Stop git add -A from leaking your .env
KatchPath is a tiny git guard. It refuses blanket adds from the wrong folder and blocks .env files, private keys, key-shaped strings and node_modules before they're staged or committed. Free, MIT, one POSIX shell file, no dependencies.
curl -fsSL https://katchpath.com/install.sh | sh
cd your-repo && katchpath install
echo 'eval "$(katchpath shell)"' >> ~/.zshrc # guards git add
Read the installer View the source
What it catches
$ git add -A
katchpath: blocked, 3 problem(s):
secret-file .env
build-dir node_modules/lodash/index.js
key-in-file src/config.py
fix: git restore --staged <file> and add it to .gitignore
allow: add a glob to .katchpathignore if you really mean it
once: KATCHPATH_SKIP=1 <your git command>
Wrong-folder adds
git add . from a subfolder or from $HOME is refused before anything is staged. That's how whole home directories end up on GitHub.
Secret-shaped files
.env* (not .env.example), *.pem, *.key, id_rsa, credentials.json, service-account JSON, .npmrc, .netrc, terraform.tfstate, *.tfvars.
Key-shaped content
AWS, GitHub, GitLab, Slack, Stripe, Google, OpenAI, Anthropic, npm and SendGrid key formats, plus private key blocks, inside staged files.
Build folders + big files
node_modules, .venv, __pycache__, .next, .terraform, Rust target, and anything over 5 MB.
Two layers: a shell wrapper checks git add -A/./--all/-u with a dry run first, and a pre-commit hook re-checks whatever is staged. Existing hooks keep running, chained after it. Config is an optional .katchpath file in the repo root; mode=warn if you want a soft start.
Team Pack, $19 one-time
$19 one-time, per organisation
The hook only protects laptops that have it. The Team Pack covers the rest:
- GitHub Action (composite, no Docker, no network calls) that fails any PR or push adding secret files, keys or build folders, with inline annotations. Catches
--no-verifyand web edits. - Org-wide rollout: a ready workflow file per repo (or one org ruleset on GitHub Enterprise Cloud), plus a one-command developer installer that keeps existing hooks.
- Policy files: baseline
.katchpath, allowlist, and a.gitignoreblock for secrets and build output. - Setup guide + paste-ready onboarding message + pre-commit framework config. Free updates.
Instant download after checkout. 14-day money-back guarantee, no questions. Secure checkout by Stripe.
Honest limits
Any hook can be skipped on purpose (--no-verify). Pattern checks catch common key formats, not every secret. If a key was already pushed, rotate it first: see I committed my .env to GitHub.