{
  "id": 10977813,
  "title": "From Theory to Practice: Three Small Tools for Big Security Problems",
  "url": "https://urgent.news/2026/09/30/from-theory-to-practice-three-small-tools-for-big-security-problems",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-30T15:38:43.000Z",
  "source": {
    "name": "HackerNoon",
    "slug": "hackernoon",
    "url": "https://hackernoon.com/from-theory-to-practice-three-small-tools-for-big-security-problems?source=rss"
  },
  "original_language": "en",
  "account": "In 2023, the author reflected on their early experiences in cybersecurity. They had learned valuable concepts like network topologies, Red Team vs Blue Team, and the Penetration Testing Execution Standard (PTES). However, the author felt that their knowledge lacked practical application. To address this, they developed three small security tools: sBOMBox, sBOMBPath, and KeyScan.\n\nEach tool tackles a specific aspect of cybersecurity. sBOMBox identifies vulnerable packages within a project's dependencies, checking against the Open Source Vulnerability Database (OSV), the GitHub Advisory Database, and the National Vulnerability Database (NVD). If critical vulnerabilities are found, the CI (Continuous Integration) pipeline fails. To avoid ignoring potential vulnerabilities, the tool only accepts advisory IDs, such as CVE, GHSA, or PYSEC, and does not permit ignoring vulnerabilities based on package names.\n\nsBOMBPath analyzes the project's code to determine if a specific vulnerability can be exploited. It identifies if a vulnerable function can be reached through user input, considering factors like reflection or getattr. However, the tool has limitations, such as not analyzing reflection or getattr, and its route mapping is specific to Django and Django REST Framework (DRF). The authors emphasize that these limitations should be seen as trust indicators, as a tool claiming to cover all vulnerabilities is likely to be less reliable.\n\nThe third tool, KeyScan, focuses on identifying leaked secrets within the project's code and its Git history. It checks for credentials related to various APIs and services, including cloud providers, payment processors, continuous integration systems, and AI platforms. The tool also verifies if a leaked secret is still active. KeyScan offers pre-commit hooks and GitHub Actions workflows to prevent secrets from being committed in the first place. By default, it excludes .env files, as they are intended for securely storing secrets. The tool prompts developers to review their code and ensure secrets are not inadvertently included elsewhere.\n\nThe three tools share common principles: they utilize only the Python standard library, avoiding additional dependencies or infrastructure. This approach, inspired by ArtemisFlow, ensures that the tools are easy to use and integrate into existing workflows. By automating security checks, the tools encourage consistent security practices and help prevent oversights. The author emphasizes that security is an ongoing process, not a one-time task, and automating these checks in CI (Continuous Integration) pipelines can help make security a habit. The combination of sBOMBox, sBOMBPath, and KeyScan provides a comprehensive approach to identifying and addressing common security vulnerabilities in Python projects.",
  "summary": "AI writes fast and leaves API keys in your code. I built three tiny Python tools to find vulnerable packages, reachable CVEs and leaked secrets.",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}