DEV Community

Devansh Shukla
Devansh Shukla

Posted on

πŸ” RepoShield AI β€” Local-First Secret Exposure Detection with Gitleaks + Gemma

Hacktoberfest Weekend Challenge: Build for a Friend Submission 🀝

This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend

What I Built

I built RepoShield AI, a local-first security tool that helps developers identify and understand potential secret exposure in their repositories.

I built it for a developer friend who wanted a simpler way to investigate accidentally exposed credentials without sending sensitive repository information to a cloud AI service.

The core idea is simple:
Detect with deterministic security tooling. Explain locally. Never send raw secrets to the AI layer.

RepoShield combines:

πŸ” Gitleaks for deterministic secret detection
πŸ›‘οΈ A sanitization layer that withholds raw secrets and absolute paths
πŸ€– Ollama + Gemma 3 1B for local AI-assisted analysis
πŸ“Š A React + TypeScript security dashboard
πŸ“„ Sanitized JSON and Markdown reports

The AI model is not responsible for detecting the secret.
Instead:
Repository
↓
Gitleaks
↓
Finding
↓
Secure Sanitization
↓
Safe Metadata
↓
Ollama + Gemma 3 1B
↓
Risk Explanation + Remediation.

This separation was one of the most important security decisions in the project.

Demo

The project has been validated as a local application with a real end-to-end workflow.

The validated demo performs:

Gitleaks detection
Authorized local repository scanning
Secret/path sanitization
Finding investigation
Local Gemma analysis
Risk explanation
Remediation guidance
Sanitized report generation.

Code

The complete project is open source:

GitHub logo devanshshukla-3004 / RepoShield-AI

Local-first secret exposure review with Gitleaks detection, secure finding sanitization, and optional Ollama/Gemma AI triage.

RepoShield AI

Local-first secret exposure review for repositories β€” deterministic detection, privacy-preserving triage, and optional local AI assistance.

CI Node.js TypeScript React Gitleaks Ollama License

RepoShield AI helps developers review repositories for potential secret exposure before code is shared. It combines deterministic Gitleaks detection with a deliberately narrow privacy boundary and optional local Ollama / gemma3:1b analysis.

The core design principle is simple:

Detect with deterministic security tooling. Explain locally. Never send raw secrets to the AI layer.


Why RepoShield?

Secret scanners are good at finding patterns. Developers still need to understand what a finding means, how serious it may be, and what to do next.

RepoShield separates those responsibilities:

  1. Gitleaks detects potential secrets.
  2. RepoShield sanitizes the result before it reaches the UI or report layer.
  3. Gemma can explain the finding locally using only server-defined metadata.
  4. The developer triages and remediates the exposure.

This keeps AI in an advisory role rather than allowing a language model…

The repository contains the React frontend, Express API, security scanning logic, sanitization layer, AI integration, tests, CI configuration, architecture documentation, and demo media.

How I Built It

The project is built around Gemma 3 1B, running locally through Ollama.

The architecture uses:

React
TypeScript
Vite
Tailwind CSS
Express
Zod
Gitleaks
Ollama
Gemma 3 1B
GitHub Actions

The security pipeline intentionally separates detection from AI analysis.

Gitleaks detects potential secrets first. RepoShield then sanitizes the resulting finding before anything reaches the model.

The AI layer receives only controlled finding metadata needed to generate an explanation and remediation guidance.

It does not receive:

❌ Raw secret values
❌ Source code
❌ Absolute filesystem paths
❌ Raw scanner evidence

I also added automated tests around path safety and finding sanitization to make the security boundary testable rather than relying only on documentation.

Why Does Open Innovation Matter?

Open innovation made it possible to build the AI portion of this project around a local, open-weight model rather than requiring a closed cloud AI API.

That matters particularly for cybersecurity.

Security findings can contain sensitive information. Sending those findings to a third-party API creates another trust boundary.

With Ollama and Gemma, I could experiment with a local inference workflow where the AI analysis happens on the developer's machine.

More importantly, open models allowed me to design the system around the question:
What should the AI never receive?

Instead of simply sending scanner output to an LLM, I could build a privacy boundary between the security scanner and the model.

That made local AI a practical part of the security architecture rather than just a chatbot feature.

My Agent Session

I used AI-assisted development throughout the project, particularly for architecture exploration, debugging, testing, documentation, and implementation.

Prize Categories

Open-source AI / Local AI

Gemma 3 1B
Ollama
Local inference

Cybersecurity / Developer Tooling

Gitleaks
Secure finding sanitization
Repository security analysis

Top comments (0)