Secrets
Detects cloud keys, tokens, private keys, connection strings, and other credentials across text files.
Security signal without the noise
Reposec brings secrets, personal data, risky code, Git history, and dependency vulnerabilities into one prioritized report—inside Claude Code or from the terminal.
› /claude-reposec:nr-scan
✓ secrets 0 critical
✓ personal data 2 findings
✓ git history checked
✓ source code 1 high
✓ dependencies 3 advisories
Report ready · sensitive values redactedFive complementary lenses
Detects cloud keys, tokens, private keys, connection strings, and other credentials across text files.
Flags email, phone, SSN, and credit-card patterns, with Luhn validation to reduce false positives.
Finds sensitive content and filenames that were committed—even when they were later removed.
Surfaces risky patterns such as debug configuration, command injection, SQL concatenation, and missing auth.
Checks Python and npm package versions against OSV advisories, with a 24-hour local cache.
One marketplace, every plugin
Python 3.10+ is required. Git enables history scanning, and internet access enables dependency checks through OSV.
pipx install git+https://github.com/nikolareljin/claude-reposec/plugin marketplace add nikolareljin/claude-plugins/plugin install claude-reposec@nikolareljin-plugins
/plugin
/claude-reposec:nr-scanUse it your way
/claude-reposec:nr-scan
/claude-reposec:nr-scan --quick
/claude-reposec:nr-scan --saveReview findings in context and save Markdown when you need an audit trail.
reposec scan path/to/repo
reposec scan --json
reposec scan --output report.mdRun the same scanners without Claude Code and choose readable or structured output.
- name: Repository security
run: |
pipx install git+https://github.com/nikolareljin/claude-reposec
reposec scan --ci--ci exits 1 when HIGH or CRITICAL findings are present.
A deliberate data boundary
Secret values are redacted in output and are never stored or logged. Reports contain only safe previews.
Dependency checks send package names and versions to the OSV API. Source code and file paths are never included. Without network access, local scanners still run while OSV lookups are unavailable.
Part of a growing toolset