Access
Install
Showcase

Try itExperimental
See what an agent can do with Gitleaks before you ever sign up. Pick a story: recorded sessions replay real probe-harness transcripts; sandboxed self-drive sessions are designed and gated (docs/TRY-IT.md).
$gitleaks versionrecorded session — replayed, not liveVerified integrations
Connections to other tracked products — hover a chip for the verbatim evidence quote behind it.
By theme — the product's score on each story themeBy theme
Agenticness — how well agents can access and operate the productAgenticnessevidence →
How well agents can access and operate the product
Automation depth — how much of the product can run unattendedAutomation depthevidence →
How much of the product can run unattended
Ci precommit — stories about ci precommit in this arenaCi precommitevidence →
Stories about ci precommit in this arena
Container scanning — stories about container scanning in this arenaContainer scanningevidence →
Stories about container scanning in this arena
n/a
Coverage accuracy — stories about coverage accuracy in this arenaCoverage accuracyevidence →
Stories about coverage accuracy in this arena
Dependency sca — stories about dependency sca in this arenaDependency scaevidence →
Stories about dependency sca in this arena
n/a
Openness — open source, data portability, and self-hosting storiesOpennessevidence →
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy postureevidence →
Data-handling and privacy stories
Sast rules — stories about sast rules in this arenaSast rulesevidence →
Stories about sast rules in this arena
Secret detection — stories about secret detection in this arenaSecret detectionevidence →
Stories about secret detection in this arena
Supply chain sbom — stories about supply chain sbom in this arenaSupply chain sbomevidence →
Stories about supply chain sbom in this arena
n/a
Triage noise — stories about triage noise in this arenaTriage noiseevidence →
Stories about triage noise in this arena
Story verdicts — every judged story with its evidenceStory verdicts
What’s free: 8 free · 0 paid · 0 enterprise · 12 not stated in evidence
Follow the green: where the map greys out is where Gitleaks stops today. ✓ full · ~ partial · ! disputed · — none · n/a not applicable.
Agenticness — how well agents can access and operate the productAgenticness
How well agents can access and operate the product
API surface
Drive the product through a documented public API
—0/10
Subscribe to events via webhooks
—0/10
Build against official SDKs
n/an/a
Issue scoped/least-privilege API credentials for an agent
n/an/a
Connect an agent via an official MCP server
n/an/a
Download a machine-readable API spec (OpenAPI or equivalent)
—0/10
Rely on versioned APIs with a documented deprecation policy
—0/10
Test against a sandbox environment without touching production data
n/an/a
Explore an interactive API reference with runnable examples
—0/10
Docs for agents
Point an agent at llms.txt or agent-oriented docs
—0/10
Agentic features
Delegate tasks to a built-in AI assistant inside the product
n/an/a
Operate the product with natural-language commands
n/an/a
Plug MCP servers into this product so it can use their tools
n/an/a
Get AI-generated insights and suggestions from my data inside the product
—0/10
Set up automations that run autonomously in the background
~6/10
Automation depth — how much of the product can run unattendedAutomation depth
How much of the product can run unattended
Ci precommit — stories about ci precommit in this arenaCi precommit
Stories about ci precommit in this arena
Container scanning — stories about container scanning in this arenaContainer scanning
Stories about container scanning in this arena
Coverage accuracy — stories about coverage accuracy in this arenaCoverage accuracy
Stories about coverage accuracy in this arena
Dependency sca — stories about dependency sca in this arenaDependency sca
Stories about dependency sca in this arena
Openness — open source, data portability, and self-hosting storiesOpenness
Open source, data portability, and self-hosting stories
Privacy posture — data-handling and privacy storiesPrivacy posture
Data-handling and privacy stories
Sast rules — stories about sast rules in this arenaSast rules
Stories about sast rules in this arena
Secret detection — stories about secret detection in this arenaSecret detection
Stories about secret detection in this arena
Supply chain sbom — stories about supply chain sbom in this arenaSupply chain sbom
Stories about supply chain sbom in this arena
Triage noise — stories about triage noise in this arenaTriage noise
Stories about triage noise in this arena
Sorted by importance (agentic first) (high → low) · 55/55 stories · click a row’s chevron for the rationale and evidence
Drive the product through a documented public API G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | none | 0/10 | ||
