Kekkai
Interactive security triage in the terminal
Details
- External ID
- 46868726
- Source
- HN
- Company
- —
- Product
- —
- Website domain
- —
- Launched
- Feb. 3, 2026
- Cohort
- —
- Upvotes
- 6
- Upvotes percentile
- 0.28099730458221023
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
Hey HN,As an AppSec engineer, I’ve spent a lot of time running and tunning open-source security scanners like Trivy, Semgrep, Gitleaks and Dojo. What I have found is that running them is easy, reviewing the results, not so much. Each tool outputs different JSON, false positives pile up, and CI either becomes noisy or blocks everything.So I built Kekkai (formerly Hokage), a small open-source CLI that wraps these scanners and focuses specifically on human triage.Kekkai runs the scanners in isolated Docker containers, normalizes their outputs into a single format, and provides an interactive terminal UI to review findings, mark false positives, and save decisions locally.You can try it out:``` pipx install kekkai-cli kekkai scan kekkai triage ```What it currently does:- Runs Trivy (dependencies), Semgrep (code), and Gitleaks (secrets) - Normalizes findings into a unified report - Provides a keyboard-driven TUI for reviewing and marking findings - Supports .kekkaiignore for false positives - Has a CI mode with severity-based failure thresholdsDesign choices:- Local-first by default (no SaaS required) - No proprietary scanning logic, it sits on top of existing tools - Scanners run in read-only, no-network Docker containersThis is still early and aimed at individual developers and small teams. The next things I’m working on are persistent triage state across runs (baselines) and better PR-level workflows.Repo and docs: https://github.com/kademoslabs/kekkaiI’m around to answer questions about tradeoffs, limitations, or why this exists at all.
Enrichment
- Theme
- self-hosted infrastructure and security tools
- Vertical
- Security
- Function
- Observability & eval
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Hobby / open-source project
- Normalized one-liner
- security triage tool for terminal
- Manually corrected
- False
Could you build this?
Yes It is a terminal user interface (TUI) that parses JSON outputs from security linters and presents an interactive review workflow.
Discussion
3 comments analyzed.
Concerns raised: Lack of code context requires alt-tabbing to IDE for ambiguous cases, Need for surrounding code and taint trace visibility in TUI
Feature requests: Syntax widget to render surrounding 10 lines of code and taint trace in TUI, Show full code context for ambiguous findings without leaving interface
Competitors
Other products that read as similar to this one — 13 launches clear the similarity bar, closest 8 shown.
Attention rank: #12 of 14 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 84 days after the earliest competitor.
- Kage-DFIR-toolkit · github · 2026-09-10 · 8 upvotes · similarity 0.33
- VaultSandbox · hn · 2026-01-06 · 58 upvotes · similarity 0.33
- Evidence-First Security Kit · ph · 2026-09-15 · 1 upvotes · similarity 0.33
- Tusk Drift · hn · 2026-01-15 · 33 upvotes · similarity 0.31
- Keepr · hn · 2025-11-14 · 17 upvotes · similarity 0.31
- Run GUIs as Scripts · hn · 2026-04-10 · 22 upvotes · similarity 0.31
- Cynative · hn · 2026-07-28 · 16 upvotes · similarity 0.31
- Dev-friendly native OTel: only OSS stateful, on-the-wire Observability · hn · 2026-06-16 · 5 upvotes · similarity 0.31
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a observability & eval tool for Media & entertainment yet.