Security signal without the noise

Find what your repository
should not be hiding.

Reposec brings secrets, personal data, risky code, Git history, and dependency vulnerabilities into one prioritized report—inside Claude Code or from the terminal.

Install ReposecView source

Claude Code
› /claude-reposec:nr-scan

  ✓ secrets       0 critical
  ✓ personal data 2 findings
  ✓ git history   checked
  ✓ source code   1 high
  ✓ dependencies  3 advisories

  Report ready · sensitive values redacted

Five complementary lenses

A practical repository review

01

Secrets

Detects cloud keys, tokens, private keys, connection strings, and other credentials across text files.

02

Personal data

Flags email, phone, SSN, and credit-card patterns, with Luhn validation to reduce false positives.

03

Git history

Finds sensitive content and filenames that were committed—even when they were later removed.

04

Code vulnerabilities

Surfaces risky patterns such as debug configuration, command injection, SQL concatenation, and missing auth.

05

Dependencies

Checks Python and npm package versions against OSV advisories, with a 24-hour local cache.

One marketplace, every plugin

Install in three steps

Python 3.10+ is required. Git enables history scanning, and internet access enables dependency checks through OSV.

  1. Install the CLI
    pipx install git+https://github.com/nikolareljin/claude-reposec
  2. Add the marketplace once
    /plugin marketplace add nikolareljin/claude-plugins
  3. Install, restart, and verify
    /plugin install claude-reposec@nikolareljin-plugins
    /plugin
    /claude-reposec:nr-scan

Use it your way

Interactive review or automated gate

Claude Code

/claude-reposec:nr-scan
/claude-reposec:nr-scan --quick
/claude-reposec:nr-scan --save

Review findings in context and save Markdown when you need an audit trail.

Standalone CLI

reposec scan path/to/repo
reposec scan --json
reposec scan --output report.md

Run the same scanners without Claude Code and choose readable or structured output.

Continuous integration

- name: Repository security
  run: |
    pipx install git+https://github.com/nikolareljin/claude-reposec
    reposec scan --ci

--ci exits 1 when HIGH or CRITICAL findings are present.

A deliberate data boundary

Your source stays local.

Secret values are redacted in output and are never stored or logged. Reports contain only safe previews.

Dependency checks send package names and versions to the OSV API. Source code and file paths are never included. Without network access, local scanners still run while OSV lookups are unavailable.

Part of a growing toolset

Explore the ecosystem