Skip to content
Castellan
Toller's icon

Concept · Toller

Read as

What the Toller checks

The lockfiles, extensions, tools, git settings, open ports and places it reads; the rules behind each finding; how secrets are found and how far each went; and its limits.

Article
1702
Applies to
Toller 0.1.1
Last reviewed
For
For developers
Written for Toller 0.1.1. Toller is at 0.1.2 now (1 small release since: what changed).

Where it looks#

Your repositories: the ones Castellan and Reeve know, the usual folders (source\repos, Projects, code, dev and the like), and any you add in More folders with repositories. It skips node_modules, .git and build output, except lockfiles.

What entered your projects#

For each lockfile, what was added, updated and removed since the last look:

EcosystemLockfiles
npm, pnpm, yarnpackage-lock.json, npm-shrinkwrap.json, pnpm-lock.yaml, yarn.lock (classic and berry)
Pythonrequirements*.txt, Pipfile.lock, poetry.lock, uv.lock
RustCargo.lock
.NETpackages.lock.json
Gogo.sum

Two kinds of new package are flagged:

  • It runs a script when installed: npm's preinstall, install or postinstall, as the lockfile or the installed package.json says, or pnpm's requiresBuild.
  • Its name is one edit away from a much more popular package in the same ecosystem: a common way to slip a look-alike in.

Known vulnerabilities are Reeve's to report, so they aren't repeated here.

What entered your tools#

  • Editor extensions, new and updated, in VS Code, VS Code Insiders and the editors built on it, with their publisher and whether they came from a .vsix file.
  • Global tools: npm, pip, pipx, uv, cargo and dotnet.
  • Folders added to PATH, the user's and the machine's.
  • Git hooks in each project, and a core.hooksPath.
  • Git's global and system settings that change: hooks, credential helpers, fsmonitor, sslVerify, safe.directory, URL rewrites.

Some git settings are flagged whenever they're there, not only when they change: sslVerify off, credentials stored in plain text, and every folder trusted.

Dev servers open to your network#

Ports listening on every address (0.0.0.0 or ::), not only this PC, whose program is a developer runtime (Node, Python, .NET, Java, Deno, Bun, Ruby, PHP, Docker's proxies, tunnels and the like) or was built inside a project. It names the project when the program's path or command line says, and says how to keep the server to this PC.

It only says what's open. Stray processes are the Pinder's.

Secrets left in the open#

What it recognises: keys by their shape, for cloud providers, code hosts, payment services, AI services, chat apps, package registries and mail services; private key blocks; and a general rule, a secret-sounding name given a random-looking value, which takes care to pass over placeholders, made-up values and test fixtures.

Where it looks (Where it looks for secrets, a setting):

  • Your repositories: tracked and untracked files, and .env files committed to git.
  • PowerShell and bash histories: PowerShell's, bash's and zsh's, and the Node and Python REPLs'.
  • Text and JSON files in Downloads.
  • And ~/.git-credentials.

How far it went, for each one in a repository: pushed, committed, not committed yet, or not tracked.

Its limits#

  • No registry data. When a package was published and who maintains it would take the network, and it doesn't ask.
  • Install scripts are known for npm and pnpm only, not Python's setup.py or Cargo's build.rs.
  • Git history: a secret is looked for in the working tree, HEAD and the upstream branch, not in every commit ever made.
  • Open isn't reachable: it means listening on every address. Your firewall isn't checked.
  • The project an open server came from is told from its program's path or command line, since Windows doesn't show another process's working folder.
  • Big repositories: up to 20,000 files each, files up to 1 MB, and 256 MB read a round. The rest is read on the next round.

Is this page right?

If something on it is wrong or out of date, tell us and we'll fix the page.

Still stuck? Write to support@castellan-software.com and mention article 1702. Every version of Toller, and what changed in it, is in its release notes.