An offline scanner for configs, code, logs and .env files: twenty-one patterns and an entropy floor, a redacted preview instead of the secret, and a clean result that promises only that nothing matched.
Nobody publishes a secret on purpose. It arrives in a commit because it was in a file nobody re-read, in a log nobody trimmed, in a config that was copied once and shared twice.
The cost is not the file: it is the window between the secret leaving and anyone noticing. Vigil closes that window on your own machine, before the file goes anywhere.
The reader on two of its bundled samples.
| Signal | What trips it |
|---|---|
| Cloud keys | AWS, Google, and their secret halves |
| Developer tokens | GitHub, GitLab, npm, PyPI |
| Service keys | Stripe, Slack, SendGrid, Twilio, OpenAI-shaped |
| Key material | armoured private key blocks, JWTs |
| Connection strings | a password embedded in a URL |
| Generic | a secret-shaped name with a high-entropy value |
| Set aside | placeholders and low-entropy values, counted not hidden |
Vigil matches patterns and entropy. It will miss any secret it has no rule for, cannot tell a live key from one revoked years ago, and will sometimes flag something harmless. A clean result means nothing matched — never that there are no secrets. It never prints a secret in full.
git clone https://github.com/at0m-b0mb/Vigil-Secret-Scanner.git
cd Vigil-Secret-Scanner
python3 -m pip install -r requirements.txt
python3 -m vigil # the window
python3 -m vigil samples/ # the command line
python3 -m pytest -q # 783 tests
The engine and the command line need no dependencies at all — only the standard library. PyQt6 is required solely for the window.