MagAudit vs TruffleHog
Written by the people who make one of the two. Read it with that in mind.
TruffleHog does one thing we will never do
TruffleHog verifies a found credential by calling the provider's API to see whether it still works. That is genuinely useful: it separates a live key from a rotated one, and it collapses the triage pile.
We do not do it, and it is not a roadmap item. Under
article 197 bis of the Spanish Penal Code — we operate
from Spain — using someone else's credential to access a system without
authorisation carries six months to two years. Our scanner talks to
api.github.com and to the package registries, and to nothing
else. There is a test that fails if any other request is made.
If verification is what you need, use TruffleHog. It is open source and free.
Where we differ
| TruffleHog | MagAudit | |
|---|---|---|
| Verifies the key against the provider | Yes | No, by design |
| Runs in CI you configure | Yes | No CI config; a GitHub App |
| Browser-boundary violations | — | Yes |
| Comments on the pull request with file, line and fix | Via your pipeline | Built in |
| Config-file awareness see the two cases below | — | Yes |
The two cases that cost us a public apology
We were preparing security notices for public repositories, and we check every one by hand before sending. Both of these were wrong, and both are now pinned by a regression test written from the exact line:
1. A variable forced empty is the fix, not the bug
...(command === "build"
? { "import.meta.env.VITE_OPENAI_API_KEY": '""' }
: {}),
That line removes the key from every production build. A six-line
comment above it explains that Vite inlines VITE_* into the
bundle. We would have told a team that understands this better than our
scanner does that they have the bug they had already fixed.
2. Reading a variable in Node is not publishing it
module.exports = {
openAIApiKey: process.env.VITE_OPENAI_API_KEY,
}
A translation tool's configuration. It runs in Node at build time. The
VITE_ prefix misleads: the variable is never referenced by client
code, so nothing reaches the browser. Any scanner that greps for the prefix
will flag this, and be wrong.
Last reviewed: 18 September 2026. Every figure about us is our own measurement and reproducible against our public endpoint and our error record. Any figure about another product is either verifiable by you in one step or marked as reported by someone else. Until today this line claimed every figure here was our own measurement, which was not true of all of them.