MagAudit vs TruffleHog

Written by the people who make one of the two. Read it with that in mind.

TruffleHog does one thing we will never do

TruffleHog verifies a found credential by calling the provider's API to see whether it still works. That is genuinely useful: it separates a live key from a rotated one, and it collapses the triage pile.

We do not do it, and it is not a roadmap item. Under article 197 bis of the Spanish Penal Code — we operate from Spain — using someone else's credential to access a system without authorisation carries six months to two years. Our scanner talks to api.github.com and to the package registries, and to nothing else. There is a test that fails if any other request is made.

If verification is what you need, use TruffleHog. It is open source and free.

Where we differ

TruffleHogMagAudit
Verifies the key against the providerYesNo, by design
Runs in CI you configureYesNo CI config; a GitHub App
Browser-boundary violations—Yes
Comments on the pull request with file, line and fixVia your pipelineBuilt in
Config-file awareness
see the two cases below
—Yes

The two cases that cost us a public apology

We were preparing security notices for public repositories, and we check every one by hand before sending. Both of these were wrong, and both are now pinned by a regression test written from the exact line:

1. A variable forced empty is the fix, not the bug

...(command === "build"
  ? { "import.meta.env.VITE_OPENAI_API_KEY": '""' }
  : {}),

That line removes the key from every production build. A six-line comment above it explains that Vite inlines VITE_* into the bundle. We would have told a team that understands this better than our scanner does that they have the bug they had already fixed.

2. Reading a variable in Node is not publishing it

module.exports = {
  openAIApiKey: process.env.VITE_OPENAI_API_KEY,
}

A translation tool's configuration. It runs in Node at build time. The VITE_ prefix misleads: the variable is never referenced by client code, so nothing reaches the browser. Any scanner that greps for the prefix will flag this, and be wrong.

Install on GitHub →

Last reviewed: 18 September 2026. Every figure about us is our own measurement and reproducible against our public endpoint and our error record. Any figure about another product is either verifiable by you in one step or marked as reported by someone else. Until today this line claimed every figure here was our own measurement, which was not true of all of them.