Ross ROSS = Recommend OSS · open-source software intelligence for agents

edoardottt/cariddi

Take a list of domains, crawl urls and scan for endpoints, secrets, api keys, file extensions, tokens and more observed · 2026-08-28

github.com/edoardottt/cariddi · homepage · Go · GPL-3.0 (copyleft) observed · 2026-08-28

Health v2 · maintenance only

84/100

  • Activity 92
  • Release rhythm 65
  • Longevity 100
How is this computed?

round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.

  • gap_med: 59
  • age_days: 1954
  • days_rel: 157
  • days_push: 49
  • n_releases_24m: 8

Full methodology

Adoption not part of the score

3753 stars · 345 forks observed · 2026-08-28

What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded

Cariddi is a fast command-line web crawler written in Go that takes a list of domains, crawls URLs, and scans for endpoints, secrets, API keys, tokens, and interesting file extensions. It is designed for reconnaissance in bug bounty hunting and penetration testing workflows.

Use cases

  • crawl a list of domains and discover hidden endpoints
  • scan websites for leaked api keys and secrets
  • recon tool for bug bounty reconnaissance
  • find interesting file extensions and tokens on a target site
  • automate endpoint discovery during pentesting
  • scrape urls from domains for osint research

When to choose

  • you need a fast, single-binary CLI crawler for recon in bug bounty or red team work
  • you want automated detection of secrets, api keys, and sensitive endpoints while crawling
  • you prefer a Go-based tool that integrates into piped CLI workflows

When to avoid

  • you need a full web vulnerability scanner with exploit capabilities rather than discovery
  • you require a GUI or browser-based crawling experience
  • you need authenticated, JavaScript-rendered crawling of complex single-page applications

Facets

cli-tool · maturity active

web-scraping security vulnerability-scanning osint parser security osint crawlers penetration-testing developer-tools windows cli go cross-platform bug-bounty recon endpoint-discovery secrets-detection crawler red-team infosec linux macos

2 sources

Member repositories

RepositoryRoleHealth v2
edoardottt/cariddimain84

For agents

markdown · JSON · MCP: product_card(name="edoardottt/cariddi")

Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem