{"_id":"@404labs/securitycheck","_rev":"3-b6dc7402591c5b535c272635ac64e381","name":"@404labs/securitycheck","dist-tags":{"latest":"0.2.1"},"versions":{"0.1.0":{"name":"@404labs/securitycheck","version":"0.1.0","keywords":["security","secrets","pre-commit","git-secrets","secret-scan","leak-detection","gitignore","git-hook","husky","lefthook","claude-code","claude-skill","anthropic","supply-chain"],"license":"MIT","_id":"@404labs/securitycheck@0.1.0","maintainers":[{"name":"error404_timeispassmeby","email":"FrancisLee920217@gmail.com"}],"homepage":"https://github.com/SpectreMercury/securitycheck#readme","bugs":{"url":"https://github.com/SpectreMercury/securitycheck/issues"},"bin":{"sec":"bin/cli.js","securitycheck":"bin/cli.js"},"dist":{"shasum":"92158483649a7aa4392ebff6b3372ef6fc84168d","tarball":"https://registry.npmjs.org/@404labs/securitycheck/-/securitycheck-0.1.0.tgz","fileCount":11,"integrity":"sha512-fzsbYCJThDL0N5oiJnJDHh8kOKTGYmtQOL2vOiGx6IYa/nTrnWEkIK5QIZ1Tb7n7ZzKElGNoWo7p1LvJ1yDbBw==","signatures":[{"sig":"MEQCIAdyV9dyzVsxA/UPOVn13ydYi5MKEB2nN8YglnMngjgyAiBGn2sJd/iDjt8/L+o/I2NcfavHYw2HrkgHcNqeRGYhKA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":42869},"main":"./lib/scan.js","engines":{"node":">=18"},"gitHead":"f17b9fc932c7277cf5715e6c0b42bc5b50d2be9c","scripts":{"scan":"node bin/cli.js scan","test":"node --test test/*.test.js"},"_npmUser":{"name":"error404_timeispassmeby","email":"FrancisLee920217@gmail.com"},"repository":{"url":"git+https://github.com/SpectreMercury/securitycheck.git","type":"git"},"_npmVersion":"11.3.0","description":"Pre-commit secret scanner. Blocks API keys, tokens, .env files, and private keys from leaking into git. Ships as a Claude Code skill and a standalone CLI / git hook.","directories":{},"_nodeVersion":"22.13.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/securitycheck_0.1.0_1779343692433_0.030759762248917966","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@404labs/securitycheck","version":"0.2.0","keywords":["security","secrets","pre-commit","git-secrets","secret-scan","leak-detection","gitignore","git-hook","husky","lefthook","claude-code","claude-skill","codex-cli","antigravity","kimi-cli","agent-skill","anthropic","openai","supply-chain"],"license":"MIT","_id":"@404labs/securitycheck@0.2.0","maintainers":[{"name":"error404_timeispassmeby","email":"FrancisLee920217@gmail.com"}],"homepage":"https://github.com/SpectreMercury/404labs/tree/master/securitycheck#readme","bugs":{"url":"https://github.com/SpectreMercury/404labs/issues"},"bin":{"sec":"bin/cli.js","securitycheck":"bin/cli.js"},"dist":{"shasum":"1ffd28f8d2577f08e276cad7ec2ff6fd8fae968d","tarball":"https://registry.npmjs.org/@404labs/securitycheck/-/securitycheck-0.2.0.tgz","fileCount":11,"integrity":"sha512-3f+GY36NGXPd0oIJGaBjx0KZCbMxDWWJ8mxIizppRoqn/DPY9dXizRZEM9qNsHriKZxXfagGttxLaE1spqdHUA==","signatures":[{"sig":"MEUCIHZkTHhSrn8rh/9YxfmiMmLMzxx6+FwnliQ/ubgpUe4hAiEAr+sf147fjWuzH26OCEffY/qqURqYg/orYWO+ByoVQCk=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":49405},"main":"./lib/scan.js","engines":{"node":">=18"},"gitHead":"8d43fc91fa4a405a5291d6cd0dda218a092e6e79","scripts":{"scan":"node bin/cli.js scan","test":"node --test test/*.test.js"},"_npmUser":{"name":"error404_timeispassmeby","email":"FrancisLee920217@gmail.com"},"repository":{"url":"git+https://github.com/SpectreMercury/404labs.git","type":"git","directory":"securitycheck"},"_npmVersion":"11.3.0","description":"Pre-commit secret scanner. Blocks API keys, tokens, .env files, and private keys from leaking into git. Ships as a skill for Claude Code, OpenAI Codex CLI, Google Antigravity, and Moonshot Kimi CLI, plus a standalone CLI / git hook.","directories":{},"_nodeVersion":"22.13.