Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Kekkai

Interactive security triage in the terminal

Details

External ID
46868726
Source
HN
Company
—
Product
—
Website domain
—
Launched
Feb. 3, 2026
Cohort
—
Upvotes
6
Upvotes percentile
0.28099730458221023
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

Hey HN,As an AppSec engineer, I’ve spent a lot of time running and tunning open-source security scanners like Trivy, Semgrep, Gitleaks and Dojo. What I have found is that running them is easy, reviewing the results, not so much. Each tool outputs different JSON, false positives pile up, and CI either becomes noisy or blocks everything.So I built Kekkai (formerly Hokage), a small open-source CLI that wraps these scanners and focuses specifically on human triage.Kekkai runs the scanners in isolated Docker containers, normalizes their outputs into a single format, and provides an interactive terminal UI to review findings, mark false positives, and save decisions locally.You can try it out:``` pipx install kekkai-cli kekkai scan kekkai triage ```What it currently does:- Runs Trivy (dependencies), Semgrep (code), and Gitleaks (secrets) - Normalizes findings into a unified report - Provides a keyboard-driven TUI for reviewing and marking findings - Supports .kekkaiignore for false positives - Has a CI mode with severity-based failure thresholdsDesign choices:- Local-first by default (no SaaS required) - No proprietary scanning logic, it sits on top of existing tools - Scanners run in read-only, no-network Docker containersThis is still early and aimed at individual developers and small teams. The next things I’m working on are persistent triage state across runs (baselines) and better PR-level workflows.Repo and docs: https://github.com/kademoslabs/kekkaiI’m around to answer questions about tradeoffs, limitations, or why this exists at all.

Enrichment

Theme
self-hosted infrastructure and security tools
Vertical
Security
Function
Observability & eval
Audience
Developer
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
security triage tool for terminal
Manually corrected
False

Could you build this?

Yes It is a terminal user interface (TUI) that parses JSON outputs from security linters and presents an interactive review workflow.

Discussion

3 comments analyzed.

Concerns raised: Lack of code context requires alt-tabbing to IDE for ambiguous cases, Need for surrounding code and taint trace visibility in TUI

Feature requests: Syntax widget to render surrounding 10 lines of code and taint trace in TUI, Show full code context for ambiguous findings without leaving interface

Competitors

Other products that read as similar to this one — 13 launches clear the similarity bar, closest 8 shown.

Attention rank: #12 of 14 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 84 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a observability & eval tool for Media & entertainment yet.