Skip to main content

secmend

Find leaked secrets in your code — and get an exact, AI-generated remediation playbook to revoke, rotate, and scrub them from git history.

CI Python 3.9+ License: MIT

Most secret scanners stop at detection — they tell you a key leaked and leave you to figure out the fix. But the real gap isn't detection, it's follow-through: studies show a majority of leaked credentials stay active for years after exposure, while an exposed cloud key can be abused within minutes.

secmend closes that gap. It detects secrets and hands you a concrete, provider-specific playbook: what to revoke right now, how to rotate, the exact git/BFG commands to purge it from history, and how to stop it happening again.

🔑 3 secret(s) detected:
  ● AWS Access Key ID (critical) AKIA************MPLE  config.py:4
  ● GitHub Personal Access Token (critical) ghp_********************************wxyz  config.py:5
  ● Stripe Secret Key (critical) sk_l************************uvwx  config.py:6

🛠  Remediation (critical): Live credentials were committed and must be treated as compromised.

🚨 Immediate actions:
  › Deactivate the AWS key: IAM → Users → Security credentials → Make inactive → Delete.
  › Revoke the GitHub token at github.com/settings/tokens.
  › Roll the Stripe key in the Stripe Dashboard → Developers → API keys.
🔄 Rotate & update:  …
🧹 Scrub from git history:  …
🛡  Prevent recurrence:  …

Why secmend

Typical scanner secmend
Detects secrets ✅ ✅
Tells you how to fix each one ❌ ✅ provider-specific
Git-history scrub commands ❌ ✅
Prevention guidance ❌ ✅
Works with no API key — ✅ --detect-only / mock / local Ollama
Never sends the secret to an LLM — ✅ only masked metadata leaves your machine

Safety first

  • Your secrets never leave your machine. Only the type of each finding (e.g. "AWS Access Key ID") is sent to the LLM — never the value. Previews are masked.
  • Read-only. secmend never edits, commits, or deletes anything. It advises; you run the commands.
  • No key required to get value: --detect-only and --provider mock are fully offline; --provider ollama uses a local model.

Install

# from source (until published to PyPI)
git clone https://github.com/jay-tank/secmend.git
cd secmend
pip install .
# for the Claude / OpenAI providers:
pip install '.[claude]'   # or '.[openai]'

Usage

# Scan a file or a whole directory
secmend ./src

# Scan a staged diff (great as a pre-commit / CI gate)
git diff --cached | secmend --stdin

# Check a single value you're worried about
secmend --secret "ghp_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx"

# Detection only — no LLM, fully offline, exits non-zero if anything is found
secmend ./src --detect-only

# Pick a provider (default: claude). mock needs no key.
secmend ./src --provider mock
secmend ./src --provider ollama
secmend ./src --json

Exit codes: 0 = clean, 1 = secret(s) found, 2 = usage/read error — so it drops straight into a CI step or git hook.

Providers

Provider Flag Needs
Claude (default) --provider claude ANTHROPIC_API_KEY + pip install '.[claude]'
OpenAI --provider openai OPENAI_API_KEY + pip install '.[openai]'
Ollama (local) --provider ollama a running local Ollama
Mock (offline) --provider mock nothing — deterministic demo output

See docs/PROVIDERS.md for configuration and docs/USAGE.md for recipes (pre-commit hook, CI gate, JSON piping).

What it detects

AWS keys, GitHub PATs (classic + fine-grained), GitLab PATs, Stripe keys, OpenAI / Anthropic / Google / Slack / SendGrid / PyPI tokens, private keys, JWTs, Slack webhooks, and generic password/secret/token = … assignments. Detection is pattern-based and best-effort — it complements, not replaces, a full history scanner like gitleaks.

Limitations

  • Pattern-based detection can miss custom/obfuscated secrets and may flag look-alikes. Treat findings as a prioritized starting point.
  • Remediation guidance is AI-generated — read before running any command, especially history rewrites.
  • v1 advises; it does not call provider APIs to rotate keys for you (by design).

License

MIT — see LICENSE.

Metadata

Release files for secmend 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for secmend 0.1.0
File Size Uploaded
secmend-0.1.0.tar.gz 18.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for secmend 0.1.0
File Interpreter ABI Platform
secmend-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 35.6 kB

Release files / secmend-0.1.0.tar.gz

Download URL secmend-0.1.0.tar.gz
Size 18.3 kB
Tags Source
SHA-256 checksum
How to use checksums
23be166e474a2df8764fbfeaeba3b6f9bd5dfb215714818d0af400b3f4f4c151
BLAKE2b-256 checksum
How to use checksums
7f3370c63145f47e1b65119f790db5a19d9ebc1ae960de7f8266313db44428b0
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.13

Release files / secmend-0.1.0-py3-none-any.whl

Download URL secmend-0.1.0-py3-none-any.whl
Size 17.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
f1446832263cbe324a258c620f313f44a31c40bca3014746ca09102f149b690f
BLAKE2b-256 checksum
How to use checksums
2def0caccadf1521ef6a5c0c9b56554bb73317c19a4b6dabe17d57f4778e974b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.12.13

Release history Release notifications | RSS feed

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page