Security

rf is a local search tool. It reads files under the path you give it and prints results to stdout. It makes no network calls of its own.

What it reads

  • File contents and names under the search path, including — by design — gitignored, hidden, and binary files. Recovering matches those filters hide is the whole point, so treat rf output like any grep output: it may surface data from files you would not normally search.
  • git history, but only in the find verb’s git_deleted stage. This stage exists to find secrets that were committed and later scrubbed from the tree. It reads history through git; it never writes to the repository.

What it runs

The content verb and the fd/binary stages of find are fully in-process — no subprocess. Two find stages shell out to external tools:

  • git for git_deleted
  • ast-grep for ast_structural

rf invokes these directly (no shell string interpolation) and treats a missing tool as a warning, not a failure. If your threat model forbids running external binaries, use content and the in-process find stages, and omit --structural.

Secrets in output

Because rf deliberately surfaces gitignored, hidden, and history-only matches, its output can contain secrets that a naive search would have hidden. Do not paste rf output into logs, issues, or chat without review. The git_deleted stage in particular is designed to print things that were removed from the tree on purpose.

Reporting an issue

Report security issues through the source repository. rf is in early development; please pin a version for anything sensitive.