Connect an agent via an official MCP server G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Delegate tasks to a built-in AI assistant inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Plug MCP servers into this product so it can use their tools G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 3 | n/a | untested | none yet | |
Run the product headlessly / in CI for automation G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | fullfree | 8/10 | Cclaimed | |
Use an official CLI G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | fullfree | 8/10 | Tprobed | |
Set up automations that run autonomously in the background G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | partial | 6/10 | Cclaimed | |
Download a machine-readable API spec (OpenAPI or equivalent) G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Explore an interactive API reference with runnable examples G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none± | 0/10 | ||
Get AI-generated insights and suggestions from my data inside the product G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Point an agent at llms.txt or agent-oriented docs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Rely on versioned APIs with a documented deprecation policy G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none± | 0/10 | ||
Subscribe to events via webhooks G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | none | 0/10 | ||
Build against official SDKs G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Issue scoped/least-privilege API credentials for an agent G Agent access | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Operate the product with natural-language commands G Agentic features | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 2 | n/a | untested | none yet | |
Test against a sandbox environment without touching production data G Api quality | ai-native user | Agenticness — how well agents can access and operate the productAgenticness | 1 | n/a | untested | none yet | |
Scan a repository and its full git history for hardcoded secrets and credentials C Secret scanning | developer | Secret detection — stories about secret detection in this arenaSecret detection | 3 | fullfree | 9/10 | Cclaimed | |
Baseline or ignore existing and false-positive findings so only new issues alert C Fp management | security-engineer | Triage noise — stories about triage noise in this arenaTriage noise | 3 | full | 8/10 | Cclaimed | |
Run scans in CI on every pull request and fail the build on new findings via exit codes C Ci gates | devops-lead | Ci precommit — stories about ci precommit in this arenaCi precommit | 3 | fullfree | 8/10 | Cclaimed | |
Run the scanner as a pre-commit hook so secrets and issues never enter my git history C Pre commit | developer | Ci precommit — stories about ci precommit in this arenaCi precommit | 3 | full | 8/10 | Cclaimed | |
Self-host the core product G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | fullfree | 8/10 | Cclaimed | |
Define rules that trigger actions automatically on events G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 3 | partial | 5/10 | Cclaimed | |
Have an agent run a scan headlessly via the CLI, parse machine-readable results, and file issues for real findings G Agent scanning | ai-native user | Ci precommit — stories about ci precommit in this arenaCi precommit | 3 | partial | 5/10 | Cclaimed | |
Run static analysis that finds vulnerability classes like injection and XSS in my source code C Code analysis | developer | Sast rules — stories about sast rules in this arenaSast rules | 3 | n/a | 0/10 | ||
Use AI to triage findings — explaining them, deduplicating, and flagging likely false positives C Ai triage | ai-native user | Triage noise — stories about triage noise in this arenaTriage noise | 3 | none | 0/10 | ||
Export all of my data in open formats and leave G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 3 | n/afree | untested | none yet | |
Prevent my data from being used to train AI models G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 3 | n/a | untested | none yet | |
Scan container images for OS-package and application-layer vulnerabilities before deploying them C Containers | devops-lead | Container scanning — stories about container scanning in this arenaContainer scanning | 3 | n/a | untested | none yet | |
Scan my dependency manifests and lockfiles for packages with known vulnerabilities C Sca scanning | developer | Dependency sca — stories about dependency sca in this arenaDependency sca | 3 | n/a | untested | none yet | |
Define custom detection rules for my organization's internal token and secret formats C Custom detection | security-engineer | Secret detection — stories about secret detection in this arenaSecret detection | 2 | full | 8/10 | Cclaimed | |
See scan findings surfaced as pull-request comments or checks in GitHub or GitLab C Ci gates | developer | Ci precommit — stories about ci precommit in this arenaCi precommit | 2 | full | 8/10 | Cclaimed | |
