Automic VaultAutomic Vault

brew

Install scrutineer with Homebrew

Security through scrutiny. Version 2026.07.14.1 via Homebrew; verified 2026-07-14.

install

Additional install commands

macOS

Homebrewverified ยท 100%
brew install scrutineer

local Homebrew formula metadata

overview

Package summary

Security through scrutiny

Commands and aliases

  • scrutineer

history

Project history and usage

Scrutineer is a local application-security workbench that scans open-source repositories with configurable agent skills, containerized language profiles, conventional analysis tools, and human-gated vulnerability-disclosure workflows. It combines a CLI-launched service with a local web interface for triage, verification, reporting, and release tracking.

Project history

Alpha-Omega introduced the public Scrutineer repository in April 2026 to make repeatable, evidence-focused open-source security review practical without overwhelming maintainers with untriaged reports. The project was packaged as a Go executable with embedded skills and runner profiles, and its first public GitHub release was v2026.07.14.1 in July 2026.

Adoption history

Scrutineer is an early-stage project. Its distribution includes precompiled Linux and macOS archives, source builds, container images, and a Homebrew formula; the official README also supports Docker, rootless Podman, and Apple's container runtime for isolated scans.

How it is used

An operator starts Scrutineer, opens its local web UI, and adds a repository URL, organization, SBOM, external finding report, or local source directory. A triage skill fans out into metadata, dependency, advisory, static-analysis, threat-modeling, and model-backed audit tasks, after which the operator verifies findings and controls disclosure through explicit workflow gates.

Why package nerds care

Scrutineer treats package metadata as security context: it discovers manifests, builds SBOMs, looks up registry versions and dependents, checks advisories, and can import dependencies for deeper scans. Its per-ecosystem runner profiles cover common package managers and native-extension cases, making it especially relevant to maintainers interested in the boundary between package graphs, reproducible tooling, and vulnerability disclosure.

Timeline

  • 2026-04: Public repository development began.
  • 2026-07: First public GitHub release, v2026.07.14.1.

Related projects

  • Semgrep, zizmor, git-pkgs, and brief are integrated as conventional analysis and repository-inspection tools.
  • Claude Code, Codex, and opencode are supported as pluggable agent backends.
  • Docker, Podman, and Apple's container CLI provide the supported isolated runner environments.

security posture

No protected-tool coverage found yet

No matching local secret-handling manifest was found for scrutineer. Nucleus package metadata is still published here so future coverage has a stable package URL.

Install behavior

  • No Homebrew post-install hook is recorded in formula metadata.
  • Homebrew bottle metadata is available for 6 platform targets.
  • Build metadata lists 1 build dependencies.

Recommended review

Before unattended agent use, check whether the tool reads plaintext credentials, writes remote state, publishes artifacts, or shells out to plugins.

local files

Configuration and credential file locations

These source-backed paths show where this package keeps local settings or durable credentials. Automic Vault can use them as review targets for secret scanning, migration, and command approval.

Configuration files

Config paths the tool may read or write during local use.

Unix
./scrutineer.yaml

executables

Installed executables

CommandKindExposureNote
scrutineercliglobal executable

freshness

Version and freshness

These signals separate page generation age, package-manager activity, and upstream release comparison. Version lag is warned only when an evidence URL and comparable versions are present.

page generated2026-07-25
manager version2026.07.14.1
manager updated2026-07-14
local dataok
upstreamnot checked
latest detectednot detected

https://github.com/alpha-omega-security/scrutineer

install metadata

Package metadata

Package keybrew:scrutineer
Version2026.07.14.1
Package managerHomebrew
Package manager pagehttps://formulae.brew.sh/formula/scrutineer
Homepagehttps://github.com/alpha-omega-security/scrutineer
Repositoryhttps://github.com/alpha-omega-security/scrutineer
Upstream docshttps://github.com/alpha-omega-security/scrutineer
LicenseMIT
Source archivehttps://github.com/alpha-omega-security/scrutineer/archive/refs/tags/v2026.07.14.1.tar.gz
Last updated2026-07-14T21:44:50Z
Pulseupdated
Build dependenciesgo
Bottleavailable (on arm64_linux, arm64_sequoia, arm64_sonoma, arm64_tahoe, sonoma, x86_64_linux)
Homebrew post-installnot defined
Servicenone declared

registry facts

Source database details

Source DatabaseHomebrew formula API
Taphomebrew/core
Full Namescrutineer
Version Scheme0
Revision0
Head VersionHEAD
Bottle Stable Root URLhttps://ghcr.io/v2/homebrew/core
Deprecatedno
Disabledno
Keg Onlyno
URL Keys
  • head
  • stable

source trail

Generated from repository data

This page is generated by av-web from the private package SQLite artifact built by scripts/generate-pkg-sqlite.py.

Used sources

  • Nucleus package database
  • av.db category and tag curation
  • cross-ecosystem install command graph
  • curated configuration and credential file locations
  • curated package history
  • package relationship graph
  • package version freshness
  • package-page enrichment