{"_id":"@01a/git-sentinel","_rev":"4-404182b7e1d35c64f32ba78f041c962d","name":"@01a/git-sentinel","dist-tags":{"latest":"1.1.4"},"versions":{"1.1.0":{"name":"@01a/git-sentinel","version":"1.1.0","keywords":[],"author":"","license":"ISC","_id":"@01a/git-sentinel@1.1.0","maintainers":[{"name":"eknowlton","email":"eknowlton@gmail.com"}],"bin":{"git-sentinel":"dist/index.js"},"dist":{"shasum":"801d13998816686708953f5a570c5507bae22a4f","tarball":"https://registry.npmjs.org/@01a/git-sentinel/-/git-sentinel-1.1.0.tgz","fileCount":17,"integrity":"sha512-dX3KJ85GCIwi9lyQdkFqZf2140Sp49ufYJHRo1oVpuYLGdDBIb6OTNQmJj7gP+pt/gsXR5Is6FlbZAQaSTJeNw==","signatures":[{"sig":"MEUCIAJLpV6fJo9JVMSQYwCgIhi5zLXOtPwySFjcZwk8xbozAiEAvFD0FeSEobAEi6EaqDSErdS/kAA2256HCNInCR7uZNk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":31615},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"7031a7ad61baa5499c959cb05b5071a4f34a0ea5","scripts":{"test":"echo \"Error: no test specified\" && exit 1","build":"tsc","start":"node --loader ts-node/esm src/index.ts"},"_npmUser":{"name":"eknowlton","email":"eknowlton@gmail.com"},"_npmVersion":"10.9.3","description":"Git Sentinel is a powerful security scanner designed to analyze Git repositories for malicious code patterns, BiDi (bidirectional) attacks, and obfuscated malware. It helps developers and security researchers safely inspect untrusted repositories before r","directories":{},"_nodeVersion":"22.20.0","dependencies":{"chalk":"^5.6.2","commander":"^14.0.3","dockerode":"^4.0.10","simple-git":"^3.33.0","@types/chalk":"^0.4.31","@types/dockerode":"^4.0.1"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","ts-node":"^10.9.2","typescript":"^5.9.3","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/git-sentinel_1.1.0_1774233378049_0.09161275401457236","host":"s3://npm-registry-packages-npm-production"}},"1.1.2":{"name":"@01a/git-sentinel","version":"1.1.2","keywords":[],"author":"","license":"ISC","_id":"@01a/git-sentinel@1.1.2","maintainers":[{"name":"eknowlton","email":"eknowlton@gmail.com"}],"bin":{"git-sentinel":"dist/index.js"},"dist":{"shasum":"5a876e4a54fe4443e4c32e42498b5a57cfac4e03","tarball":"https://registry.npmjs.org/@01a/git-sentinel/-/git-sentinel-1.1.2.tgz","fileCount":17,"integrity":"sha512-x3o02vTDgAebfx+NTLBmVZ4hsHfmU1E6ymLd+Brhu8LcdidTJ5xll59CZHoH+zJHOOCdLkNcAmGDh3OuTSrNug==","signatures":[{"sig":"MEQCIDxTRY+6A+n9iyqBID/y0keSKSPGmfKPKezoDv9ntyf1AiBaZoXfmMvt0hspDHQfcC/erGAA3k6agIjmBrCrBdNZ5g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":32155},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"a713ea30243d4d33f8c18c85b7a2061720ec180f","scripts":{"test":"echo \"Error: no test specified\" && exit 1","build":"tsc","start":"node --loader ts-node/esm src/index.ts"},"_npmUser":{"name":"eknowlton","email":"eknowlton@gmail.com"},"_npmVersion":"10.9.3","description":"[![npm version](https://img.shields.io/npm/v/@01a/git-sentinel.svg)](https://www.npmjs.com/package/@01a/git-sentinel) [![npm downloads](https://img.shields.io/npm/dm/@01a/git-sentinel.svg)](https://www.npmjs.com/package/@01a/git-sentinel) [![license](http","directories":{},"_nodeVersion":"22.20.0","dependencies":{"chalk":"^5.6.2","commander":"^14.0.3","dockerode":"^4.0.10","simple-git":"^3.33.0","@types/chalk":"^0.4.31","@types/dockerode":"^4.0.1"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","ts-node":"^10.9.2","typescript":"^5.9.3","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/git-sentinel_1.1.2_1774233881031_0.5128299459229506","host":"s3://npm-registry-packages-npm-production"}},"1.1.3":{"name":"@01a/git-sentinel","version":"1.1.3","keywords":[],"author":"","license":"ISC","_id":"@01a/git-sentinel@1.1.3","maintainers":[{"name":"eknowlton","email":"eknowlton@gmail.com"}],"bin":{"git-sentinel":"dist/index.js"},"dist":{"shasum":"54d9b11937115bd7830124382f550555cd99ddaf","tarball":"https://registry.npmjs.org/@01a/git-sentinel/-/git-sentinel-1.1.3.tgz","fileCount":17,"integrity":"sha512-ELlbSHSEzcVzWCGxoz4wJfxwd+IiIH09b2TY+pyd3W+oP9kskZqIvnSOVIT9knTBvqMTet0HpoRpE/J6IBhwWQ==","signatures":[{"sig":"MEQCICHaoUsRdOB3EjOUikoSv9N/8hN/ajRLsO6Nb0Z9pj+AAiA8cfiSFlSh30oF4InsEKPQNnyqoU27P5lFquDzYWSUlw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":32197},"main":"dist/index.js","type":"module","types":"./dist/index.d.ts","gitHead":"a58c7a359822d7859ce95e119ee64bbc7c3851d1","scripts":{"test":"echo \"Error: no test specified\" && exit 1","build":"tsc","start":"node --loader ts-node/esm src/index.ts"},"_npmUser":{"name":"eknowlton","email":"eknowlton@gmail.com"},"_npmVersion":"10.9.3","description":"[![npm version](https://img.shields.io/npm/v/@01a/git-sentinel.svg)](https://www.npmjs.com/package/@01a/git-sentinel) [![npm downloads](https://img.shields.io/npm/dm/@01a/git-sentinel.svg)](https://www.npmjs.com/package/@01a/git-sentinel) [![license](http","directories":{},"_nodeVersion":"22.20.0","dependencies":{"chalk":"^5.6.2","commander":"^14.0.3","dockerode":"^4.0.10","simple-git":"^3.33.0","@types/chalk":"^0.4.31","@types/dockerode":"^4.0.1"},"_hasShrinkwrap":false,"devDependencies":{"tsx":"^4.21.0","ts-node":"^10.9.2","typescript":"^5.9.3","@types/node":"^25.5.0"},"_npmOperationalInternal":{"tmp":"tmp/git-sentinel_1.1.3_1774234167562_0.0386765394515185","host":"s3://npm-registry-packages-npm-production"}},"1.1.4":{"name":"@01a/git-sentinel","version":"1.1.4","description":"[![npm version](https://img.shields.io/npm/v/@01a/git-sentinel.svg)](https://www.npmjs.com/package/@01a/git-sentinel) [![npm downloads](https://img.shields.io/npm/dm/@01a/git-sentinel.svg)](https://www.npmjs.com/package/@01a/git-sentinel) [![license](http","main":"dist/index.js","bin":{"git-sentinel":"dist/index.js"},"scripts":{"test":"echo \"Error: no test specified\" && exit 1","start":"node --loader ts-node/esm src/index.ts","build":"tsc"},"keywords":[],"author":"","license":"ISC","devDependencies":{"@types/node":"^25.5.0","ts-node":"^10.9.2","tsx":"^4.21.0","typescript":"^5.9.3"},"dependencies":{"@types/chalk":"^0.4.31","@types/dockerode":"^4.0.1","chalk":"^5.6.2","commander":"^14.0.3","dockerode":"^4.0.10","simple-git":"^3.33.0"},"type":"module","_id":"@01a/git-sentinel@1.1.4","gitHead":"0b7eae702d6db5c159501133991712b2bf49a23c","types":"./dist/index.d.ts","_nodeVersion":"22.20.0","_npmVersion":"10.9.3","dist":{"integrity":"sha512-qgTYGmDSJ21h2NUR71/cbnnJFn2Ob1mfJJBemFgYJuVW9P4O2QduxZH28g+nBJREC01RtjsRR1l3PyvLcteV3w==","shasum":"eaa46661f00d2c1e330304b2fa74bd8c919f69d6","tarball":"https://registry.npmjs.org/@01a/git-sentinel/-/git-sentinel-1.1.4.tgz","fileCount":18,"unpackedSize":38653,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIBsL3Q9jBGvpvDGVcwt2ChG6Z1/gkXGA0/vXCd4fZYrPAiBmixIlub4uV8B750ILxbLKR3RWW9NMhrDiPoHbkzHR9w=="}]},"_npmUser":{"name":"eknowlton","email":"eknowlton@gmail.com"},"directories":{},"maintainers":[{"name":"eknowlton","email":"eknowlton@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/git-sentinel_1.1.4_1774318934543_0.08866651848728746"},"_hasShrinkwrap":false}},"time":{"created":"2026-03-23T02:36:17.932Z","modified":"2026-03-24T02:22:14.835Z","1.1.0":"2026-03-23T02:36:18.184Z","1.1.2":"2026-03-23T02:44:41.181Z","1.1.3":"2026-03-23T02:49:27.714Z","1.1.4":"2026-03-24T02:22:14.696Z"},"license":"ISC","keywords":[],"description":"[![npm version](https://img.shields.io/npm/v/@01a/git-sentinel.svg)](https://www.npmjs.com/package/@01a/git-sentinel) [![npm downloads](https://img.shields.io/npm/dm/@01a/git-sentinel.svg)](https://www.npmjs.com/package/@01a/git-sentinel) [![license](http","maintainers":[{"name":"eknowlton","email":"eknowlton@gmail.com"}],"readme":"# Git Sentinel\n\n[![npm version](https://img.shields.io/npm/v/@01a/git-sentinel.svg)](https://www.npmjs.com/package/@01a/git-sentinel)\n[![npm downloads](https://img.shields.io/npm/dm/@01a/git-sentinel.svg)](https://www.npmjs.com/package/@01a/git-sentinel)\n[![license](https://img.shields.io/npm/l/@01a/git-sentinel.svg)](https://www.npmjs.com/package/@01a/git-sentinel)\n\nGit Sentinel is a powerful security scanner designed to analyze Git repositories for malicious code patterns, BiDi (bidirectional) attacks, and obfuscated malware.\n It helps developers and security researchers safely inspect untrusted repositories before running scripts or including them in their projects.