Read the product's source under an open license G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | fullfree | 7/10 | Tprobed | |
Write custom static-analysis rules in a simple syntax and share them across repositories C Custom rules | security-engineer | Sast rules — stories about sast rules in this arenaSast rules | 2 | partial | 7/10 | Cclaimed | |
Perform bulk operations across many items at once G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | partial | 6/10 | Cclaimed | |
Scan projects across all the major languages and package ecosystems my organization uses C Coverage | developer | Coverage accuracy — stories about coverage accuracy in this arenaCoverage accuracy | 2 | partial | 6/10 | Cclaimed | |
Emit scan results in machine-readable formats like JSON or SARIF for downstream tooling C Output formats | developer | Coverage accuracy — stories about coverage accuracy in this arenaCoverage accuracy | 2 | partial | 5/10 | Cclaimed | |
Wire the scanner into my coding agent so AI-generated code is scanned for issues before it lands C Agent scanning | ai-native user | Ci precommit — stories about ci precommit in this arenaCi precommit | 2 | partial | 4/10 | Cclaimed | |
Apply suggested or automatic code fixes for findings instead of only reading reports C Fix suggestions | developer | Sast rules — stories about sast rules in this arenaSast rules | 2 | none | 0/10 | ||
Control data retention and deletion G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | n/a | 0/10 | ||
Do everything through the API that I can do in the UI G | ai-native user | Openness — open source, data portability, and self-hosting storiesOpenness | 2 | n/a | 0/10 | ||
Filter and gate on findings by severity or confidence so low-value noise does not block builds C Fp management | developer | Triage noise — stories about triage noise in this arenaTriage noise | 2 | none | 0/10 | ||
Scan non-git sources like S3 buckets, Docker images, and CI logs for leaked secrets C Secret scanning | security-engineer | Secret detection — stories about secret detection in this arenaSecret detection | 2 | none | 0/10 | ||
Choose where my data is stored (region/residency) G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | n/a | untested | none yet | |
Detect taint-style vulnerabilities that flow across files and function boundaries C Code analysis | security-engineer | Sast rules — stories about sast rules in this arenaSast rules | 2 | n/a | untested | none yet | |
Generate a software bill of materials (SPDX or CycloneDX) for my project or image C Sbom | security-engineer | Supply chain sbom — stories about supply chain sbom in this arenaSupply chain sbom | 2 | n/a | untested | none yet | |
Get concrete upgrade paths or automated fix pull requests that remediate vulnerable dependencies C Dependency fixes | developer | Dependency sca — stories about dependency sca in this arenaDependency sca | 2 | n/a | untested | none yet | |
Have AI draft remediation pull requests for security findings that I review and merge C Ai remediation | ai-native user | Sast rules — stories about sast rules in this arenaSast rules | 2 | n/a | untested | none yet | |
Have detected secrets verified against the issuing service so I know which ones are live C Secret scanning | security-engineer | Secret detection — stories about secret detection in this arenaSecret detection | 2 | none | untested | none yet | |
Opt out of telemetry and usage tracking G | ai-native user | Privacy posture — data-handling and privacy storiesPrivacy posture | 2 | nonefree | untested | none yet | |
Prioritize dependency alerts by whether the vulnerable code is actually reachable from my code C Sca scanning | security-engineer | Dependency sca — stories about dependency sca in this arenaDependency sca | 2 | n/a | untested | none yet | |
Scan Terraform, Kubernetes, and other IaC files for security misconfigurations C Iac misconfig | devops-lead | Container scanning — stories about container scanning in this arenaContainer scanning | 2 | n/a | untested | none yet | |
Schedule recurring jobs or workflows G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 2 | none | untested | none yet | |
Detect the licenses of my dependencies and enforce a license policy in scans C Licenses | devops-lead | Supply chain sbom — stories about supply chain sbom in this arenaSupply chain sbom | 1 | n/a | untested | none yet | |
Version, review, and roll back my automations G | ai-native user | Automation depth — how much of the product can run unattendedAutomation depth | 1 | n/a | untested | none yet |
Opportunities — the stories that would move this product's scores, from its own judged verdictsOpportunitiestop 8 of 22 stories with headroom
What would move Gitleaks’s scores — derived from its own judged verdicts, biggest headroom first. Each line quotes what the judge found missing; shipping it (or evidencing it publicly) is the fix.
