
Image: ranwhat preview image from ranwhat.com
Coding agents now have your shell, your keys and your repo. They run hundreds of commands in a session and most people never look back at what was run. ranwhat does that for you. It reads the history your agents already write to disk and reports what they actually did.
What it catches
- Credential reads, so you know when an agent opened a file with keys in it.
- Destructive commands like rm -rf and force pushes.
- Package publishing and files piped to curl.
- Secrets left in transcripts, with a list of what to rotate. It can mask them when you ask.
Works with the agents you use
It reads the history from Claude Code, Codex, Gemini CLI and GitHub Copilot CLI, and supports more agents beyond those.
Private by design
- Everything runs on your machine.
- No account, no telemetry, no dependencies.
- MIT licensed, so you can read the code.
For a tool that reads your most sensitive logs, this is the right way round. Nothing leaves your laptop.
Try it in one line
If you have uv installed, run: uvx ranwhat check . You can also run a watch over the last 90 days to see a longer picture.
Who ranwhat is for
Developers and small teams who let agents run commands on real machines and want a quick audit. Also anyone who has pasted a key into a chat and wondered where it ended up. It is free and open source. It does not stop an agent from doing things, it shows you what already happened.
Links
- Visit ranwhat: ranwhat.com
- ranwhat on PyPI: pypi.org/project/ranwhat
- Source on GitHub: MatijaMiki/ranwhat
- ranwhat on Maidensail.com: maidensail.com/startup/ranwhat

