Secrets
API keys, tokens, private keys and credentials committed to the working tree.
- Cloud, SaaS and payment provider keys
- Findings are redacted — secret values are never stored
- Only a one-way hash is kept to track a finding across audits
Paste a GitHub repo, run an audit, get a graded report. vetkit checks for leaked secrets, vulnerable dependencies, risky code patterns and repo hygiene — whether the code was written by your team, a contractor or an AI agent.
acme/payments-api@main·9f3c2e1
SUCCEEDED86/100
10 findings · 0 critical
Top findings4 of 10
Slack webhook URL committed to source
src/notify/slack.ts:14
lodash 4.17.20 — command injection (CVE-2021-23337)
package-lock.json
SQL built from string concatenation
src/db/orders.ts:88
No SECURITY.md disclosure policy
repository root
How it works
No agents to install, no pipelines to wire up. Start in the browser; automate later with the API or MCP.
Sign in with GitHub and install the vetkit GitHub App on the repositories you choose — public or private. It asks for read-only access and nothing more.
Contents · Metadata · Pull requests — read
Paste a repository URL and pick a branch, tag or commit, or turn on auto-audit to re-run on every push to the default branch. vetkit makes a shallow, throwaway checkout and runs its analyzers against the files — without installing, building or executing anything.
github.com/acme/payments-api @ main
An A–F grade, a score per category, and every finding with file, line, severity and a suggested fix. Re-run later to see which findings are new and how many you fixed. Download Markdown or SARIF, or fetch JSON over the API.
B · 86/100 · 10 findings
What we check
Each audit runs proven open-source scanners and vetkit's own checks, then normalizes everything into a single list of deduplicated findings. The report names every analyzer and tool version that ran.
API keys, tokens, private keys and credentials committed to the working tree.
Known vulnerabilities in the packages your lockfiles pin, matched against the open OSV database.
Pattern-based analysis for risky code: injection, unsafe deserialization, weak crypto and similar mistakes.
The basics that make a codebase safe to hand over, open-source or deploy.
A heuristic estimate of how much of a codebase was written with AI assistance, based on commit trailers and cadence, agent config files such as CLAUDE.md or AGENTS.md, and a model review of a small sample of files.
Honest caveat: AI authorship cannot be reliably detected from code. This is a signal, not evidence — a conversation starter. It is informational only and never affects your grade.
Each category starts at 100 and loses points per finding, weighted by severity and capped per severity so a pile of minor findings cannot sink a repo. Categories are weighted into an overall score and a letter grade.
An unresolved critical finding caps the grade at D, and the report tells you why. Suppress false positives with a reason and an optional expiry; suppressions carry over to later audits and stay visible in the audit trail.
Security & privacy
We built vetkit around least privilege and short retention, because you are trusting it with your source.
vetkit can read the repositories you grant it. It cannot push, open issues, change settings or touch other repos.
No install scripts, builds or tests. Analyzers only read files, symlinks are disabled at checkout, and a repo’s own scanner config is ignored.
Each audit uses a shallow clone in a fresh temporary directory that is deleted when the audit finishes — pass or fail.
Secret findings are redacted before they are saved. We keep the file, line and a one-way hash — never the credential itself.
GitHub access tokens are minted per audit, scoped to that one repository, expire within an hour and are never written to disk or database.
Session tokens and API keys are stored only as hashes. An API key is shown exactly once, carries explicit scopes and can be revoked instantly.
Exactly what the app requests. GitHub will ask you to approve any change.
| Permission | Access |
|---|---|
| ContentsFetch the files at the commit you audit | Read |
| MetadataList repositories and default branches | Read |
| Pull requestsPull-request audits (coming soon) | Read |
| Email addressesIdentify your account at sign-in | Read |
More detail on our security page and in the privacy policy.
MCP & API
The vetkit MCP server gives Claude Code — and any other MCP client — tools to connect repos, run audits and read findings. Everything in the app is also available over a documented REST API.
claude mcp add vetkit -e VETKIT_API_KEY=vk_live_... -- npx -y @vetkit/mcp# Start an audit on a connected repositorycurl -X POST https://api.vetkit.dev/v1/orgs/$ORG_ID/audits \ -H "Authorization: Bearer $VETKIT_API_KEY" \ -H "Content-Type: application/json" \ -d "{\"repositoryId\":\"$REPO_ID\",\"ref\":\"main\"}" # Download the report as SARIF for GitHub code scanningcurl "https://api.vetkit.dev/v1/orgs/$ORG_ID/audits/$AUDIT_ID/report?format=sarif" \ -H "Authorization: Bearer $VETKIT_API_KEY" -o vetkit.sarifPricing
vetkit is new and we are onboarding teams in small batches. During the beta every feature is free — in exchange, we would love your feedback on what the reports get right and wrong.
Beta
$0no credit card required
When paid plans arrive we will announce them in advance, and nothing you run during the beta will be billed retroactively.
We are onboarding teams in small batches. Tell us about your team and the repositories you want to audit, and we will get you set up — free during beta.
Prefer to write directly? mehmetnamiduru@vetkit.dev