$npx skillfedfor your agent

truffleHog

Searches through git repositories for high entropy strings, digging deep into commit history.

With conditionsPyPI SecurityReleased Feb 2021137.6K downloads / moGNUPure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — truffleHog-2.2.1-py2.py3-none-any.whl
v2.2.1 · released 2021-02-05

Yes, with conditions. Install if you need to audit Git history for leaked credentials and can work around the unclear GNU license terms. The tool is actively maintained on GitHub with strong community adoption, has no runtime dependencies, and detects a broad range of secret types with validation capability. However, verify the GNU license variant's compatibility with your project before committing, and note that the PyPI package has not been updated since 2021-02-05—you may want to use the Docker image or binary releases for the latest features.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Git to be installed and accessible; scanning remote repositories requires network access and appropriate credentials for private repos.
  • Low install friction with no runtime dependencies.
  • Repository is active with recent commits and substantial community engagement (27463 stars), though the PyPI package itself has not received updates since 2021-02-05.

License · maintenance · safety

GNU (unclear) — Licensed under GNU with unclear SPDX classification. Before adopting, verify which GNU variant applies (GPL, LGPL, AGPL) and whether its copyleft terms align with your project's licensing strategy.

last release 2021-02-05 (2016 days) · last repo commit 2026-08-14 · 27,463 stars

0 known vulnerabilities (OSV.dev, 2026-08-14) · 137,592 downloads/mo, #11,363 on PyPI

Verify before relying

pip install trufflehog
trufflehog git https://github.com/example/repo --results=verified
  • Whether the PyPI package version 2.2.1 reflects current functionality or if the active GitHub repository has diverged significantly
  • Specific GNU license variant and its compatibility with commercial or proprietary projects
  • Current Python version support, as the package metadata does not specify minimum or maximum Python versions
Same gist for agents: .md · .json

What it is and what it does

TruffleHog is a secrets discovery and validation tool that searches through Git repositories and other sources for leaked credentials. It classifies over 800 secret types—including API keys, database passwords, encryption keys, and service-specific credentials—and maps them back to their origin (AWS, Stripe, Cloudflare, Postgres, etc.). For many common credential types, it can validate whether a discovered secret is still active by attempting authentication, distinguishing between historical leaks and present dangers.

The tool is designed for security teams and developers who need to audit code history, scan organizational repositories, or integrate credential detection into CI/CD pipelines. It outputs findings in multiple formats (plain text, JSON, SARIF) and supports scanning across Git, Jira, Slack, Confluence, and other platforms through its enterprise variant. The open-source version focuses on discovery, classification, and validation of secrets found in Git history and local filesystems.

Use it for

  • Audit a Git repository's full history to find accidentally committed API keys or database passwords before they cause a breach.
  • Scan a GitHub organization's repositories to identify and validate leaked credentials across multiple projects.
  • Integrate secret detection into CI/CD pipelines to block commits containing unvalidated high-entropy strings.
  • Classify and analyze discovered secrets to understand which services or accounts are at risk and what permissions they hold.
  • Generate SARIF output for GitHub Security tab to track credential findings alongside other code scanning results.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

With conditions

Yes, with conditions.

Install if you need to audit Git history for leaked credentials and can work around the unclear GNU license terms. The tool is actively maintained on GitHub with strong community adoption, has no runtime dependencies, and detects a broad range of secret types with validation capability. However, verify the GNU license variant's compatibility with your project before committing, and note that the PyPI package has not been updated since 2021-02-05—you may want to use the Docker image or binary releases for the latest features.

Install

trufflehog on PyPI

Before you install

Low install friction with no runtime dependencies. Repository is active with recent commits and substantial community engagement (27463 stars), though the PyPI package itself has not received updates since 2021-02-05.

Requires Git to be installed and accessible; scanning remote repositories requires network access and appropriate credentials for private repos.

License in practice

Licensed under GNU with unclear SPDX classification. Before adopting, verify which GNU variant applies (GPL, LGPL, AGPL) and whether its copyleft terms align with your project's licensing strategy.

Quickstart

pip install trufflehog
trufflehog git https://github.com/example/repo --results=verified

Verify before relying

  • Whether the PyPI package version 2.2.1 reflects current functionality or if the active GitHub repository has diverged significantly
  • Specific GNU license variant and its compatibility with commercial or proprietary projects
  • Current Python version support, as the package metadata does not specify minimum or maximum Python versions

Package facts

LicenseGNU unclear
Python supportNot specified
Install frictionLow. Pure-Python wheel
Runtime dependenciesNone
MaintenanceActively maintained 2,016 days since the last release
Last repo commit
First released
Downloads137,592 / month, #11,363 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14

Evidence: truffleHog-2.2.1-py2.py3-none-any.whl

Tags

Capabilities
credential scanningsecret detection gitleaked credentials finderapi key discoverypassword leak detectionsecrets validation toolgit history secrets
Topics
secrets-scanningcredential-detectiongit-audit

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “credential scanning”

  • truffleHogScans Git repositories and other sources for leaked credentials,…
  • pygitguardianAPI client library for GitGuardian's secret detection service,…
  • ggshieldggshield is a CLI tool that scans files, repositories, Docker images,…

Give your agent the search over MCP, or paste the wish link into any chat.

More Security packages

SecretStorage With conditions
PyPI · Python Modules · released Nov 2025

Provides Python bindings to the FreeDesktop.org Secret Service API for securely storing and retrieving passwords and secrets through GNOME Keyring, KWallet, or KeePassXC.

BSD-3-Clausepure Python · 3.10+aging
226.9Mdownloads / mo
msal Worth it
PyPI · Security · released May 2026

MSAL for Python handles OAuth2 and OpenID Connect authentication with Microsoft identity services, managing token acquisition, caching, and refresh for applications integrating with Microsoft Entra ID, Microsoft Accounts, and Azure AD B2C.

MITpure Python · 3.9+
223.0Mdownloads / mo
joserfc Worth it
PyPI · Security · released Jul 2026

joserfc implements JOSE standards (JWS, JWE, JWK, JWT, and related RFCs) for signing, encrypting, and managing JSON-based cryptographic tokens in Python.

BSD-3-Clausepure Python · 3.10+
155.5Mdownloads / mo
Authlib Worth it
PyPI · Security · released May 2026

Authlib provides a complete implementation of OAuth 1.0, OAuth 2.0, and OpenID Connect 1.0 for building both authentication clients and servers, with built-in support for JWS, JWK, JWA, and JWT standards.

BSD-3-Clausepure Python · 3.10+
155.1Mdownloads / mo
argon2-cffi-bindings With conditions
PyPI · Python Modules · released Jul 2025

Provides low-level CFFI bindings to the official Argon2 password hashing algorithm for use by libraries and applications that need direct access to Argon2 without higher-level abstractions.

MITcompiled wheel · 3.9+
74.2Mdownloads / mo
adal Skip
PyPI · Security · released Apr 2021

ADAL for Python authenticates applications with Azure Active Directory to obtain tokens for accessing Azure AD-protected resources.

Install only if maintaining existing code that already depends on it, and plan a migration.

MITpure Pythonabandoned
44.5Mdownloads / mo

See also kingfisher-bin · trufflehog3 · detect-secrets · bc-detect-secrets · ggshield · pygitguardian · dodgy · semgrep · git-credentials · pysentry-rs

Further reading