Skip to content

Folders and files

NameName
Last commit message
Last commit date

Latest commit

Β 

History

108 Commits
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 
Β 

Repository files navigation

ENVDOCTOR

ENVDOCTOR

.env validator, secret-presence and config-drift checker

PyPI CI License: COCL 1.0 Suite

Developer Tools β€” fast, single-purpose, CI- and agent-friendly.

pip install cognis-envdoctor
envdoctor scan .            # β†’ prioritized findings in seconds

πŸ”Ž Example output

Real, reproducible output from the tool β€” runs offline:

$ envdoctor-emit --version
envdoctor 0.1.0
$ envdoctor-emit --help
usage: envdoctor [-h] [--version] [--format {table,json}]
                 {lint,drift,check} ...

.env validator, secret-presence and config-drift checker.

positional arguments:
  {lint,drift,check}
    lint                lint a .env file for structure + secrets
    drift               detect config drift vs an example file
    check               validate a .env against a JSON schema

options:
  -h, --help            show this help message and exit
  --version             show program's version number and exit
  --format {table,json}
                        output format (default: table)

Blocks above are real envdoctor output β€” reproduce them from a clone.

Sample result format (illustrative values β€” run on your own data for real findings):

{
"findings": [
    {
        "id": "123456",
        "title": "Suspicious Network Traffic",
        "description": "Potential malicious activity detected on port 443",
        "severity": "medium",
        "created_at": "2023-02-15T14:30:00Z"
    },
    {
        "id": "789012",
        "title": "Unusual File Access",
        "description": "User accessed a file with suspicious permissions",
        "severity": "high",
        "created_at": "2023-02-16T10:45:00Z"
    }
]
}

Usage β€” step by step

  1. Install the CLI:

    pipx install "git+https://github.com/cognis-digital/envdoctor.git"
  2. Lint a .env file for structural problems and exposed secrets β€” the primary command:

    envdoctor lint .env
  3. Detect drift between your .env and the committed example, and validate against a JSON schema:

    envdoctor drift --example .env.example --env .env
    envdoctor check --schema env.schema.json --env .env
  4. Read the output β€” table by default, or JSON for pipelines:

    envdoctor --format json lint .env > env-report.json
  5. Automate in CI β€” block a deploy when config drifts from the example or fails the schema:

    envdoctor drift --example .env.example --env .env
    envdoctor check --schema env.schema.json --env .env
    # non-zero exit => config problem => job fails

Contents

Why envdoctor?

single-binary DX, viral

envdoctor is single-purpose, scriptable, and self-hostable: point it at a target, get prioritized results in the format your workflow already speaks (table Β· JSON Β· SARIF), gate CI on it, and let agents drive it over MCP.

Features

  • βœ… Parse Env
  • βœ… Looks Like Secret
  • βœ… Lint File
  • βœ… Diff Env
  • βœ… Check Schema
  • βœ… Runs on Linux/macOS/Windows Β· Docker Β· devcontainer
  • βœ… Ports in Python, JavaScript, Go, and Rust (ports/)

Quick start

pip install cognis-envdoctor
envdoctor --version
envdoctor scan .                       # scan current project
envdoctor scan . --format json         # machine-readable
envdoctor scan . --fail-on high        # CI gate (non-zero exit)

Example

$ envdoctor scan .
  [HIGH    ] ENV-001  example finding             (./src/app.py)
  [MEDIUM  ] ENV-002  another signal              (./config.yaml)

  2 findings Β· risk score 5 Β· 38ms

Architecture

flowchart LR
  IN[input] --> P[envdoctor<br/>analyze + score]
  P --> OUT[report]
Loading

Use it from any AI stack

envdoctor is interoperable with every popular way of using AI:

  • MCP server β€” envdoctor mcp (Claude Desktop, Cursor, Cognis.Studio, uncensored-fleet)
  • OpenAI-compatible / JSON β€” pipe envdoctor scan . --format json into any agent or LLM
  • LangChain Β· CrewAI Β· AutoGen Β· LlamaIndex β€” wrap the CLI/JSON as a tool in one line
  • CI / scripts β€” exit codes + SARIF for non-AI pipelines

How it compares

Cognis envdoctor dotenv-linter
Self-hostable, no account βœ… varies
Single command, zero config βœ… ⚠️
JSON + SARIF for CI βœ… varies
MCP-native (AI agents) βœ… ❌
Polyglot ports (JS/Go/Rust) βœ… ❌
Open license βœ… COCL varies

Built in the spirit of dotenv-linter, re-framed the Cognis way. Missing a credit? Open a PR.

Integrations

Pipes into your stack: SARIF for code-scanning, JSON for anything, an MCP server (envdoctor mcp) for AI agents, and a webhook forwarder for SIEM/Slack/Jira. See docs/INTEGRATIONS.md.

Install β€” every way, every platform

pip install "git+https://github.com/cognis-digital/envdoctor.git"    # pip (works today)
pipx install "git+https://github.com/cognis-digital/envdoctor.git"   # isolated CLI
uv tool install "git+https://github.com/cognis-digital/envdoctor.git" # uv
pip install cognis-envdoctor                                          # PyPI (when published)
docker run --rm ghcr.io/cognis-digital/envdoctor:latest --help        # Docker
brew install cognis-digital/tap/envdoctor                             # Homebrew tap
curl -fsSL https://raw.githubusercontent.com/cognis-digital/envdoctor/main/install.sh | sh
Linux macOS Windows Docker Cloud
scripts/setup-linux.sh scripts/setup-macos.sh scripts/setup-windows.ps1 docker run ghcr.io/cognis-digital/envdoctor DEPLOY.md (AWS/Azure/GCP/k8s)

Related Cognis tools

  • mcpforge β€” Scaffold, test, and publish MCP servers in minutes
  • promptlint β€” Lint, version, and test prompts as code with a CI gate
  • apidiff β€” Breaking-change detector for OpenAPI / GraphQL across commits
  • codeglance β€” Repo onboarding map β€” architecture + hotspots for humans and agents
  • flakefinder β€” Flaky-test detector from CI history with quarantine suggestions
  • licenselens β€” Dependency license + SBOM gate, developer-CLI first

Explore the suite β†’ πŸ—‚οΈ all 170+ tools Β· ⭐ awesome-cognis Β· πŸ”— cognis-sources Β· πŸ€– uncensored-fleet Β· 🧠 engram

Contributing

PRs, new rules, and demo scenarios are welcome under the collaboration-pull model β€” see CONTRIBUTING.md and SECURITY.md.

⭐ If envdoctor saved you time, star it β€” it genuinely helps others find it.

Interoperability

{} composes with the 300+ tool Cognis suite β€” JSON in/out and a shared OpenAI-compatible /v1 backbone. See INTEROP.md for the suite map, composition patterns, and reference stacks.

License

Source-available under the Cognis Open Collaboration License (COCL) v1.0 β€” free for personal, internal-evaluation, research, and educational use; commercial / production use requires a license (licensing@cognis.digital). See LICENSE.


Cognis Digital Β· one of 170+ tools in the Cognis Neural Suite Β· Making Tomorrow Better Today