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/securitycheck_0.2.0_1779418945567_0.5259659543960731","host":"s3://npm-registry-packages-npm-production"}},"0.2.1":{"name":"@404labs/securitycheck","version":"0.2.1","description":"Pre-commit secret scanner. Blocks API keys, tokens, .env files, and private keys from leaking into git. Ships as a skill for Claude Code, OpenAI Codex CLI, Google Antigravity, and Moonshot Kimi CLI, plus a standalone CLI / git hook.","bin":{"securitycheck":"bin/cli.js","sec":"bin/cli.js"},"main":"./lib/scan.js","scripts":{"test":"node --test test/*.test.js","scan":"node bin/cli.js scan"},"keywords":["security","secrets","pre-commit","git-secrets","secret-scan","leak-detection","gitignore","git-hook","husky","lefthook","claude-code","claude-skill","codex-cli","antigravity","kimi-cli","agent-skill","anthropic","openai","supply-chain"],"license":"MIT","engines":{"node":">=18"},"repository":{"type":"git","url":"git+https://github.com/SpectreMercury/404labs.git","directory":"securitycheck"},"bugs":{"url":"https://github.com/SpectreMercury/404labs/issues"},"homepage":"https://github.com/SpectreMercury/404labs/tree/master/securitycheck#readme","_id":"@404labs/securitycheck@0.2.1","gitHead":"c0eefb2fe68237e22e942f9cb5e3a998f129c470","_nodeVersion":"22.13.0","_npmVersion":"11.3.0","dist":{"integrity":"sha512-Ba7A/FtV3rErzhwMS1Qc3Cq+o7lG9kBLuyXpAXt+LY4VaeRBI5bcDt+518KxLKzVoVpoga3jlJ+hgK6bP36lbg==","shasum":"f62223508305346a876489922fa1677313186c92","tarball":"https://registry.npmjs.org/@404labs/securitycheck/-/securitycheck-0.2.1.tgz","fileCount":11,"unpackedSize":49879,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIDdnpfOB2858/vEY8H1u01vtKQ2RIYGIKUl6+kCFeZBgAiBVvl4FSJEGJmYXhDddYwriVV+HnzZf9AhWaCvpBbgGoQ=="}]},"_npmUser":{"name":"error404_timeispassmeby","email":"FrancisLee920217@gmail.com"},"directories":{},"maintainers":[{"name":"error404_timeispassmeby","email":"FrancisLee920217@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/securitycheck_0.2.1_1779423444722_0.8739796033754541"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-21T06:08:12.288Z","modified":"2026-05-22T04:17:25.034Z","0.1.0":"2026-05-21T06:08:12.598Z","0.2.0":"2026-05-22T03:02:25.713Z","0.2.1":"2026-05-22T04:17:24.918Z"},"bugs":{"url":"https://github.com/SpectreMercury/404labs/issues"},"license":"MIT","homepage":"https://github.com/SpectreMercury/404labs/tree/master/securitycheck#readme","keywords":["security","secrets","pre-commit","git-secrets","secret-scan","leak-detection","gitignore","git-hook","husky","lefthook","claude-code","claude-skill","codex-cli","antigravity","kimi-cli","agent-skill","anthropic","openai","supply-chain"],"repository":{"type":"git","url":"git+https://github.com/SpectreMercury/404labs.git","directory":"securitycheck"},"description":"Pre-commit secret scanner. Blocks API keys, tokens, .env files, and private keys from leaking into git. Ships as a skill for Claude Code, OpenAI Codex CLI, Google Antigravity, and Moonshot Kimi CLI, plus a standalone CLI / git hook.","maintainers":[{"name":"error404_timeispassmeby","email":"FrancisLee920217@gmail.com"}],"readme":"# securitycheck\n\n> Block API keys, tokens, `.env` files, and private keys from leaking into\n> git. Ships as a **skill for Claude Code, OpenAI Codex CLI, Google\n> Antigravity, and Moonshot Kimi CLI**, plus a standalone **CLI / git hook**\n> that works without any agent.\n\nAfter the GitHub OAuth-token compromise in early 2026, \"my repo is private\"\nstopped being a credible secrets-management strategy. Any secret committed\nto a repo — public or private — should be considered compromised the moment\nit enters `.git/objects`. `securitycheck` runs before commits land so it\nnever gets that far.\n\n---\n\n## What it does\n\nThree phases, always run all three:\n\n1. **`.gitignore` audit** — verifies the file exists and covers `.env`,\n   `*.pem`, `*.key`, SSH keys, `.aws/`, service-account JSON. Flags any\n   sensitive file that's already tracked (a `.gitignore` rule does not\n   retroactively untrack).\n2. **Staged-file check** — refuses to commit a `.env`, private key, or\n   credential file, regardless of content.\n3. **Diff content scan** — applies ~30 provider-specific regexes to the\n   staged diff. Catches AWS, GitHub, OpenAI, Anthropic, Google, Slack,\n   Stripe, npm, DigitalOcean, HuggingFace, Azure, MongoDB/Postgres URIs,\n   PEM private key blocks, JWT, and generic `password=...