| semgrep | No | Partial | No | No | No |
| repo-security-scanner | Yes | Yes | Yes | Yes | Yes |
Quick Start
pip install repo-security-scanner
repo-scanner https://github.com/user/repo.git
Installation
Requires Python 3.8 or higher.
From PyPI
pip install repo-security-scanner
repo-scanner https://github.com/user/repo.git
From source
git clone https://github.com/MR-UNKNOWN8014/repo-security-scanner.git
cd repo-security-scanner
python -m venv venv
source venv/bin/activate # Linux/macOS
venv\Scripts\activate # Windows
pip install -e .
repo-scanner https://github.com/user/repo.git
pip install -e . reads pyproject.toml, which declares requires-python = ">=3.8", so pip refuses to install on an older interpreter. Running python main.py <url> also works from a source checkout without installing.
Usage
Basic commands
# Remote repository
repo-scanner https://github.com/user/repo.git
# Local path
repo-scanner /path/to/local/repo
# Quick scan (size limited, good for CI)
repo-scanner https://github.com/user/repo.git --mode quick
# Thorough scan with detailed output
repo-scanner https://github.com/user/repo.git --mode thorough --detailed
# Export report to JSON
repo-scanner https://github.com/user/repo.git --output report.json
# Several formats from one scan
repo-scanner https://github.com/user/repo.git -o report.json -o results.sarif
# Query OSV.dev for live dependency vulnerabilities
repo-scanner https://github.com/user/repo.git --check-vulns
Arguments
| Option | Short | Description | Default |
|---|---|---|---|
--mode |
-m |
Scan mode: quick, balanced, thorough, smart | balanced |
--output |
-o |
Export report to JSON, CSV or SARIF by file extension. Repeatable. | None |
--verbose |
-v |
Show detailed scan progress | False |
--detailed |
-d |
Show detailed breakdown in report | False |
--format |
-f |
Report format: simple, multi, categories, detailed, all | all |
--fail-on |
-F |
Exit 1 when the risk score reaches this level: none, low, medium, high, critical | high |
--keep-repo |
-k |
Keep cloned repo after scanning. Only effective with --auto-decision; interactively, your answer decides. |
False |
--auto-decision |
-A |
Automatically decide based on risk score | False |
--check-vulns |
-c |
Query OSV.dev for every pinned dependency. Sends names and versions to a third party. | False |
Exit codes
| Code | Meaning |
|---|---|
| 0 | Scan completed below the --fail-on threshold |
| 1 | Risk score reached the --fail-on threshold |
| 2 | The scan itself failed, for example a clone error |
A threshold breach and a tool failure are deliberately different codes, so CI can tell a risky repository from a broken scanner and never fail open.
# fail the build only on a critical score
repo-scanner https://github.com/user/repo.git -A -F critical
# report everything, never fail the build
repo-scanner https://github.com/user/repo.git -A -F none
Scan modes
| Mode | Behavior | Files scanned |
|---|---|---|
| Quick | Fast, size limited | Files under 1 MB, max 10,000 |
| Balanced | Moderate coverage and speed | All valid files |
| Thorough | Everything | No limits. Will take time on large repos. |
| Smart | Prioritizes executables | Scripts, binaries, executables |
For CI pipelines, --mode quick is usually enough. For a full audit, use --mode thorough.
Ignoring known false positives
Drop a .reposecurityignore in the root of the repo being scanned. One glob pattern per line:
# skip test fixtures with fake credentials
tests/fixtures/*
*.sample.env
Lines starting with # and blank lines are ignored. Patterns match both the path relative to the repo root and the filename.
GitHub Action
Scan in CI, either your own checkout or a third party repository you are about to trust:
- uses: actions/checkout@v4
- uses: MR-UNKNOWN8014/repo-security-scanner@v1
with:
mode: quick
fail-on: high
The job fails when the score reaches fail-on, and fails separately when the scan itself could not complete, so a broken scan never reads as a pass. Outputs include risk-score, risk-level, findings-count and threshold-exceeded, and SARIF can be uploaded to GitHub Code Scanning.
Inputs, outputs, exit behavior and Code Scanning setup: docs/GITHUB_ACTION.md.
Detection capabilities
| Check | What it finds |
|---|---|
| Malicious patterns | Crypto miners, backdoors, data exfiltration, obfuscation, shell commands |
| Language-specific calls | Dangerous functions in Python, JavaScript, Bash, PHP, Ruby, Go, Rust, Java |
| Vulnerable dependencies | Pinned versions below a known-bad floor, plus live OSV.dev lookups |
| Secrets | AWS, GitHub, GitLab, Slack, Google, Stripe, Twilio, SendGrid keys, JWTs, more |
| Dockerfiles | Root user, curl-pipe-bash, insecure TLS, baked secrets |
| Cautions | Long lines, unpinned base images, ADD vs COPY, network calls, listed separately and never scored |
Full pattern lists, package lists and per-check behavior: docs/DETECTION_CAPABILITIES.md.
Risk scoring
Scores run 0 to 100. Higher means more risk.
| Score | Level | Recommendation |
|---|---|---|
| 0-9 | SAFE | Safe to clone |
| 10-24 | LOW RISK | Review before cloning |
| 25-49 | MEDIUM RISK | Exercise caution |
| 50-74 | HIGH RISK | Avoid cloning |
| 75-100 | CRITICAL | Do not clone |
The score is weighted by category. Malicious patterns and dangerous functions dominate. Entropy, base64, and file size are secondary signals. Vulnerable dependencies and Dockerfile findings add per-package or per-finding penalties. A confirmed secret can single-handedly push a file to CRITICAL.
