CISO and CSO

A new attack surface your current stack cannot see.

Your secret scanners watch git. Your DLP watches email and endpoints. Nobody is watching AI coding session logs - and that is where credentials are leaking today, in plaintext, outside every control you have.

Skarn is the local-first, no-egress forensic layer for the AI-session surface the inline and cloud tools disclaim: local-disk session content, MCP and tool-call detail, and post-hoc attack-chain reconstruction with a session risk score.

248
Detection rules and growing - 93 AI-specific plus 155 community, continuously updated
5
AI assistants covered: Claude Code, Cursor, GitHub Copilot, Gemini CLI, Codex CLI
0
Network calls by default - fully air-gappable, no egress, no vendor access
<1ms
Per-session scan time; real-time pre-execution guard hook around 35ms per call

What Skarn detects

Live credentials in AI session logs

AWS keys, database URIs, OAuth tokens, .env file contents, API keys - pasted into a chat and never committed to git. Invisible to your secret scanners. Obvious to Skarn.

Prompt injection and AI-specific attack chains

Skarn maps the full attack chain: poisoned content drives a credential read, the assistant exfiltrates. Findings are mapped against MITRE ATLAS techniques and the OWASP Top 10 for LLM Applications 2025, and the chain is correlated across ATLAS tactic-aligned stages. Not just the secret - the mechanism.

Encoded exfiltration via tool calls

Base64-encoded payloads piped to curl, wget, or netcat through agentic tool calls - the class of exfiltration that looks like normal developer activity until the pattern is surfaced.

Architecture and integration

Deployment

Single binary, on-premise only. macOS, Windows, Linux (Intel + ARM). No cloud dependency, no vendor dashboard enrolment, no persistent agent required.

Output formats

SARIF and JSON for SIEM integration. Risk scores per session and per team. CI/CD gate support for policy enforcement at the pipeline level.

Standards-vocabulary findings

Every finding is crosswalked against MITRE ATLAS, the OWASP Top 10 for LLM Applications 2025, and CWE, emitted as SARIF 2.1.0 taxonomies and mirrored to result tags. Findings land in your SIEM and ASPM in a standard vocabulary your team already triages against, not a vendor-specific one. See the standards crosswalk.

Real-time guard mode

A pre-execution hook (Claude Code, Cursor, Codex CLI, and GitHub Copilot) intercepts and blocks malicious tool calls before execution - a hardcoded credential, a typosquatted package - without interrupting the developer.

Redaction policy

All credentials masked in reports. Raw values never appear in output, enforced by a gate. Each finding attributed to the exact session and message.

Regulatory obligations Skarn helps satisfy

NIS-2, Article 21

Requires assessing the effectiveness of cybersecurity risk-management measures, including software-development security. Skarn provides documented, SARIF-format evidence of AI-session scanning - the auditable artifact supervisory authorities expect. Management-body members are accountable under Article 20.

DORA, Article 8 (BaFin)

Requires financial entities to identify ICT vulnerabilities. Credential exposure through AI development tools is a direct ICT risk. The management body owns the framework under Article 5. Applicable since 17 January 2025, supervised by BaFin for German entities.

EU AI Act, Article 12

From 2 August 2026, high-risk AI systems must technically allow the automatic recording of events over their lifetime. Skarn is not an AI system under the Act, so it is not in scope itself. Where you must show that AI activity is monitored, --audit-log (Team) appends a hash-chained record of each scan - timestamp, policy, finding counts, verdict, no secrets - and detects in-place edits and reordering of that history.

KRITIS-Dachgesetz

In force since 17 March 2026 for the physical resilience of critical installations; the cyber duties for the same operators sit in NIS-2 and the BSIG. Operators registering with the BBK by 17 July 2026 document their technical, security-related, and organisational measures - and AI-session exposure is now part of that picture. Skarn produces the evidence locally, with nothing leaving your machines.

BSI C5 and the EU Cloud Sovereignty Framework

Both assess cloud services: C5 through an auditor's attestation, the Commission's framework (2025-10-20) through a sovereignty score on data localisation, operational control, and legal jurisdiction. Skarn ships no cloud service, so neither applies to it and no vendor cloud enters your assessment scope.

Skarn surfaces exposure - it does not auto-remediate. Your team owns the response: credential rotation, developer coaching, policy enforcement. Visibility and evidence, not a black-box fix.

More for your team: CTO and VP Eng, Legal and DPO, CEO and Board

Request a technical assessment

Run Skarn on a sample of developer machines and see, in your own data, what is leaking into AI sessions right now. Nothing sent to a cloud.

[email protected]