AI-Native Secret Detection for Modern Development Teams
Stop secrets from leaking before they hit your repository
Demo โข Features โข Documentation โข Contributing โข Roadmap
$4.45 million โ the average cost of a data breach in 2023. Many start with a single leaked secret.
Developers accidentally commit API keys, database credentials, and tokens to repositories every day. Traditional scanners catch these after the damage is done.
ShepScan is an open-core AI-native security platform that:
- ๐ Scans repositories for 13+ secret types with regex + AI classification
- ๐ค Eliminates false positives using Claude/GPT-4 powered analysis
- ๐ฌ Explains risks in plain English โ built for founders, not just security teams
- ๐ Visualizes severity with real-time heat maps
| Feature | Description |
|---|---|
| 13+ Secret Patterns | AWS, Stripe, GitHub, Google, Slack, Discord, OpenAI, JWT, Private Keys, Database URLs |
| Git Integration | Clone any public GitHub repo and scan in seconds |
| Line-Level Results | Exact file path, line number, and redacted snippets |
| Severity Scoring | Critical, High, Medium, Low classifications |
| Feature | Description |
|---|---|
| Real vs False Positive | AI classifies if detected patterns are actual secrets |
| Confidence Scoring | 0-100% confidence on each detection |
| Founder Mode Explanations | Plain-English risk, impact, and remediation steps |
| Multi-Provider Support | Works with OpenAI GPT-4 or Anthropic Claude |
| Feature | Description |
|---|---|
| Severity Heat Map | Visual distribution of detected secrets |
| Expandable Details | Click any secret to see AI analysis |
| Scan History | Track previous scans and results |
| GitHub OAuth | Connect your account for personalized experience |
- Node.js 20+
- Git (for repo cloning)
- Docker (optional, for database)
git clone https://github.com/Radix-Obsidian/ShepScan.git
cd ShepScancd apps/api
npm install
npm run start:devcd apps/web
npm install
npm run devNavigate to http://localhost:3000 and scan your first repo!
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Frontend โ
โ Next.js 15 + React โ
โ TailwindCSS + shadcn/ui โ
โโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ REST API
โโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Backend โ
โ NestJS 10 โ
โ โโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโ โ
โ โ Scan Module โ โ AI Module โ โ Auth Module โ โ
โ โ โข Detection โ โ โข Classify โ โ โข GitHub OAuth โ โ
โ โ โข Git Clone โ โ โข Explain โ โ โข JWT Sessions โ โ
โ โโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโ โโโโโโโโโโโโโโโโโโโโโโโ โ
โโโโโโโโโโโโโโโโโโโโโโโฌโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ
โโโโโโโโโโโโโโโโโโโโโโโผโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
โ Infrastructure โ
โ PostgreSQL (Prisma) โข Redis โข OpenAI/Anthropic โ
โโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโโ
| Document | Description |
|---|---|
| Product Requirements (PRD) | Vision, goals, and user stories |
| System Design (SDD) | Architecture and module breakdown |
| Technical Design (TDD) | Implementation details and APIs |
Create apps/api/.env:
# Database
DATABASE_URL="postgresql://user:pass@localhost:5432/shepscan"
# AI Provider (choose one)
OPENAI_API_KEY=sk-...
# or
ANTHROPIC_API_KEY=sk-ant-...
# GitHub OAuth (optional)
GITHUB_CLIENT_ID=...
GITHUB_CLIENT_SECRET=...
# JWT
JWT_SECRET=your-secure-secret-here- Secret detection engine (13 patterns)
- GitHub repo scanning
- AI classification (OpenAI/Anthropic)
- Founder-friendly explanations
- Severity heat map
- GitHub OAuth
- Pre-commit hooks
- GitHub App integration
- Real-time push protection
- Slack/Discord notifications
- Private repo scanning
- Team management
- Audit logs
- SSO/SAML
We welcome contributions! ShepScan is an open-core project.
- Fork the repository
- Create a feature branch (
git checkout -b feature/amazing-feature) - Commit your changes (
git commit -m 'Add amazing feature') - Push to the branch (
git push origin feature/amazing-feature) - Open a Pull Request
See CONTRIBUTING.md for detailed guidelines.
This project is licensed under the MIT License โ see the LICENSE file for details.
ShepScan is built by Golden Sheep AI, a bootstrapped pre-seed startup focused on developer security tools.
Our Philosophy: Build narrow. Test deep. Ship confidently.