` assignments\n   (under `--strict`).\n\nFindings come back as **BLOCK** (exit 1, refuse commit) or **WARN** (looks\nlike a placeholder or public sample — human verifies).\n\n---\n\n## Install\n\n### As an agent skill\n\n**Recommended — via the [Vercel Labs `skills` CLI](https://github.com/vercel-labs/skills)**\n(supports 55+ agent CLIs including Claude Code, Codex, Antigravity,\nKimi, Cursor, OpenCode, Gemini CLI, Cline, Roo, Windsurf, Qwen Code,\nGoose, …; auto-detects which one you have):\n\n```bash\n# Install to whichever agent is detected on this machine\nnpx skills add SpectreMercury/404labs --skill securitycheck\n\n# Install globally instead of project-local\nnpx skills add SpectreMercury/404labs --skill securitycheck -g\n\n# Install to every supported agent on your system\nnpx skills add SpectreMercury/404labs --skill securitycheck --all\n\n# Target specific agents\nnpx skills add SpectreMercury/404labs --skill securitycheck -a claude-code -a codex\n```\n\n**Alternative — via this package's built-in installer** (no extra CLI\nneeded, but covers only the four listed below):\n\n```bash\nnpx @404labs/securitycheck install                      # auto-detect, install to each\nnpx @404labs/securitycheck install --target all         # install for all 4 supported\nnpx @404labs/securitycheck install --target claude,kimi # comma-separated explicit list\nnpx @404labs/securitycheck install --list-targets       # show what's supported\n```\n\n| Built-in target | CLI | Path |\n|---|---|---|\n| `claude` | Claude Code | `~/.claude/skills/securitycheck/` |\n| `codex` | OpenAI Codex CLI | `~/.agents/skills/securitycheck/` |\n| `antigravity` | Google Antigravity | `~/.gemini/antigravity/skills/securitycheck/` |\n| `kimi` | Moonshot Kimi CLI | `~/.kimi/skills/securitycheck/` |\n\nAll paths receive the same `SKILL.md` (YAML frontmatter + Markdown).\nRestart your CLI so the skill index picks it up.\n\n**For agents with no native skill loader — go through a host CLI:**\n\n- **Zhipu GLM** — distribute via\n  [GLM-skills / clawhub](https://github.com/zai-org/GLM-skills), or just\n  call `npx @404labs/securitycheck scan` from your own pre-commit hook.\n- **MiniMax** — use the\n  [MiniMax-AI/skills](https://github.com/MiniMax-AI/skills) marketplace\n  (it redistributes into Claude Code / Cursor) or wire the CLI in\n  manually.\n\n### As a one-off CLI\n\n```bash\nnpx @404labs/securitycheck scan          # scan the staged diff\nnpx @404labs/securitycheck scan --strict # also generic password=... heuristics\nnpx @404labs/securitycheck scan --all    # scan working tree, not just staged\nnpx @404labs/securitycheck scan --json   # machine-readable output\n```\n\nAfter a global install (`npm i -g @404labs/securitycheck`) the `securitycheck`\nbinary is on your `$PATH`, so you can drop the `npx @404labs/` prefix.\n\n### As a git pre-commit hook (no dependencies)\n\n```bash\nnpx @404labs/securitycheck hook > .git/hooks/pre-commit\nchmod +x .git/hooks/pre-commit\n```\n\n### With Husky\n\n```bash\nnpm install -D husky @404labs/securitycheck\nnpx husky init\necho 'npx securitycheck scan' > .husky/pre-commit\n```\n\n### With lefthook\n\n```yaml\n# lefthook.yml\npre-commit:\n  commands:\n    securitycheck:\n      run: npx securitycheck scan\n```\n\n---\n\n## Output\n\n```\nsecuritycheck — pre-commit scan\n\n  .gitignore:      present\n  BLOCK findings:  2\n  WARN findings:   1\n\n  BLOCK — do not commit:\n    • src/config.ts:14 — Anthropic API key [anthropic-key]\n      const key = \"sk-ant-api03-AbCdEf...\";\n    • .env — staged sensitive file\n      Fix: git restore --staged \".env\" && add to .gitignore\n\n  WARN — verify these manually:\n    • tests/fixtures/token.js:3 — JWT-shaped token [jwt]\n      const t = \"eyJhbGciOiJIUzI1NiJ9.eyJzdWIiOiIxMjM...\";\n\n  ✗ 2 blocking finding(s). Refusing to commit.\n    Bypass (NOT recommended): SECURITYCHECK_SKIP=1 git commit ...