\n\n## Features\n\n- **Repository Scanning**: Scan local directories or remote Git repositories by URL.\n- **BiDi Attack Detection**: Identifies Unicode control characters (BiDi) that can visually reorder code logic to hide malicious intent.\n- **Pattern Matching**: Uses a robust set of predefined rules to detect reverse shells, persistence mechanisms, dropper behaviors, and obfuscation.\n- **Custom Rules**: Extend the scanner with your own JSON-based rule sets.\n- **Isolated Sandbox**: Safely execute repository scripts (like `./configure` or install scripts) in an isolated, non-networked Docker container.\n- **Suspicious Filename Detection**: Flags files with names like `...` or ` .` commonly used by malware.\n- **Obfuscation Detection**: Identifies excessively long lines and common obfuscation techniques (Base64 eval, character concatenation).\n\n## Installation\n\n### Prerequisites\n\n- [Node.js](https://nodejs.org/) (v16 or higher)\n- [Docker](https://www.docker.com/) (required for sandbox execution)\n- [Git](https://git-scm.com/)\n\n### Setup\n\n1. Clone this repository:\n   ```bash\n   git clone https://github.com/youruser/git-sentinel.git\n   cd git-sentinel\n   ```\n\n2. Install dependencies:\n   ```bash\n   npm install\n   ```\n\n3. Build the project:\n   ```bash\n   npm run build\n   ```\n\n## Usage\n\nThe easiest way to run Git Sentinel is with `npx`:\n\n```bash\nnpx @01a/git-sentinel scan <url-or-path> [options]\n```\n\nOr you can run it directly using `npm start` after cloning the repository.\n\n### Self-Scanning Example\n\nYou can try scanning this repository itself to see Git Sentinel in action:\n\n```bash\nnpx @01a/git-sentinel scan git@github.com:eknowlton/git-sentinel.git\n```\n\n### Options\n\n| Option | Shortcut | Description |\n|--------|----------|-------------|\n| `--run-script <script>` | `-s` | Execute a specific script from the repo in an isolated sandbox. |\n| `--rules-dir <dir>` | `-r` | Include custom JSON rule files from a specific directory. |\n| `--keep-repo` | | Do not delete the cloned repository after the scan completes. |\n| `--version` | `-v` | Show the version number. |\n| `--help` | `-h` | Show help information. |\n\n### Example with Sandbox\n\nTo scan a repository and safely test its `install.sh` script:\n```bash\nnpm start -- scan https://github.com/example/repo.git -s ./install.sh\n```\n\n## Custom Rules\n\nCustom rules are JSON files containing an array of rule objects.\n\nExample `custom-rules/my-rules.json`:\n```json\n[\n  {\n    \"pattern\": \"rm -rf /\",\n    \"description\": \"Attempted destruction of the root directory\",\n    \"severity\": \"critical\"\n  }\n]\n```\n\nRun with custom rules:\n```bash\nnpm start -- scan ./target-repo -r ./custom-rules\n```\n\n## How the Sandbox Works\n\nThe sandbox uses Docker to create an isolated environment with the following constraints:\n- **No Network**: The container has no internet access (`--network none`).\n- **Read-Only Mount**: The repository is mounted as read-only at `/repo`.\n- **Resource Limits**: Limited to 512MB RAM and 0.5 CPU core.\n- **Non-Privileged User**: Scripts run as a restricted `sentinel` user.\n- **Base Image**: Uses a lightweight Alpine Linux image with `bash`, `python3`, and `coreutils` pre-installed.\n\n## Disclaimer and Limitation of Liability\n\n**Git Sentinel is provided \"as is\", without warranty of any kind, express or implied.** \n\nThe authors and contributors of this project:\n- **Do not guarantee** the detection of all malicious patterns or security threats.\n- **Are not responsible** for any damage to your system, data loss, or security breaches that may occur while using this tool or as a result of relying on its findings.\n- **Do not endorse** or guarantee the safety of any repository scanned by this tool, even if no issues are found.\n\nSecurity scanning is an inherently complex task. This tool should be used as part of a broader security strategy and not as a sole source of truth. **Use at your own risk.**\n\n## License\n\nISC License. See `package.json` for details.\n","readmeFilename":"README.md"}