Best practice notes such as long lines are reported as cautions, in their own section, and never affect the score. Every finding and caution reports the file it came from, and a line number wherever one applies.
Full breakdown: docs/SCORING_AND_FORMATS.md.
Report formats
Four formats, plus an all option that prints them in sequence:
- simple: one line with risk score, bar, and level
- multi: four-factor breakdown (code quality, security, obfuscation, malicious)
- categories: risk level, score, and file breakdown by severity
- detailed: everything above, plus file stats and top findings
repo-scanner https://github.com/user/repo.git --format simple
repo-scanner https://github.com/user/repo.git --format detailed
Sample output for each format lives in docs/SCORING_AND_FORMATS.md.
JSON and CSV export are separate from the display format:
repo-scanner https://github.com/user/repo.git --output report.json
repo-scanner https://github.com/user/repo.git --output report.csv
repo-scanner https://github.com/user/repo.git --output results.sarif
SARIF 2.1.0 is rendered natively by GitHub Code Scanning, so scan results show up in the Security tab. See docs/SCORING_AND_FORMATS.md.
Limitations
- Static analysis only. Obfuscated or packed payloads can evade detection.
- Pattern based detection produces false positives. Always review flagged files.
- Not a replacement for sandboxing or VM isolation when running untrusted code.
- Entropy detection is tuned to be sensitive. High entropy is a signal, not proof.
- Offline dependency checks cover a small curated list. Use
--check-vulnsfor full coverage.
Project structure
repo-security-scanner/
├── requirements.txt # Python dependencies
├── pyproject.toml # Packaging
├── README.md
├── LICENSE
├── run_scanner.py # Entry point
├── main.py # CLI entry point
│
├── .github/
│ ├── SECURITY.md # Vulnerability reporting policy
│ ├── PULL_REQUEST_TEMPLATE.md
│ ├── ISSUE_TEMPLATE/
│ │ ├── bug_report.md
│ │ ├── feature_request.md
│ │ ├── false_positive.md
│ │ └── config.yml
│ └── workflows/
│ ├── tests.yml # CI: test suite on push/PR
│ └── publish.yml # Publish to PyPI on GitHub Release
│
├── action.yml # GitHub Action definition
│
├── docs/
│ ├── SCORING_AND_FORMATS.md # Risk scoring and report formats
│ ├── DETECTION_CAPABILITIES.md # Full detection reference
│ └── GITHUB_ACTION.md # GitHub Action reference
│
├── tests/
│ ├── test_entropy_calculator.py
│ ├── test_pattern_matcher.py
│ ├── test_dependency_checker.py
│ ├── test_file_utils.py
│ ├── test_formatter.py
│ ├── test_scoring.py
│ ├── test_secret_detector.py
│ └── test_dockerfile_scanner.py
│
└── repo_scanner/
├── __init__.py
├── config.py
├── cli/
│ └── arguments.py
├── scanner/
│ ├── core.py
│ ├── file_analyzer.py
│ ├── pattern_matcher.py
│ ├── dependency_checker.py
│ ├── entropy_calculator.py
│ ├── secret_detector.py
│ └── dockerfile_scanner.py
├── report/
│ ├── formatter.py
│ └── exporters.py
├── models/
│ └── scan_result.py
└── utils/
├── file_utils.py
└── git_utils.py
Troubleshooting
| Problem | Check | Solution |
|---|---|---|
| Python not found | Python installed? | Install Python 3.8+ from python.org |
| ModuleNotFoundError | Dependencies installed? | Run pip install -r requirements.txt |
| Git clone failed | Git installed? | Install Git from git-scm.com |
| Command not found | Installed in this env? | pip install repo-security-scanner, or run python main.py from a checkout |
| Scan takes too long | Large repository? | Use --mode quick or --mode smart |
| Report not generated | Output path valid? | Check write permissions for the output directory |
| Entropy warnings | False positives? | Review the file. If it is legitimate, add it to .reposecurityignore |
Contributing
Pull requests welcome.
- Fork the repo
- Create a branch:
git checkout -b feature/my-feature - Run the tests:
python -m unittest discover -s tests -v - Commit:
git commit -m 'Add my feature' - Push:
git push origin feature/my-feature - Open a Pull Request
All PRs must pass CI (.github/workflows/tests.yml, Python 3.8 and 3.12) and stay compatible with Python 3.8+.
Reporting issues
When filing a bug, include:
- What you expected
- What actually happened
- Steps to reproduce
- OS and Python version
- Relevant logs or screenshots
License
MIT. See LICENSE.
Metadata
Release files for repo-security-scanner 0.3.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| repo_security_scanner-0.3.0.tar.gz | 40.5 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| repo_security_scanner-0.3.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 74.1 kB
Release files / repo_security_scanner-0.3.0.tar.gz
| Download URL | repo_security_scanner-0.3.0.tar.gz |
|---|---|
| Size | 40.5 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
6711a6b5b648c390ae9d1053d527adbd80062f184ffe0681f9587f2abf278570
|
|
BLAKE2b-256 checksum How to use checksums |
382a156342249d75f8610ae22532f8003407943fc5954715ac5336f3bf795c58
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 28, 2026.
Transparency logRelease files / repo_security_scanner-0.3.0-py3-none-any.whl
| Download URL | repo_security_scanner-0.3.0-py3-none-any.whl |
|---|---|
| Size | 33.5 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
6cbf1a45dad22c4b1db0294316e7e16df38ee8b9b6ea751fb73cb2a17c1eaee0
|
|
BLAKE2b-256 checksum How to use checksums |
fc173f87ecb84530a84d6d2742deafc06c526b4c51cf11302d11ca2bc771ff25
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 28, 2026.
Transparency log