{"_id":"@0xkobold/pi-secret-guardian","name":"@0xkobold/pi-secret-guardian","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@0xkobold/pi-secret-guardian","version":"0.1.0","description":"Secret detection and pi-share-hf integration for pi-coding-agent. Scans projects, sessions, and environment for secrets, syncs to pi-share-hf workspace, and manages the collection/upload pipeline.","author":{"name":"0xKobold"},"license":"MIT","keywords":["pi-package","pi-extension","0xkobold","secrets","security","trufflehog","pi-share-hf"],"type":"module","main":"dist/index.js","types":"dist/index.d.ts","exports":{".":{"import":"./dist/index.js","types":"./dist/index.d.ts"},"./shared":{"import":"./dist/shared.js","types":"./dist/shared.d.ts"}},"scripts":{"build":"tsc","dev":"tsc --watch","test":"bun test","prepublishOnly":"rm -rf dist && tsc"},"pi":{"extensions":["./dist/index.js"]},"peerDependencies":{"@mariozechner/pi-coding-agent":">=0.65.0","@sinclair/typebox":">=0.32.0"},"devDependencies":{"@types/bun":"latest","@types/node":"^20.0.0","typescript":"^5.0.0"},"repository":{"type":"git","url":"git+https://github.com/0xKobold/pi-secret-guardian.git"},"bugs":{"url":"https://github.com/0xKobold/pi-secret-guardian/issues"},"homepage":"https://github.com/0xKobold/pi-secret-guardian#readme","gitHead":"07fde3625dcb115a25c2f9792f8ba33bff4b47b3","_id":"@0xkobold/pi-secret-guardian@0.1.0","_nodeVersion":"25.1.0","_npmVersion":"11.6.2","dist":{"integrity":"sha512-pmg+Ea+oWZ7Ha8HhnNcxJ1YSd0gOB3PRNce0GUPREscizW6xwlB1RLkPP8rNwHBfNfLXh4Bfsu0E+At7nYPIHw==","shasum":"de583e4e610aaec5f9aa332fcbff7ba5c26c5f40","tarball":"https://registry.npmjs.org/@0xkobold/pi-secret-guardian/-/pi-secret-guardian-0.1.0.tgz","fileCount":9,"unpackedSize":90043,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQCIwFyVmlsTsC/wpCnZ0/6WwQElge7XnprCIegW7MBCvAIgZoavWGi/kw555DfuRk5tnhqmsk1s/mgW0j2IWbWDEAA="}]},"_npmUser":{"name":"moikapy","email":"warrenckhan@gmail.com"},"directories":{},"maintainers":[{"name":"moikapy","email":"warrenckhan@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/pi-secret-guardian_0.1.0_1775700924325_0.7831932402580988"},"_hasShrinkwrap":false}},"time":{"created":"2026-04-09T02:15:24.212Z","0.1.0":"2026-04-09T02:15:24.490Z","modified":"2026-04-09T02:15:24.734Z"},"maintainers":[{"name":"moikapy","email":"warrenckhan@gmail.com"}],"description":"Secret detection and pi-share-hf integration for pi-coding-agent. Scans projects, sessions, and environment for secrets, syncs to pi-share-hf workspace, and manages the collection/upload pipeline.","homepage":"https://github.com/0xKobold/pi-secret-guardian#readme","keywords":["pi-package","pi-extension","0xkobold","secrets","security","trufflehog","pi-share-hf"],"repository":{"type":"git","url":"git+https://github.com/0xKobold/pi-secret-guardian.git"},"author":{"name":"0xKobold"},"bugs":{"url":"https://github.com/0xKobold/pi-secret-guardian/issues"},"license":"MIT","readme":"# 🛡️ pi-secret-guardian\n\nSecret detection and [pi-share-hf](https://github.com/badlogic/pi-share-hf) integration for [pi](https://pi.dev).\n\nPart of the [0xKobold](https://github.com/0xKobold) ecosystem.\n\n## What it does\n\n- **Scans** project files, pi sessions, and environment for secrets (API keys, tokens, passwords)\n- **Runs TruffleHog** for verified secret detection as a backstop\n- **Syncs** discovered secrets to pi-share-hf's `secrets.txt` for deterministic redaction\n- **Patches** pi-share-hf to load pi-ollama during LLM review (patches `--no-extensions`)\n- **Manages** the full collect → review → upload pipeline\n\n## Installation\n\n### Bundled (recommended)\n\n```bash\npi install npm:@0xkobold/pi-kobold\n# pi-secret-guardian loaded as sub-extension automatically\n```\n\n### Standalone\n\n```bash\npi