Finds credentials sitting in your coding-agent transcripts and shell history, scrubs them, and tells you which keys to rotate.
Keys pasted into prompts, printed by tool calls, or exported in a shell end up on disk in plaintext and stay there. On one real machine scrbddy found seven live credentials in a fish history going back months. It covers Claude Code, Codex, Cursor, opencode, Copilot, Aider and Gemini, plus zsh, bash, fish and REPL histories.
Once installed it edits your files nightly. It acts only on 30 rules — 29 provider token
formats plus PEM private keys — never generic or entropy-based ones. Redactions stay
reversible for 30 days: to put one back, run scrbddy rollback.
Requires Node 22+ and gitleaks.
brew install gitleaks
git clone https://github.com/chughtapan/scrbddy.git
cd scrbddy && npm install && npm run build && npm linkscrbddy status # what's on this machine
scrbddy scan --dry-run # find secrets, write nothing
scrbddy audit --rotate # which keys to rotate
scrbddy scan # scrub them
scrbddy install # run it daily from now on| See what can still be put back | scrbddy rollback --list |
| Put a redaction back | scrbddy rollback --id 42 |
| Put back everything one run changed | scrbddy rollback --run 7 |
| Put back everything in one file | scrbddy rollback --path ~/.zsh_history |
| Scan one source | scrbddy scan --source fish |
| Scan a file outside the registry | scrbddy path add ~/notes.md --kind text |
| Turn a source off | scrbddy source disable cursor |
| Ignore the cache and rescan everything | scrbddy scan --all |
| Remove the schedule | scrbddy uninstall |
| Filter the history | scrbddy audit --rule github-pat --since 2026-01-01 |
A partial status means some files were skipped rather than scanned. scrbddy status
names each one and the reason.
npm run check # typecheck + lint + testsArchitecture and rationale: docs/superpowers/specs/2026-08-04-scrbddy-design.md.