Skip to content
Back to the index

shadowgit

PyPIInfrastructure

PulseGate's liveness check found it on 14 Sep 2026; it is registered on GitHub and PyPI and has been in the index since 12 Jul 2026. How this is checked

shadowgit is an open-source Python CLI tool that automates the detection of dangling commits and secrets in GitHub repositories. It helps security researchers and developers identify potential security risks in their codebases.

Inferred · not functionally tested

Open SourceMITCLI
Visit PyPI

Overview

4 features

Purpose: Identifying security risks from dangling commits and exposed secrets in GitHub repositories.

Inferred · not functionally tested

Audience: security researchers and developers

Inferred · not functionally tested

Functions: data_extraction

Inferred · not functionally tested

Interfaces: API: unknown · MCP: unknown · CLI: indicated (inferred, not tested) · Self-hosting: unknown

Recorded constraints: pricing: open_source · license: MIT · platforms: CLI · deployment: cli

Constraint provenance is unknown; confirm requirements with the publisher.

Record sources: pypi.org · github.com. These links do not verify the individual claims.

shadowgit is a Penetration testing & red teaming project. Inferred · not functionally tested: It focuses on identifying security risks from dangling commits and exposed secrets in GitHub repositories. Inferred · not functionally tested: It is built as an open-source project for security researchers and developers. Basis unknown · not verified: The project is open source (MIT). Basis unknown · not verified: It runs on the command line.

It is developed by 0xcardinal, and it first shipped in 2026. Inferred · not functionally tested: Among its 4 catalogued features are detect dangling commits, find secrets in repos, and gitHub integration.

Summary written by a language model from the project’s public pages.

Tasks: Inferred · not functionally tested

  • Detect dangling commits
  • Find secrets in repos
  • GitHub integration
  • Automated scanning

Topics: Inferred · not functionally tested

Tags
dangling-commitssecret-detectiongithub-security
AI capabilities
Weights: Open

JSON profile · Text profile · Access guide

Built with & integrations

Connectors
github
Runs on
CLI

Trust & compliance

License
MIT
Public signals

Indexing history

1

What PulseGate has recorded for this listing

  1. Indexed12 Jul · 23:18 UTC
    shadowgit seen via PyPI Fresh Feed
    Source: PyPI Fresh Feed · Open

Frequently asked questions about shadowgit

What does shadowgit do?
Inferred · not functionally tested: Shadowgit focuses on identifying security risks from dangling commits and exposed secrets in GitHub repositories. It is catalogued under Penetration testing & red teaming on PulseGate.
Who should use shadowgit?
Inferred · not functionally tested: shadowgit is an open-source project built for security researchers and developers.
Is shadowgit free?
Basis unknown · not verified: Yes — shadowgit is open source under the MIT license and free to use.
What platforms does shadowgit run on?
Basis unknown · not verified: shadowgit runs on the command line.
Is shadowgit still active?
PulseGate's liveness check found it on 14 Sep 2026.
Who develops shadowgit?
shadowgit is developed by 0xcardinal.
When did shadowgit launch?
shadowgit first shipped in 2026.
Is shadowgit open source?
Basis unknown · not verified: Yes — shadowgit is open source under the MIT license, developed on GitHub.

Similar projects

Closest matches by what these projects do