\n```\n\nJSON mode (`--json`) emits the same data as a single JSON object — see\n`test/scan.test.js` for the shape.\n\n---\n\n## Exit codes\n\n| Code | Meaning |\n|---|---|\n| `0` | Clean, or WARN-only |\n| `1` | One or more BLOCK findings |\n| `2` | Usage error or not a git repository |\n\n---\n\n## What it catches\n\nFull catalogue in [skill/references/secret-patterns.md](skill/references/secret-patterns.md).\nHighlights:\n\n| Provider | Token shape |\n|---|---|\n| AWS | `AKIA…`, `ASIA…`, `aws_secret_access_key=\"…\"` |\n| GitHub | `ghp_…`, `github_pat_…`, `gho_…`, `ghs_…`, `ghu_…`, `ghr_…` |\n| Anthropic | `sk-ant-api03-…`, `sk-ant-admin01-…` |\n| OpenAI | `sk-…`, `sk-proj-…` |\n| Google | `AIza…`, `GOCSPX-…`, `\"type\": \"service_account\"` |\n| Slack | `xoxb-…`, `xoxp-…`, `hooks.slack.com/services/…` |\n| Stripe | `sk_live_…`, `rk_live_…`, `sk_test_…` (WARN) |\n| npm / HF / DO | `npm_…`, `hf_…`, `dop_v1_…` |\n| Azure | `DefaultEndpointsProtocol=…;AccountKey=…` |\n| Databases | `mongodb://user:pass@…`, `postgres://user:pass@…` |\n| Private keys | `-----BEGIN (RSA\\|EC\\|OPENSSH\\|PGP) PRIVATE KEY-----` |\n| Generic | `password=`, `secret=`, `api_key=` (`--strict` only) |\n\nPlaceholder-like strings (`YOUR_API_KEY`, `xxx`, `changeme`, `<API_KEY>`)\nare auto-downgraded to WARN.\n\n---\n\n## When a real secret is found\n\nIf the secret has ever been committed (not just staged), unstaging is not\nenough. In order:\n\n1. **Rotate at the provider immediately.** Assume it's already compromised.\n2. **Remove from history** — `git filter-repo --path <file> --invert-paths`\n   or BFG. Squashing in a PR does not remove the blob.\n3. **Force-push.** Coordinate with collaborators; this rewrites shared\n   history.\n4. **Add the path to `.gitignore`** so it can't come back.\n\nOrder matters. Cleaning a still-valid key buys nothing — the attacker\nalready has it cached.\n\n---\n\n## Configuration\n\nNo config file. Behaviour is controlled by CLI flags:\n\n```\n--all         Scan working tree, not just staged diff\n--strict      Enable lower-confidence heuristics (more false positives)\n--json        Machine-readable output\n--no-color    Disable ANSI colors\n--no-ignore   Skip the .gitignore audit\n--no-files    Skip the sensitive-file presence check\n--no-content  Skip the diff content scan\n```\n\nEnvironment:\n\n- `SECURITYCHECK_SKIP=1` — bypass entirely. Intended for emergencies only;\n  the output makes the bypass visible in CI logs.\n\n---\n\n## FAQ\n\n**Why not use `gitleaks` / `trufflehog`?**\nUse them too if you can — they're battle-tested. `securitycheck` is\nzero-config, has no Go/Python dependency, and ships as a Claude Code skill\nso the agent inside your editor checks before you do. If a repo already\nruns `gitleaks` in CI, this is a strictly local belt-and-suspenders.\n\n**False positives?**\nThree guards: provider-specific prefixes (we don't match `sk-` generically;\nwe require `sk-proj-` / `sk-ant-` / 32+ chars and not a Stripe prefix); a\nplaceholder heuristic that downgrades `YOUR_API_KEY`/`xxx`/`changeme`; and\na `--strict` opt-in for the lossy generic `password=` rule.\n\n**False negatives?**\nYes, by design. We don't do entropy scanning in v0.1 — it has too many\nfalse positives without per-language tuning. Add provider-specific patterns\nvia PR; see [`skill/references/secret-patterns.md`](skill/references/secret-patterns.md).\n\n**Why ship a Claude Code skill at all?**\nBecause the agent writing your code is also the one most likely to paste a\nsecret into it. Wiring `securitycheck` into the agent's pre-commit\nworkflow closes that loop before the commit reaches your git index.\n\n---\n\n## Roadmap\n\n- [ ] Entropy-based detection (opt-in, per-file-type tuned)\n- [ ] `gitleaks`-compatible config file consumption\n- [ ] Pre-push hook variant that scans the full pushed range\n- [ ] GitHub Action wrapper\n- [ ] Per-project pattern overrides via `.securitycheck.json`\n\n---\n\n## License\n\nMIT — see [LICENSE](LICENSE).\n","readmeFilename":"README.md"}