npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, πŸ‘‹, I’m Ryan HefnerΒ  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you πŸ™

Β© 2026 – Pkg Stats / Ryan Hefner

keyhound

v1.0.0

Published

πŸ• Sniff out leaked secrets, API keys, and credentials before they hit production

Downloads

171

Readme

πŸ• KeyHound

Sniff out leaked secrets, API keys, and credentials before they hit production.

License: MIT Node.js Zero Dependencies

KeyHound is a fast, lightweight, offline-first security scanner that analyzes your source code for accidentally exposed secrets (AWS keys, Stripe secrets, GitHub tokens, private keys, database passwords) and prevents leaks in your CI/CD pipeline or local development workflow.


⚑ Instant Quickstart (Zero Install)

Run KeyHound directly in any directory without installing anything:

npx keyhound .

πŸ“¦ Installation Options

1. npm (Global CLI)

npm install -g keyhound

# Scan any folder
keyhound .

2. GitHub Action (CI/CD)

Add KeyHound to .github/workflows/security.yml to automatically scan PRs and post review alerts:

name: Security Scan
on:
  push:
    branches: [ main ]
  pull_request:
    branches: [ main ]

jobs:
  keyhound:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4

      - name: πŸ• Run KeyHound Secret Scan
        uses: Krish121234/Keyhound@v1
        with:
          github-token: ${{ secrets.GITHUB_TOKEN }}
          fail-on-findings: 'true'

3. Docker

docker run --rm -v $(pwd):/workspace keyhound /workspace

4. Git Pre-Commit Hook (Husky / Local Git)

Prevent secrets from ever leaving your machine:

# .husky/pre-commit or .git/hooks/pre-commit
npx keyhound .

🎯 What KeyHound Detects

| Secret Type | Examples | Confidence | | --- | --- | --- | | AWS Access Keys | AKIAIOSFODNN7EXAMPLE | πŸ”΄ High | | AWS Secret Keys | aws_secret = "..." | 🟑 Medium | | GitHub Tokens | ghp_..., gho_..., ghu_... | πŸ”΄ High | | Stripe Keys | sk_live_..., pk_live_... | πŸ”΄ High | | Slack Tokens | xoxb-..., xoxp-... | πŸ”΄ High | | Google API Keys | AIzaSy... | 🟑 Medium | | Private Keys | -----BEGIN PRIVATE KEY----- | πŸ”΄ High | | Generic Credentials | API_KEY="xxx", PASSWORD="xxx" | 🟒 Low | | High Entropy Strings | Unknown base64 / hex random tokens (Shannon entropy) | 🟑 Medium |


πŸ’» CLI Usage

# Basic scan
keyhound [path]

# Scan specific folder
keyhound src/

# Output machine-readable JSON (useful for custom scripts & pipelines)
keyhound . --json

# Ignore specific files or directories
keyhound . --ignore "docs/" --ignore "*.mock.js"

# Use a custom rules file
keyhound . --config ./my-rules.json

# Verbose output with full error traces
keyhound . --verbose

Exit Codes

  • 0 β€” Codebase is clean, no secrets detected.
  • 1 β€” Potential secrets detected (blocks CI builds).
  • 2 β€” Error encountered (e.g. invalid arguments or non-existent path).

🚫 Ignoring Files (.scanignore)

Place a .scanignore file in the root of your project to exclude files and test fixtures (supports glob patterns):

# Dependencies & Build artifacts
node_modules/
dist/
coverage/

# Test mocks with fake credentials
test/fixtures/
**/*.mock.json

βš™οΈ Custom Rules Configuration

Create a custom rules.json file to add your company's custom token patterns:

{
  "rules": [
    {
      "id": "acme-corp-key",
      "name": "Acme Corp Production Token",
      "pattern": "acme_live_[0-9a-zA-Z]{32}",
      "confidence": "high"
    }
  ],
  "placeholders": [
    "your_key_here",
    "dummy_token"
  ],
  "entropy": {
    "enabled": true,
    "minLength": 32,
    "minEntropy": 4.5
  }
}

Then run:

keyhound . --config rules.json

πŸ”’ Security & Privacy Guarantee

  • Zero Telemetry / Offline First: KeyHound operates 100% locally on your machine. It does not send code or metadata to any external server.
  • Always Redacted: Secret values are never logged or stored in plain text. Previews only show the first and last two characters (e.g., AK...LE).

πŸ› οΈ Contributing & Testing

# Clone the repository
git clone https://github.com/Krish121234/Keyhound.git
cd Keyhound

# Run unit tests
npm test

πŸ“„ License

MIT License. Free for personal and commercial use.