chughtapan/scrbddy

Scans coding-agent transcripts and shell history for credentials, redacts them, and records what to rotate

★ 0Forks 0TypeScriptGitHub ↗Compare

README

scrbddy

Finds credentials sitting in your coding-agent transcripts and shell history, scrubs them, and tells you which keys to rotate.

Keys pasted into prompts, printed by tool calls, or exported in a shell end up on disk in plaintext and stay there. On one real machine scrbddy found seven live credentials in a fish history going back months. It covers Claude Code, Codex, Cursor, opencode, Copilot, Aider and Gemini, plus zsh, bash, fish and REPL histories.

Once installed it edits your files nightly. It acts only on 30 rules — 29 provider token formats plus PEM private keys — never generic or entropy-based ones. Redactions stay reversible for 30 days: to put one back, run scrbddy rollback.

Getting started

Requires Node 22+ and gitleaks.

brew install gitleaks
git clone https://github.com/chughtapan/scrbddy.git
cd scrbddy && npm install && npm run build && npm link
scrbddy status                        # what's on this machine
scrbddy scan --dry-run                # find secrets, write nothing
scrbddy audit --rotate                # which keys to rotate
scrbddy scan                          # scrub them
scrbddy install                       # run it daily from now on

How to do other things

See what can still be put back scrbddy rollback --list
Put a redaction back scrbddy rollback --id 42
Put back everything one run changed scrbddy rollback --run 7
Put back everything in one file scrbddy rollback --path ~/.zsh_history
Scan one source scrbddy scan --source fish
Scan a file outside the registry scrbddy path add ~/notes.md --kind text
Turn a source off scrbddy source disable cursor
Ignore the cache and rescan everything scrbddy scan --all
Remove the schedule scrbddy uninstall
Filter the history scrbddy audit --rule github-pat --since 2026-01-01

A partial status means some files were skipped rather than scanned. scrbddy status names each one and the reason.

Development

npm run check     # typecheck + lint + tests

Architecture and rationale: docs/superpowers/specs/2026-08-04-scrbddy-design.md.

Contributors

chughtapan

Issues