Agenticness — how well agents can access and operate the productDrive the product through a documented public API
nonemoves agent-readyimpact 45
Gitleaks is a CLI/scanner tool with no documented public API for programmatic/agentic access; probes confirm no llms.txt and no OpenAPI/swagger endpoint exist, and the CLI/GitHub Action docs don't constitute a public API.
Triage noise — stories about triage noise in this arenaUse AI to triage findings — explaining them, deduplicating, and flagging likely false positives
nonemoves PA Scoreimpact 30
No evidence of any AI-based triage, explanation, deduplication, or false-positive flagging feature; Gitleaks only offers manual allowlists, baselines, and composite rules for reducing noise, none of which use AI.
Agenticness — how well agents can access and operate the productPoint an agent at llms.txt or agent-oriented docs
nonemoves agent-readyimpact 30
A direct probe found no llms.txt file (404) and no agent-oriented docs/openapi endpoints, so there is no evidence Gitleaks provides machine-readable docs for AI agents.
Agenticness — how well agents can access and operate the productGet AI-generated insights and suggestions from my data inside the product
nonemoves Built-in AIimpact 30
Gitleaks is a rule-based secret-detection scanner with no evidence of AI-generated insights, summaries, or suggestions; probes for llms.txt and API/OpenAPI endpoints returned 404, and all documented features are deterministic regex/rule-based scanning, alerting, and CI integration.
Agenticness — how well agents can access and operate the productSubscribe to events via webhooks
nonemoves agent-readyimpact 30
Gitleaks is a CLI secret-scanning tool with CI integrations (GitHub Action, PR comments, alerts) but no evidence of a webhook subscription mechanism for events; probes for API/openapi specs returned 404s, and no webhook docs exist.
Agenticness — how well agents can access and operate the productExplore an interactive API reference with runnable examples
nonemoves API qualityimpact 30
Gitleaks is a CLI secret-scanning tool with no interactive API reference; probes explicitly show no llms.txt and no OpenAPI/swagger spec found on gitleaks.io, and evidence only documents CLI commands, not a runnable API playground.
Agenticness — how well agents can access and operate the productDownload a machine-readable API spec (OpenAPI or equivalent)
nonemoves API qualityimpact 30
Gitleaks is a CLI secret-scanning tool with no API/web service, and direct probes confirm no OpenAPI or machine-readable spec exists at any expected location.
Agenticness — how well agents can access and operate the productRely on versioned APIs with a documented deprecation policy
nonemoves API qualityimpact 30
Gitleaks is a CLI/CI secret-scanning tool with no evidence of a public/versioned API; probes for OpenAPI spec and llms.txt both returned 404s, and there's no mention of an API deprecation policy anywhere in the evidence.
Showing the top 8 of 22 — every none/partial verdict in the story verdicts table is headroom.
Think a verdict is wrong? Every verdicts-table row has a Flag link — see the methodology.
Coverage map — which docs area, API section, or community source covers which judged storiesCoverage map2 surfaces · 18 covered stories
Where the cited evidence behind each covered verdict came from — the same citations the verdicts table shows, no extra judging.
GitHub README18 stories
- Run the product headlessly / in CI for automation
- Use an official CLI
- Set up automations that run autonomously in the background
- Perform bulk operations across many items at once
- Define rules that trigger actions automatically on events
- Have an agent run a scan headlessly via the CLI, parse machine-readable results, and file issues for real findings
- Wire the scanner into my coding agent so AI-generated code is scanned for issues before it lands
- Run scans in CI on every pull request and fail the build on new findings via exit codes
- See scan findings surfaced as pull-request comments or checks in GitHub or GitLab
- Run the scanner as a pre-commit hook so secrets and issues never enter my git history
- Scan projects across all the major languages and package ecosystems my organization uses
- Emit scan results in machine-readable formats like JSON or SARIF for downstream tooling
- Read the product's source under an open license
- Self-host the core product
- Write custom static-analysis rules in a simple syntax and share them across repositories
- Define custom detection rules for my organization's internal token and secret formats
- Scan a repository and its full git history for hardcoded secrets and credentials
- Baseline or ignore existing and false-positive findings so only new issues alert
Probe proofs — replayable recordings from the probe harnessProbe proofs
Replayable recordings from our probe harness — see the Prove-It protocol to submit one.
