VIGIL
find it before they do

Find the secret before you commit it.

An offline scanner for configs, code, logs and .env files: twenty-one patterns and an entropy floor, a redacted preview instead of the secret, and a clean result that promises only that nothing matched.

Python 3.10+PyQt6 network never783 testsMIT

Why

Nobody publishes a secret on purpose. It arrives in a commit because it was in a file nobody re-read, in a log nobody trimmed, in a config that was copied once and shared twice.

The cost is not the file: it is the window between the secret leaving and anyone noticing. Vigil closes that window on your own machine, before the file goes anywhere.

What it draws. The exposure map — a minimap of the whole document, tinted by the worst finding on each span of lines, so clustering shows itself.
Vigil reading two samples

The reader on two of its bundled samples.

What it checks

SignalWhat trips it
Cloud keysAWS, Google, and their secret halves
Developer tokensGitHub, GitLab, npm, PyPI
Service keysStripe, Slack, SendGrid, Twilio, OpenAI-shaped
Key materialarmoured private key blocks, JWTs
Connection stringsa password embedded in a URL
Generica secret-shaped name with a high-entropy value
Set asideplaceholders and low-entropy values, counted not hidden

The honest part

Vigil matches patterns and entropy. It will miss any secret it has no rule for, cannot tell a live key from one revoked years ago, and will sometimes flag something harmless. A clean result means nothing matched — never that there are no secrets. It never prints a secret in full.

Install

git clone https://github.com/at0m-b0mb/Vigil-Secret-Scanner.git
cd Vigil-Secret-Scanner
python3 -m pip install -r requirements.txt

python3 -m vigil                      # the window
python3 -m vigil samples/             # the command line
python3 -m pytest -q                   # 783 tests

The engine and the command line need no dependencies at all — only the standard library. PyQt6 is required solely for the window.

One of seven readers