TRUFFLES

Find repos at scale.
Scan every commit.
Catch leaked secrets.

Enumerate owners or search GitHub globally, filter with globs or regex, then scan full git history with trufflehog — or run both steps from a YAML playbook.

truffles
truffles CLI — find, filter, and scan for secrets
truffles — quickstart
truffles — search openhat-security, filter with *run*, author a playbook, run it

What is truffles?

truffles is an open-source CLI that finds GitHub repos at scale, filters them, and scans full git history with trufflehog — or runs both steps from a YAML playbook.

Read docs

Get started in 3 commands

Architecture notes
  1. 1.

    Install

  2. 2.

    Wizard

  3. 3.

    Scan

Search · filter · scan · playbook

Terminal tours for each step of the secrets pipeline.

FAQ

What is truffles?

An open-source CLI to find GitHub repos at scale, filter them, and scan full git history with trufflehog — or run both steps from a YAML playbook.

How do I use truffles?

Install from the tabs above, then run truffles wizard. Or search an owner, write a repo list, and scan with truffles scan -f repos.txt.

Do I need a GitHub token?

Optional for public search. Required for private repos. Set GITHUB_TOKEN (or GH_TOKEN) in your environment.

What about trufflehog?

scan shells out to trufflehog on PATH. Override with -bin if needed. Install trufflehog separately.

Are reports safe to commit?

No. Reports contain secrets in plaintext and are gitignored by default. Keep them out of version control.

What does [!!] mean?

Not scanned — never counted as clean. [ok] is clean, [++] means findings.

Is -max-depth safe?

No. -max-depth N is lossy and can miss old commits. Prefer full history when secrets matter.

Is truffles open source?

Yes. MIT. Issues and PRs are welcome on GitHub.

Collaborate

Looking to collaborate — or searching for offensive security / secrets research work?

Check out OpenHat Security on GitHub — truffles, RunHug, and related tooling live there. If you want to contribute playbooks, proxy pools, cluster workers, or talk about engagements that need secrets hunting at scale, email Adam.

© 2026 Adam SiwiecMITGitHub