CISO and CSO

A new attack surface your current stack cannot see.

Your secret scanners watch git. Your DLP watches email and endpoints. AI coding session logs sit outside both, and that is where credentials are leaking today, unencrypted.

Skarn is the local-first, no-egress forensic layer for the AI-session surface the inline and cloud tools disclaim: local-disk session content, MCP and tool-call detail, and post-hoc attack-chain reconstruction with a session risk score.

251
Detection rules - 96 AI-specific plus 155 community
13
AI assistants covered: Claude Code, Gemini CLI, Antigravity, Codex CLI, Cursor, GitHub Copilot, Kimi Code CLI, Grok Build, Grok Bot, OpenCode, Cline, Cowork, Claude Enterprise
0
Network calls by default - fully air-gappable, no egress, no vendor access
<1ms
Per-session scan time; real-time pre-execution guard hook around 35ms per call

What you can answer today, and after one scan

The question With the assistants as installed After skarn assess on the same machine
Which credentials went into an AI coding session? Each assistant keeps its own session store on the developer's disk, in its own format and location. The vendor documentation we reviewed for Claude Code, Codex, Cursor, Copilot and Gemini describes transcripts, audit logs and usage metrics, and no report of the credentials inside sessions. Repository secret scanners read repositories. One list over every supported assistant on the machine: each credential masked, with its severity and what kind of credential it is. The HTML report adds the rule and the session for each.
Was a session steered into reading a secret and sending it somewhere? The steps are separate tool calls inside one transcript, or across several. Finding them means reading transcripts by hand. The read, the injection and the outbound call are linked into one attack chain. It raises the machine's risk score, and the HTML report maps each finding in it to MITRE ATLAS.
Can security see a finding without seeing the secret? The session files these assistants write hold the secret in full. A redacted Markdown or HTML report, or a dossier scoped to one finding. No report carries a secret in full.
How exposed is this machine, as a number? The assistants report none. A risk score from 0 to 100 with its band, and severity counts.
How far back does it go? As far as each assistant keeps its sessions. Claude Code and Gemini CLI delete sessions older than 30 days by default. The same. Skarn reads what is on disk and changes none of it.

skarn assess needs no account and no license, and the scan makes no network call. Install Skarn and run it, or open a sample report first.

What Skarn detects

Live credentials in AI session logs

AWS keys, database URIs, OAuth tokens, .env file contents, API keys - pasted into a chat and never committed to git. Invisible to your secret scanners. Obvious to Skarn.

Prompt injection and AI-specific attack chains

Skarn maps the full attack chain: poisoned content drives a credential read, the assistant exfiltrates. Findings are mapped against MITRE ATLAS techniques and the OWASP Top 10 for LLM Applications 2025, and the chain is correlated across ATLAS tactic-aligned stages: the secret and the mechanism. Before you put that in front of an analyst, read what the correlation costs in false positives.

Encoded exfiltration via tool calls

Base64-encoded payloads piped to curl, wget, or netcat through agentic tool calls - the class of exfiltration that looks like normal developer activity until the pattern is surfaced.

Architecture and integration

Deployment

Single binary, on-premise only. macOS, Windows, Linux (Intel + ARM). No cloud dependency, no vendor dashboard enrolment, no persistent agent required.

Output formats

SARIF and JSON for SIEM integration. Risk scores per session and per team. CI/CD gate support for policy enforcement at the pipeline level.

Standards-vocabulary findings

Every finding is crosswalked against MITRE ATLAS, the OWASP Top 10 for LLM Applications 2025, and CWE, emitted as SARIF 2.1.0 taxonomies and mirrored to result tags. Findings land in your SIEM and ASPM in a standard vocabulary your team already triages against, not a vendor-specific one. See the standards crosswalk.

Real-time guard mode

A pre-execution hook (Claude Code, Gemini CLI, Antigravity, Codex CLI, Cursor, GitHub Copilot, Kimi Code CLI, Grok Build, Cline) intercepts and blocks malicious tool calls before execution - a hardcoded credential, a typosquatted package - without interrupting the developer.

Redaction policy

All credentials masked in reports. Raw values never appear in output, enforced by a gate. Each finding attributed to the exact session and message.

The regulations, by purpose

NIS-2

NIS-2 asks organisations to manage their cyber risk, including the security of how they develop software, and to show that the measures work. Skarn provides documented, SARIF-format evidence of AI-session scanning.

DORA

DORA asks financial entities to identify the weaknesses in their ICT systems. Credential exposure through AI development tools is one of them, and Skarn finds it.

EU AI Act

The AI Act sets rules for AI systems and the records kept about them. Where you keep a record that AI activity is monitored, --audit-log (Pro) appends a hash-chained record of each scan - timestamp, policy, finding counts, verdict, no secrets - and detects in-place edits and reordering of that history.

KRITIS-Dachgesetz

The umbrella law asks operators of critical installations to document their resilience measures. Skarn produces a local record of what AI coding sessions exposed, with nothing leaving your machines.

BSI C5 and the EU Cloud Sovereignty Framework

Both assess cloud services: C5 through an auditor's attestation, the Commission's framework through a sovereignty score. The scan runs on your own machines and makes no network call when it scans.

Skarn surfaces exposure - it does not auto-remediate. Your team owns the response: credential rotation, developer coaching, policy enforcement.

More for your team: CTO and VP Eng, Legal and DPO, CEO and Board, Sovereign and air-gapped

Book a live demo

Run Skarn on a developer's machine and see, in your own data, what is leaking into AI sessions right now. Nothing sent to a cloud.

hello@getskarn.com