This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend
What I Built
I built RepoShield AI, a local-first security tool that helps developers identify and understand potential secret exposure in their repositories.
I built it for a developer friend who wanted a simpler way to investigate accidentally exposed credentials without sending sensitive repository information to a cloud AI service.
The core idea is simple:
Detect with deterministic security tooling. Explain locally. Never send raw secrets to the AI layer.
RepoShield combines:
π Gitleaks for deterministic secret detection
π‘οΈ A sanitization layer that withholds raw secrets and absolute paths
π€ Ollama + Gemma 3 1B for local AI-assisted analysis
π A React + TypeScript security dashboard
π Sanitized JSON and Markdown reports
The AI model is not responsible for detecting the secret.
Instead:
Repository
β
Gitleaks
β
Finding
β
Secure Sanitization
β
Safe Metadata
β
Ollama + Gemma 3 1B
β
Risk Explanation + Remediation.
This separation was one of the most important security decisions in the project.
Demo
The project has been validated as a local application with a real end-to-end workflow.
The validated demo performs:
Gitleaks detection
Authorized local repository scanning
Secret/path sanitization
Finding investigation
Local Gemma analysis
Risk explanation
Remediation guidance
Sanitized report generation.
Code
The complete project is open source:
devanshshukla-3004
/
RepoShield-AI
Local-first secret exposure review with Gitleaks detection, secure finding sanitization, and optional Ollama/Gemma AI triage.
RepoShield AI
Local-first secret exposure review for repositories β deterministic detection, privacy-preserving triage, and optional local AI assistance.
RepoShield AI helps developers review repositories for potential secret exposure before code is shared. It combines deterministic Gitleaks detection with a deliberately narrow privacy boundary and optional local Ollama / gemma3:1b analysis.
The core design principle is simple:
Detect with deterministic security tooling. Explain locally. Never send raw secrets to the AI layer.
Why RepoShield?
Secret scanners are good at finding patterns. Developers still need to understand what a finding means, how serious it may be, and what to do next.
RepoShield separates those responsibilities:
- Gitleaks detects potential secrets.
- RepoShield sanitizes the result before it reaches the UI or report layer.
- Gemma can explain the finding locally using only server-defined metadata.
- The developer triages and remediates the exposure.
This keeps AI in an advisory role rather than allowing a language modelβ¦
The repository contains the React frontend, Express API, security scanning logic, sanitization layer, AI integration, tests, CI configuration, architecture documentation, and demo media.
How I Built It
The project is built around Gemma 3 1B, running locally through Ollama.
The architecture uses:
React
TypeScript
Vite
Tailwind CSS
Express
Zod
Gitleaks
Ollama
Gemma 3 1B
GitHub Actions
The security pipeline intentionally separates detection from AI analysis.
Gitleaks detects potential secrets first. RepoShield then sanitizes the resulting finding before anything reaches the model.
The AI layer receives only controlled finding metadata needed to generate an explanation and remediation guidance.
It does not receive:
β Raw secret values
β Source code
β Absolute filesystem paths
β Raw scanner evidence
I also added automated tests around path safety and finding sanitization to make the security boundary testable rather than relying only on documentation.
Why Does Open Innovation Matter?
Open innovation made it possible to build the AI portion of this project around a local, open-weight model rather than requiring a closed cloud AI API.
That matters particularly for cybersecurity.
Security findings can contain sensitive information. Sending those findings to a third-party API creates another trust boundary.
With Ollama and Gemma, I could experiment with a local inference workflow where the AI analysis happens on the developer's machine.
More importantly, open models allowed me to design the system around the question:
What should the AI never receive?
Instead of simply sending scanner output to an LLM, I could build a privacy boundary between the security scanner and the model.
That made local AI a practical part of the security architecture rather than just a chatbot feature.
My Agent Session
I used AI-assisted development throughout the project, particularly for architecture exploration, debugging, testing, documentation, and implementation.
Prize Categories
Open-source AI / Local AI
Gemma 3 1B
Ollama
Local inference
Cybersecurity / Developer Tooling
Gitleaks
Secure finding sanitization
Repository security analysis
Top comments (0)