{"categories":[{"label":"Security","url":"https://skillfed.io/packages/category/security/3"}],"enrichment":{"capability":"Kingfisher is a command-line secret scanner that detects, validates, and triages leaked API keys, tokens, and credentials across code repositories, cloud storage, chat platforms, and CI pipelines using 1,089 built-in rules and live validation against provider APIs.","skillfed_tags":["secret-detection","credential-scanning","compliance"],"use_cases":["Scan Git repositories and commit history for accidentally committed API keys and tokens before they reach production","Validate discovered credentials against provider APIs to confirm they are live and reduce false-positive alerts","Generate compliance-ready audit reports with scan metadata and validation results for security and regulatory reviews","Integrate secret scanning into CI/CD pipelines with JSON, SARIF, or webhook alerts to Slack or Microsoft Teams","Triage and deduplicate findings from multiple scanning tools (Gitleaks, TruffleHog) in a unified browser-based viewer","Map blast radius of leaked credentials to identify which cloud resources and identities are exposed across 43 providers"],"what_it_does":"Kingfisher is a Rust-based command-line tool that scans for exposed secrets\u2014API keys, tokens, and credentials\u2014across multiple sources including local files, Git repositories, GitHub, GitLab, Azure Repos, Bitbucket, Gitea, Hugging Face, Docker, Jira, Confluence, Slack, Microsoft Teams, Postman, AWS S3, and Google Cloud Storage. It uses an Intel SIMD-accelerated regex engine (Hyperscan) combined with language-aware parsing to achieve high accuracy at scale.\n\nBeyond detection, Kingfisher validates discovered secrets by checking them against provider APIs to reduce false positives, and supports direct revocation for many platforms. It generates output in JSON, SARIF, TOON, and HTML formats, sends alerts to Slack, Microsoft Teams, Discord, Mattermost, Google Chat, or custom webhooks, and includes a browser-based report viewer that can visualize and triage findings from Kingfisher, SARIF, Gitleaks, and TruffleHog reports. The tool is designed for both offensive security engineers and blue-team defenders scanning repositories, cloud storage, chat systems, and CI pipelines.","worth_installing":"Yes. Kingfisher is actively maintained, has no runtime dependencies, supports modern Python versions, carries a permissive Apache-2.0 license, and offers comprehensive secret detection with live validation across 1,089 rules and many platforms. It is well-suited for developers, security teams, and compliance workflows. Install via Homebrew, PyPI, or Docker depending on your environment."},"id":"kingfisher-bin","links":{"html":"https://skillfed.io/packages/kingfisher-bin","md":"https://skillfed.io/packages/kingfisher-bin.md","pypi":"https://pypi.org/project/kingfisher-bin/"},"maintenance":{"status":"active"},"meta":{"latest_release":"2026-08-08","license_spdx":null,"license_treatment":"permissive","name":"kingfisher-bin","python_support":"supports_current","summary":"Kingfisher secret scanning CLI (packaged binary)"},"popularity":{"monthly_downloads":74556,"position":14816,"tier":"top_15000"},"security":{"n_vulnerabilities":0},"version":"1.112.0"}
