$npx skillfedfor your agent

cycode

Boost security in your dev lifecycle via SAST, SCA, Secrets & IaC scanning.

Worth itPyPI SecurityReleased Aug 2026176.7K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — cycode-3.19.1-py3-none-any.whl
v3.19.1 · released 2026-08-13 · Python >=3.9 · 19 runtime deps: anyio, arrow, click, colorama, gitpython, marshmallow, mcp, patch-ng

Yes. Cycode is actively maintained, has no known vulnerabilities, low install friction, and a permissive MIT license. It is production-stable (Development Status 5) and supports current Python versions (3.9–3.14). Install it if you need a unified CLI for secrets, IaC, SCA, and SAST scanning; authentication setup is required before first use.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.9 or later; the MCP command requires Python 3.10 or above.
  • Authentication via Cycode credentials (Client ID and Secret, or OIDC token) is required before scanning.
  • Low install friction with a pure Python wheel distribution.

License · maintenance · safety

MIT (permissive) — MIT license permits commercial and private use with minimal restrictions—you can use, modify, and distribute the package freely as long as you include the license notice.

last release 2026-08-13 (1 days) · last repo commit 2026-08-13 · 99 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 176,729 downloads/mo, #10,235 on PyPI

Verify before relying

pip install cycode
cycode auth
cycode scan --repository .
  • Whether the 19 runtime dependencies introduce any transitive vulnerabilities or compatibility issues beyond what OSV reports.
  • Performance characteristics and scan time for large repositories or monorepos.
  • Whether pre-commit hook integration works reliably across different Git configurations.
  • Accuracy and false-positive rates for each scan type (secrets, IaC, SCA, SAST).
Same gist for agents: .md · .json

What it is and what it does

Cycode is a production-grade CLI tool for scanning code repositories across four security domains: secret detection, infrastructure-as-code validation, software composition analysis (SCA), and static application security testing (SAST). It integrates into local development workflows via command-line invocation, pre-commit hooks, or CI/CD pipelines, and supports authentication through browser-based login, manual credential configuration, or environment variables.

The tool scans repositories, individual paths, commit history, and Terraform plans, then reports findings with configurable severity thresholds and remediation guidance. It allows fine-grained result filtering—ignoring specific secrets by value or hash, paths, rules, or packages—and can generate SBOM reports. An experimental MCP (Model Context Protocol) server mode and beta platform command extend its capabilities for integration with AI tools and centralized policy management.

Use it for

  • Scan a Git repository before pushing to detect leaked credentials, API keys, or tokens in commit history.
  • Validate Terraform or CloudFormation configurations for security misconfigurations in infrastructure-as-code files.
  • Identify vulnerable dependencies in package manifests (requirements.txt, package.json, etc.) as part of SCA.
  • Integrate into pre-commit hooks to block commits containing secrets or policy violations before they reach the repository.
  • Generate software bill-of-materials (SBOM) reports for compliance and supply-chain security audits.
  • Run static analysis on source code to flag common security anti-patterns and coding issues.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

Cycode is actively maintained, has no known vulnerabilities, low install friction, and a permissive MIT license. It is production-stable (Development Status 5) and supports current Python versions (3.9–3.14). Install it if you need a unified CLI for secrets, IaC, SCA, and SAST scanning; authentication setup is required before first use.

Install

cycode on PyPI

Before you install

Low install friction with a pure Python wheel distribution. The package is actively maintained with a recent release (1 day old) and 99 repository stars. It has 19 runtime dependencies including common libraries like click, pydantic, and requests, all of which are well-established.

Requires Python 3.9 or later; the MCP command requires Python 3.10 or above. Authentication via Cycode credentials (Client ID and Secret, or OIDC token) is required before scanning.

License in practice

MIT license permits commercial and private use with minimal restrictions—you can use, modify, and distribute the package freely as long as you include the license notice.

Quickstart

pip install cycode
cycode auth
cycode scan --repository .

Verify before relying

  • Whether the 19 runtime dependencies introduce any transitive vulnerabilities or compatibility issues beyond what OSV reports.
  • Performance characteristics and scan time for large repositories or monorepos.
  • Whether pre-commit hook integration works reliably across different Git configurations.
  • Accuracy and false-positive rates for each scan type (secrets, IaC, SCA, SAST).

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.9
Install frictionLow. Pure-Python wheel
Runtime dependencies
19 packages
anyioarrowclickcoloramagitpythonmarshmallowmcppatch-ngpathvalidatepydanticpyjwtpyyamlrequestsrichtenacitytomlitomli-wtyperurllib3
MaintenanceActively maintained 1 days since the last release
Last repo commit
First released
Downloads176,729 / month, #10,235 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableEnvironment :: ConsoleNatural Language :: EnglishOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3 :: OnlyProgramming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.14Programming Language :: Python :: 3.9

Evidence: cycode-3.19.1-py3-none-any.whl

Tags

Capabilities
secret scanning CLIinfrastructure as code securitysoftware composition analysisSAST static analysisDevSecOps scanning toolcode security scannervulnerability detection CLI
Topics
secrets-detectiondevops-securityvulnerability-scanning
PyPI keywords
secret-scancycodedevopstokensecretsecuritycode

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “software composition analysis”

  • cycodeCycode is a command-line security scanner that detects secrets,…
  • cyclonedx-bomGenerates Software Bill of Materials (SBOM) documents in CycloneDX…
  • blackduckPython bindings for the Synopsys Black Duck Hub REST API, providing a…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also bc-detect-secrets · ggshield · bridgecrew · checkov · detect-secrets · kingfisher-bin · scanoss · trufflehog3 · skylos · semgrep