CISO and CSO
A new attack surface your current stack cannot see.
Your secret scanners watch git. Your DLP watches email and endpoints. AI coding session logs sit outside both, and that is where credentials are leaking today, unencrypted.
Skarn is the local-first, no-egress forensic layer for the AI-session surface the inline and cloud tools disclaim: local-disk session content, MCP and tool-call detail, and post-hoc attack-chain reconstruction with a session risk score.
What you can answer today, and after one scan
| The question | With the assistants as installed | After skarn assess on the same machine |
|---|---|---|
| Which credentials went into an AI coding session? | Each assistant keeps its own session store on the developer's disk, in its own format and location. The vendor documentation we reviewed for Claude Code, Codex, Cursor, Copilot and Gemini describes transcripts, audit logs and usage metrics, and no report of the credentials inside sessions. Repository secret scanners read repositories. | One list over every supported assistant on the machine: each credential masked, with its severity and what kind of credential it is. The HTML report adds the rule and the session for each. |
| Was a session steered into reading a secret and sending it somewhere? | The steps are separate tool calls inside one transcript, or across several. Finding them means reading transcripts by hand. | The read, the injection and the outbound call are linked into one attack chain. It raises the machine's risk score, and the HTML report maps each finding in it to MITRE ATLAS. |
| Can security see a finding without seeing the secret? | The session files these assistants write hold the secret in full. | A redacted Markdown or HTML report, or a dossier scoped to one finding. No report carries a secret in full. |
| How exposed is this machine, as a number? | The assistants report none. | A risk score from 0 to 100 with its band, and severity counts. |
| How far back does it go? | As far as each assistant keeps its sessions. Claude Code and Gemini CLI delete sessions older than 30 days by default. | The same. Skarn reads what is on disk and changes none of it. |
skarn assess needs no account and no license, and the scan makes no network call. Install Skarn and run it, or open a sample report first.
What Skarn detects
AWS keys, database URIs, OAuth tokens, .env file contents, API keys - pasted into a chat and never committed to git. Invisible to your secret scanners. Obvious to Skarn.
Skarn maps the full attack chain: poisoned content drives a credential read, the assistant exfiltrates. Findings are mapped against MITRE ATLAS techniques and the OWASP Top 10 for LLM Applications 2025, and the chain is correlated across ATLAS tactic-aligned stages: the secret and the mechanism. Before you put that in front of an analyst, read what the correlation costs in false positives.
Base64-encoded payloads piped to curl, wget, or netcat through agentic tool calls - the class of exfiltration that looks like normal developer activity until the pattern is surfaced.
Architecture and integration
Single binary, on-premise only. macOS, Windows, Linux (Intel + ARM). No cloud dependency, no vendor dashboard enrolment, no persistent agent required.
SARIF and JSON for SIEM integration. Risk scores per session and per team. CI/CD gate support for policy enforcement at the pipeline level.
Every finding is crosswalked against MITRE ATLAS, the OWASP Top 10 for LLM Applications 2025, and CWE, emitted as SARIF 2.1.0 taxonomies and mirrored to result tags. Findings land in your SIEM and ASPM in a standard vocabulary your team already triages against, not a vendor-specific one. See the standards crosswalk.
A pre-execution hook (Claude Code, Gemini CLI, Antigravity, Codex CLI, Cursor, GitHub Copilot, Kimi Code CLI, Grok Build, Cline) intercepts and blocks malicious tool calls before execution - a hardcoded credential, a typosquatted package - without interrupting the developer.
All credentials masked in reports. Raw values never appear in output, enforced by a gate. Each finding attributed to the exact session and message.
The regulations, by purpose
NIS-2 asks organisations to manage their cyber risk, including the security of how they develop software, and to show that the measures work. Skarn provides documented, SARIF-format evidence of AI-session scanning.
DORA asks financial entities to identify the weaknesses in their ICT systems. Credential exposure through AI development tools is one of them, and Skarn finds it.
The AI Act sets rules for AI systems and the records kept about them. Where you keep a record that AI activity is monitored, --audit-log (Pro) appends a hash-chained record of each scan - timestamp, policy, finding counts, verdict, no secrets - and detects in-place edits and reordering of that history.
The umbrella law asks operators of critical installations to document their resilience measures. Skarn produces a local record of what AI coding sessions exposed, with nothing leaving your machines.
Both assess cloud services: C5 through an auditor's attestation, the Commission's framework through a sovereignty score. The scan runs on your own machines and makes no network call when it scans.
More for your team: CTO and VP Eng, Legal and DPO, CEO and Board, Sovereign and air-gapped
Book a live demo
Run Skarn on a developer's machine and see, in your own data, what is leaking into AI sessions right now. Nothing sent to a cloud.