Documentation
README
Forensify
The agent stack you have already installed is your biggest blind spot.
repo-forensics catches threats before install. Forensify tells you what
is already on this machine, across every agent framework, and where the
credential, injection, and auto-execution surfaces are right now.
What makes this different
Every Codex user has ~/.codex/auth.json. TruffleHog will tell you it
contains secrets. Forensify tells you its permissions are 0o644 (world-readable),
its auth_mode is apiKey (non-rotating, broad-scope), it has not been refreshed
in 47 days, AND OpenClaw's models status command is known to silently
overwrite it (openai/codex#54506). That cross-ecosystem stack interaction
finding is a class no existing credential scanner produces.
This is the opening of the README. Read the full README on GitHub.