$npx skillfedfor your agent

ggshield

Detect secrets from all sources using GitGuardian's brains

Worth itPyPI SecurityReleased Jul 2026513.1K downloads / moMITPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — ggshield-1.53.0-py3-none-any.whl
v1.53.0 · released 2026-07-28 · Python >=3.9 · 24 runtime deps: charset-normalizer, click, configupdater, cryptography, filelock, keyring, marshmallow-dataclass, marshmallow

Yes. ggshield is actively maintained, has low installation friction, carries a permissive MIT license, and solves a critical security problem (preventing secrets in code). It integrates cleanly into development workflows via Git hooks or CI/CD, requires no complex setup beyond authentication, and has no known vulnerabilities. Install it if your team needs automated secrets detection.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires a supported (non-EOL) version of Python and git.
  • Authentication via GitGuardian API key (GITGUARDIAN_API_KEY environment variable or interactive login) is required before scanning.
  • Low friction installation with a pure Python wheel and 24 runtime dependencies.

License · maintenance · safety

MIT (permissive) — MIT license (permissive) means you can use, modify, and distribute ggshield freely in commercial and private projects with minimal restrictions, provided you include the license notice.

last release 2026-07-28 (17 days) · last repo commit 2026-08-13 · 1,987 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 513,108 downloads/mo, #6,253 on PyPI

Verify before relying

pipx install ggshield
ggshield auth login
ggshield secret scan path -r .
  • Whether the '500+ types of secrets' detection claim is current and what categories are covered.
  • Performance characteristics and scan time for large repositories or Docker images.
  • Whether pre-commit hook integration is automatic or requires manual configuration.
Same gist for agents: .md · .json

What it is and what it does

ggshield is a command-line security scanner that integrates with GitGuardian's threat detection API to find secrets and vulnerabilities in your codebase. It runs locally or in CI/CD pipelines and can scan files, Git repositories, Docker images, and PyPI packages. The tool sends only metadata (call time, request size, scan mode) to GitGuardian—your actual files and secrets remain local and are not stored on their servers. You authenticate once with a personal access token, then use simple commands like `ggshield secret scan path` to check directories or `ggshield secret scan repo` to scan a repository. It's designed to catch credential leaks before they reach version control, supporting integration as Git hooks (pre-commit, pre-push, pre-receive) and CI/CD workflows.

The package depends on 24 runtime libraries including click for CLI handling, cryptography and pyjwt for authentication, requests and oauthlib for API communication, and rich for terminal output formatting. It requires a non-EOL Python version (3.9 or later) and git. The tool is actively maintained, with recent releases and ongoing repository updates, making it suitable for teams implementing secrets detection as part of their development security workflow.

Use it for

  • Prevent accidental commits of API keys, database passwords, or OAuth tokens to Git repositories.
  • Scan Docker images before deployment to detect embedded credentials or secrets in layers.
  • Integrate into CI/CD pipelines to block builds or pull requests containing detected secrets.
  • Set up pre-commit Git hooks to catch secrets locally before they reach the repository.
  • Audit PyPI packages for embedded credentials or leaked secrets in dependencies.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

ggshield is actively maintained, has low installation friction, carries a permissive MIT license, and solves a critical security problem (preventing secrets in code). It integrates cleanly into development workflows via Git hooks or CI/CD, requires no complex setup beyond authentication, and has no known vulnerabilities. Install it if your team needs automated secrets detection.

Install

ggshield on PyPI

Before you install

Low friction installation with a pure Python wheel and 24 runtime dependencies. Active maintenance with a recent release 17 days ago and ongoing repository activity. Supports current Python versions (3.9–3.13) and follows the Python release cycle.

Requires a supported (non-EOL) version of Python and git. Authentication via GitGuardian API key (GITGUARDIAN_API_KEY environment variable or interactive login) is required before scanning.

License in practice

MIT license (permissive) means you can use, modify, and distribute ggshield freely in commercial and private projects with minimal restrictions, provided you include the license notice.

Quickstart

pipx install ggshield
ggshield auth login
ggshield secret scan path -r .

Verify before relying

  • Whether the '500+ types of secrets' detection claim is current and what categories are covered.
  • Performance characteristics and scan time for large repositories or Docker images.
  • Whether pre-commit hook integration is automatic or requires manual configuration.

Package facts

LicenseMIT permissive
Python supportSupports the current Python release >=3.9
Install frictionLow. Pure-Python wheel
Runtime dependencies
24 packages
charset-normalizerclickconfigupdatercryptographyfilelockkeyringmarshmallow-dataclassmarshmallownotify-pyoauthlibpackagingplatformdirspygitguardianpyjwtpython-dotenvpyyamlrequestsrichsigstoretomlitruststoretyping-extensionsunearthurllib3
MaintenanceActively maintained 17 days since the last release
Last repo commit
First released
Downloads513,108 / month, #6,253 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
Development Status :: 5 - Production/StableEnvironment :: ConsoleIntended Audience :: DevelopersIntended Audience :: End Users/DesktopLicense :: OSI Approved :: MIT LicenseNatural Language :: EnglishOperating System :: OS IndependentProgramming Language :: PythonProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Programming Language :: Python :: 3.9Topic :: Security

Evidence: ggshield-1.53.0-py3-none-any.whl

Tags

Capabilities
secret detection clisecrets scannercredential leak detectiongitguardian secretsdevsecops scanning toolpre-commit secret scanningci/cd secret detection
Topics
devsecopssecrets-detectionpre-commit-hook
PyPI keywords
clidevsecopsgitguardiansecrets-detectionsecurity-tools

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “secret detection cli”

  • ggshieldggshield is a CLI tool that scans files, repositories, Docker images,…
  • cycodeCycode is a command-line security scanner that detects secrets,…
  • bc-detect-secretsDetects secrets (API keys, tokens, credentials) in code repositories…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also pygitguardian · cycode · kingfisher-bin · truffleHog · trufflehog3 · bc-detect-secrets · detect-secrets · semgrep · detect-installer · prowler