HOW THE ENGINE WORKS
The deterministic 6-layer exclusion pipeline, active secret scanner heuristics, and zero-egress architectural security guarantees.
1. DETERMINISTIC 6-LAYER EXCLUSION
Every single file or directory encountered during an async walk is evaluated through a strict, deterministic hierarchy before inclusion:
Purges system and OS noise: .git, .DS_Store, Thumbs.db, *.log, .cache, .tmp, tmp/.
Detects marker files (package.json, requirements.txt, Cargo.toml, go.mod) and eliminates bulky dependencies and build folders (node_modules, dist, venv, target, bin/obj).
Parses the project root .gitignore file using standard gitignore semantics. Layers on top of stack defaults without discarding them.
Discovers nested .gitignore files inside packages or services and scopes rules specifically to their relative subtrees.
Pre-excludes and flags secret-named files: .env*, *.pem, *.key, id_rsa, credentials.json, service-account*.json.
Applies user-selected saved profiles to force-include or force-exclude specific patterns.
2. TWO-LAYER SECRET DETECTION
The content secret scanner acts as an active second layer on top of filename exclusion. It reads candidate text files line-by-line (skipping binaries via isbinaryfile and files over 2 MB) to catch accidental credential leaks:
HIGH-CONFIDENCE RULES
- • AWS Access Key ID (
AKIA...) & secret keys - • GCP Service Account JSON structure
- • Azure Storage connection strings
- • GitHub Personal Access Tokens (
ghp_...) - • Stripe & OpenAI live API keys
- • Private key headers (
BEGIN RSA PRIVATE KEY) - • Generic variable assignments (
api_key = "...")
HEURISTICS & ENTROPY
- • JSON Web Tokens (3-segment base64url shape)
- • Shannon entropy > 4.65 bits/char
- • Placeholder filter (rejects
your_key_here) - • Zero raw credential leak in UI or logs
The secret scanner is an active safety net designed to catch common accidents. It is not a substitute for proper secrets management and cannot guarantee detection of custom-encrypted or highly obfuscated strings. Always inspect the tree preview before sharing sensitive repos.
3. AIR-GAPPED PRIVACY GUARANTEE
Xipper never transmits file names, paths, or code off your machine. The Electron renderer operates in a sandboxed process with nodeIntegration: false and contextIsolation: true. Local diagnostic logs in app.log never contain file contents and are capped at 5 MB with rotation.
