@mingderwang/xsift
v0.1.9
Published
URL network-vulnerability scanner CLI with Google login, scan reports, and scan history.
Maintainers
Readme
xsift
A URL network-vulnerability scanner in your terminal. Sign in with Google, scan any public URL, and review your scan history — no account setup beyond your Google login.
Install
npm install -g @mingderwang/xsiftRequires Node.js 18+.
Quick start
# 1. Sign in with Google (opens your browser, like `turso auth login`)
xsift auth login
# 2. Create a wallet for paid scans (asks for a new password, ~/.xsift/wallet.json)
xsift wallet create
# 3. Scan a URL — pays 0.5 USDC on Base Sepolia (x402) automatically
xsift scan https://example.com
# 4. See your scan history
xsift historyScans on the hosted backend are behind an x402 paywall (0.5 USDC on
Base Sepolia). On your first xsift scan the CLI gets a 402 Payment Required
response, signs an EIP-3009 TransferWithAuthorization with your wallet, and
resends it via the X-PAYMENT header. If your wallet has no USDC the scan is
rejected with insufficient_funds — fund the address shown by
xsift wallet address with Base Sepolia USDC and ETH (faucet) to enable real
settlement.
Commands
| Command | Description |
| --- | --- |
| xsift auth login | Sign in with your Google account |
| xsift auth logout | Forget the saved session |
| xsift auth whoami | Show the signed-in account |
| xsift scan <url> | Scan a URL (pays 0.5 USDC via x402) and print a full report |
| xsift history | Show your recent scan history |
| xsift wallet create | Create a wallet + encrypted keystore |
| xsift wallet import | Import a wallet from a mnemonic or private key |
| xsift wallet address | Show the wallet address |
| xsift wallet balance | Show ETH + USDC balances (--network <id>, default Base Sepolia) |
| xsift wallet export | Show the private key / mnemonic (password protected) |
| xsift wallet delete | Delete the local keystore |
Options:
--limit <n>— limit history rows (default 20)--json— print raw JSON instead of formatted output--network <id>— network forwallet balance(ethereum-sepolia,ethereum-mainnet,base-sepolia,base)
What a scan checks
- TLS: protocol version, certificate validity, expiry, hostname match, self-signed
- HTTP security headers: CSP, HSTS (+ preload/subdomains), X-Content-Type-Options, Referrer-Policy, Permissions-Policy, frame protection
- Cookie flags:
Secure,HttpOnly,SameSite, expiry - Transport: HTTP version, redirects, response time, server disclosure
- Open ports: common web, mail, FTP, SSH, and database ports
- A 0–100 score with a letter grade (A is a perfect hardening score)
Configuration
- Session is stored at
~/.xsift/config.json(permissions0600). - Wallet keystore (encrypted with scrypt + AES-256-GCM) at
~/.xsift/wallet.json. XSIFT_API_URLoverrides the backend API base URL. Default:https://network-vulnerability-scanner-pink.vercel.appX402_RPC_URLoverrides the RPC used for balances / payment defaults.XSIFT_WALLET_PASSWORD— optional env override for wallet unlock (CI/testing; otherwise xsift prompts interactively).
License
MIT