$gitleaks versionreproduced$ gitleaks version 8.30.1
Claims vs evidence — vendor claims reconciled against independent verdictsClaims vs evidence
0 of 7 testable claims verified · 1 contradicted → integrity 0/100
16 distinct capability claims found in Gitleaks’s own claimed-docs/GitHub materials, reconciled against our judge’s independent verdicts.
0
Verified
6
Unverified
1
Contradicted
12
Undersold
Unverified (11)
“Scan local git repositories and their full commit history for secrets”
Scan a repository and its full git history for hardcoded secrets and credentialsfullproof ↗
“Run as a pre-commit git hook, blocking commits that contain secrets”
Run the scanner as a pre-commit hook so secrets and issues never enter my git historyfullproof ↗
“Commit is rejected/failed when a hardcoded secret is detected in it”
Run the scanner as a pre-commit hook so secrets and issues never enter my git historyfullproof ↗
“Write custom secret-detection rules using a configuration format”
Define custom detection rules for my organization's internal token and secret formatsfullproof ↗
“Composite rules combine a primary rule with required auxiliary rules for more precise detection”
Define custom detection rules for my organization's internal token and secret formatsfullproof ↗
“Use a baseline file so previously known findings are ignored and only new issues are reported”
Baseline or ignore existing and false-positive findings so only new issues alertfullproof ↗
“Baseline-path scanning produces a findings report containing only new issues”
Baseline or ignore existing and false-positive findings so only new issues alertfullproof ↗
“GitHub Action alerts teams in workflows as soon as secrets are leaked”
Run scans in CI on every pull request and fail the build on new findings via exit codesfullproof ↗
“Action can run scans automatically on all pull requests/commits or on-demand”
Run scans in CI on every pull request and fail the build on new findings via exit codesfullproof ↗
“Uses a GitHub API token to post scan findings as comments on pull requests”
See scan findings surfaced as pull-request comments or checks in GitHub or GitLabfullproof ↗
“Config path can be set via GITLEAKS_CONFIG or auto-detected from a gitleaks.toml at repo root”
Define custom detection rules for my organization's internal token and secret formatsfullproof ↗
Contradicted (1)
“Stream arbitrary data via stdin to scan for secrets outside a git repo”
Scan non-git sources like S3 buckets, Docker images, and CI logs for leaked secretsnoneproof ↗
Undersold (12)
Run the product headlessly / in CI for automationfullproof ↗
Set up automations that run autonomously in the backgroundpartialproof ↗
Perform bulk operations across many items at oncepartialproof ↗
Define rules that trigger actions automatically on eventspartialproof ↗
Have an agent run a scan headlessly via the CLI, parse machine-readable results, and file issues for real findingspartialproof ↗
Wire the scanner into my coding agent so AI-generated code is scanned for issues before it landspartialproof ↗
Scan projects across all the major languages and package ecosystems my organization usespartialproof ↗
Emit scan results in machine-readable formats like JSON or SARIF for downstream toolingpartialproof ↗
Write custom static-analysis rules in a simple syntax and share them across repositoriespartialproof ↗
Claims outside our story set (4)
Real capability claims found in Gitleaks’s own materials, but no story in this arena’s taxonomy covers them yet — that’s feedback on the taxonomy, not a mark against the product.
“Scan arbitrary directories and files (not just git repos) for secrets”
source ↗“Installable via Homebrew, Docker, or Go”
source ↗“Configurable list of GitHub accounts to notify when a leak is detected”
source ↗“Provides a 'protected by gitleaks' badge to display in project README”
source ↗
Business model
MIT-licensed open-source secret scanner; the maintainer monetizes via GitHub Sponsors and a license key for organizations using the Gitleaks GitHub Action.
pricing ↗Score trend
How this product’s scores have moved as evidence and verdicts are re-derived — a point per change, not per day.
Try Experimental
Run it in the microterminal →Recorded agent sessions — and a live MCP handshake where the vendor ships one.
Flag
⚑ Flag a verdictThink a verdict is wrong? Opens a prefilled GitHub issue — or use the ⚑ next to any verdict above.
For agents
