Committed secrets
Detect high-signal credential patterns such as private keys, GitHub tokens, AWS credentials and hardcoded secrets.
GSkout turns a GitHub repository into a readable technical risk report covering source security, vulnerable dependencies, committed secrets, configuration, repository files and overall health.
GSkout combines focused analyzers into one report so you can understand what was found, where it lives, how serious it is and what to investigate next.
Explore analyzersDetect high-signal credential patterns such as private keys, GitHub tokens, AWS credentials and hardcoded secrets.
AST-aware analysis detects dangerous execution primitives and adds stronger findings when request-controlled data reaches them.
Evaluate installed dependency versions against vulnerability advisories, deprecations and available updates.
Inspect selected Node.js, Next.js, Docker, Vercel and GitHub Actions configuration for high-signal problems.
GSkout uses AST-aware analysis and lightweight framework context to distinguish a dangerous primitive from stronger evidence that request-controlled data reaches a sensitive sink.
That distinction helps reduce noise and raises severity when the repository contains a clearer path to command injection or dangerous dynamic execution.
GSkout combines installed package versions with registry metadata and OSV advisory information. Vulnerability findings can link to external resources such as NVD, GitHub Security Advisories, upstream advisories and package pages.
Repository health combines security signals, dependency condition, analysis coverage and analysis quality. The report exposes the components instead of hiding the score behind a black box.
How repository health worksPaste a public GitHub URL, or authenticate with GitHub and select a repository available through the installed integration.
GSkout loads repository metadata, dependency information, selected source files, configuration and repository structure.
Review findings, inspect affected files and dependencies, follow advisory resources and move between multiple repository reports.
GSkout V1 is deliberately focused. It does not claim to be a universal language scanner or complete SAST platform.
GSkout V1 focuses on JavaScript and Node.js repositories that contain a package.json. Public GitHub repositories can be analyzed by URL.
Yes, when the repository is available through the configured GitHub App installation.
No. GSkout combines focused repository intelligence, dependency analysis, secret detection, AST-aware checks and lightweight source-to-sink context. It does not claim full program-wide static analysis.
No. Repository health summarizes the signals GSkout can evaluate. A repository can still contain issues outside GSkout's supported analysis scope.
Analyze the repository and see security, dependencies, configuration, files and health in one place.
Open workspace