Stop git add -A from leaking your .env

KatchPath is a tiny git guard. It refuses blanket adds from the wrong folder and blocks .env files, private keys, key-shaped strings and node_modules before they're staged or committed. Free, MIT, one POSIX shell file, no dependencies.

curl -fsSL https://katchpath.com/install.sh | sh
cd your-repo && katchpath install
echo 'eval "$(katchpath shell)"' >> ~/.zshrc   # guards git add

Read the installer   View the source

What it catches

$ git add -A
katchpath: blocked, 3 problem(s):
  secret-file  .env
  build-dir    node_modules/lodash/index.js
  key-in-file  src/config.py

  fix:    git restore --staged <file>   and add it to .gitignore
  allow:  add a glob to .katchpathignore if you really mean it
  once:   KATCHPATH_SKIP=1 <your git command>

Wrong-folder adds

git add . from a subfolder or from $HOME is refused before anything is staged. That's how whole home directories end up on GitHub.

Secret-shaped files

.env* (not .env.example), *.pem, *.key, id_rsa, credentials.json, service-account JSON, .npmrc, .netrc, terraform.tfstate, *.tfvars.

Key-shaped content

AWS, GitHub, GitLab, Slack, Stripe, Google, OpenAI, Anthropic, npm and SendGrid key formats, plus private key blocks, inside staged files.

Build folders + big files

node_modules, .venv, __pycache__, .next, .terraform, Rust target, and anything over 5 MB.

Two layers: a shell wrapper checks git add -A/./--all/-u with a dry run first, and a pre-commit hook re-checks whatever is staged. Existing hooks keep running, chained after it. Config is an optional .katchpath file in the repo root; mode=warn if you want a soft start.

Team Pack, $19 one-time

$19 one-time, per organisation

The hook only protects laptops that have it. The Team Pack covers the rest:

Get the Team Pack, $19

Instant download after checkout. 14-day money-back guarantee, no questions. Secure checkout by Stripe.

Honest limits

Any hook can be skipped on purpose (--no-verify). Pattern checks catch common key formats, not every secret. If a key was already pushed, rotate it first: see I committed my .env to GitHub.