install npm:@0xkobold/pi-secret-guardian\n\n# Or in pi-config.ts\n{\n  extensions: [\n    'npm:@0xkobold/pi-secret-guardian'\n  ]\n}\n\n# Or temporary (testing)\npi -e npm:@0xkobold/pi-secret-guardian\n```\n\n### External dependencies\n\n```bash\n# TruffleHog (required for verified secret detection)\nbrew install trufflehog\n\n# pi-share-hf (required for HF sync/upload)\nnpm install -g pi-share-hf\n```\n\n## Tools\n\n| Tool | Description |\n|------|-------------|\n| `secret_scan` | Scan project/sessions/env for secrets (pattern + TruffleHog) |\n| `secret_sync_hf` | Sync secrets to pi-share-hf workspace + run collect |\n| `secret_report` | Report on pi-share-hf workspace status |\n| `secret_upload` | Upload reviewed sessions to HuggingFace |\n\n## Commands\n\n| Command | Description |\n|---------|-------------|\n| `/secret-scan` | Quick scan for secrets |\n| `/hf-status` | Show pi-share-hf workspace status |\n\n## Usage\n\n### 1. Scan for secrets\n\n```\nRun secret_scan with scope=all and includeTruffleHog=true\n```\n\n### 2. Sync and collect\n\n```\nRun secret_sync_hf to sync secrets and run pi-share-hf collect\n```\n\n### 3. Review and upload\n\n```\nRun secret_report to check uploadable sessions\nRun secret_upload to upload to HuggingFace\n```\n\n## API / Library Usage\n\nTypes and utility functions are available for programmatic use:\n\n```typescript\n// Import from shared module (recommended)\nimport {\n  type SecretFinding,\n  type TruffleHogFinding,\n  type ScanResult,\n  maskSecret,\n  parseEnvFile,\n  parseNpmrc,\n  scanWithPatterns,\n  SECRET_PATTERNS,\n  ENV_FILES,\n} from \"@0xkobold/pi-secret-guardian/shared\";\n\n// Or from the main entry (convenience re-exports)\nimport { maskSecret, type SecretFinding } from \"@0xkobold/pi-secret-guardian\";\n\n// Mask a secret for safe display\nmaskSecret(\"ghp_ABCDEFGHIJKLMNOPQRSTUVWXYZ1234567890\");\n// → \"ghp_****890\"\n\n// Parse an .env file for secrets\nconst findings = parseEnvFile(envContent, \"/path/to/.env\");\n\n// Scan content against known patterns\nconst patternHits = scanWithPatterns(sourceCode, \"/path/to/file.ts\", \"project-file\");\n```\n\n## pi-share-hf Ollama Patch\n\npi-share-hf's LLM review subprocess uses `pi --no-extensions`, which prevents pi-ollama from loading. This extension includes a patch script that adds `-e <pi-ollama-path>` after `--no-extensions` so the review can use your ollama models.\n\nThe patch is applied automatically by `secret_sync_hf`. To apply manually:\n\n```bash\nbash packages/pi-secret-guardian/scripts/pi-share-hf-patch.sh\n```\n\nRe-run after any `npm update -g pi-share-hf`.\n\n## Configuration\n\n| File | Purpose |\n|------|---------|\n| `.pi/hf-sessions/secrets.txt` | Auto-managed list of secrets to redact |\n| `.pi/hf-sessions/deny.txt` | Regex patterns to reject sessions |\n| `.pi/hf-sessions/workspace.json` | pi-share-hf workspace config |\n\n## Architecture\n\n```\nsrc/\n├── index.ts    # Extension factory (4 tools + 2 commands + lifecycle hooks)\n└── shared.ts   # Types, patterns, and utility functions (library API)\nscripts/\n└── pi-share-hf-patch.sh  # Patches pi-share-hf for ollama support\n```\n\nIntegrated into pi-kobold as a sub-extension with duplicate-load guard.\n\n## Related Packages\n\n- [`@0xkobold/pi-kobold`](https://github.com/0xKobold/pi-kobold) — Meta-extension that bundles this and other sub-extensions\n- [`@0xkobold/pi-ollama`](https://github.com/0xKobold/pi-ollama) — Ollama integration (required for HF review patch)\n\n## Local Development\n\n```bash\ngit clone https://github.com/0xKobold/pi-secret-guardian\ncd pi-secret-guardian\nnpm install\nnpm run build\npi install ./\n```\n\n## License\n\nMIT © 0xKobold","readmeFilename":"README.md","_rev":"1-5ecbbe971193119626c689c5e4c6e7d5"}