Skip to content

Repository files navigation

kasap-security-tools

CI License: MIT

3 small, real defensive/educational security tools — not exploit tooling. A pnpm workspace monorepo, TypeScript/ESM, real vitest coverage with no live network/git calls in the automated test suite.

  • secret-scanner-lite — scans a directory (and optionally full git history via git log -p, so it catches secrets that were committed and later removed) for likely credentials using shape-based detectors plus a conservative entropy fallback. Redacts every reported value. Only ever scan repos you're authorized to scan.
  • rate-limit-middleware-kit — real token-bucket and sliding-window-log rate limiters, framework-agnostic with thin Express/Fastify adapters, an injectable clock for deterministic tests, and a pluggable store interface (in-memory implementation included).
  • cors-config-validator — a rule engine that flags common CORS misconfigurations (wildcard origin + credentials, overly broad methods/headers, missing Vary: Origin, naive reflect-everything configs). Supports a config-file mode (no network) and a live-check mode against a URL you're authorized to test.

Install & verify

pnpm install
pnpm build
pnpm typecheck
pnpm test

License

MIT

About

3 defensive security tools: git secret scanner (incl. history scan), token-bucket/sliding-window rate-limit middleware for Express/Fastify, CORS config auditor

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages