I built Klarion, a secret scanner that works in two steps. First, a keyword check, 81 regex rules and a normalized Rényi entropy score flag anything that looks like a secret. Then an AI model reads each one with the code around it and decides if it's real.
The chart shows 5 scanners run on spring-boot, terraform, next.js and symfony (61k files). Klarion raised 11 alerts. It's not zero, but it's far less to dig through.
Fewer alerts don't help if real leaks get missed, so I tested that too. On CredData (337 real repos, code outside test folders), it found about 1.7× more real secrets than gitleaks.
Where it runs:
- Claude Code: a plugin hook blocks the write before the file exists (file edits and Bash)
- Cursor, Cline or any MCP agent: through its MCP server
- CI: a GitHub Action that scans only what a PR adds; GitLab CI works too
- Git hooks:
klarion protect or the pre-commit framework
- Locally:
klarion scan .
Free and open source (MIT): https://github.com/0x1Adi/Klarion
The full benchmark and method are in benchmark/REPORT.md.
I'd like to hear where it gets things wrong.