The zero-trust, local-only codebase packager for developers and AI workflows.
Xipper takes a project folder, automatically detects its technology stack, applies smart exclusions for dependencies and caches, actively screens for hardcoded secrets, and produces a clean .zip archive or LLM-friendly text digest in one action.
- 100% Local-Only / Zero Data Egress: All directory walking, secret scanning, and compression run strictly on your local machine. No cloud telemetry, no analytics, no phone-home.
- Smart Stack Detection: Automatically recognizes Node.js/TypeScript, Python, Go, Rust, Java/Kotlin, .NET, Ruby, PHP, and monorepo configurations.
- Deterministic 6-Layer Exclusion:
- Universal defaults (
.git,.DS_Store,*.log,tmp/,.cache) - Detected stack defaults (
node_modules,venv,target,build,bin/obj, etc.) - Root
.gitignoreparsing - Nested
.gitignorescoping across monorepo packages - Sensitive filename screening (
.env*,*.pem,id_rsa,credentials.json) - Reusable user exclusion profiles
- Universal defaults (
- Two-Layer Content Secret Scanner: Inspects non-binary text files for AWS keys, GCP service accounts, Azure connection strings, GitHub tokens, Stripe/OpenAI keys, private key headers, JWTs, and high Shannon entropy literals.
- LLM Text Digest Mode: Generates structured Markdown containing an ASCII directory tree and syntax-highlighted code blocks formatted for Claude, Gemini, or ChatGPT context windows.
- Streaming & High Performance: Non-blocking asynchronous directory walker and streaming
archiverpipeline capable of handling 50,000+ files with live progress tracking and cancel rollback.
xipper/
├── packages/
│ └── engine-core/ # Pure, framework-agnostic TypeScript core engine
│ ├── src/
│ │ ├── detect.ts # Stack marker detection
│ │ ├── exclude.ts # 6-layer exclusion & gitignore engine
│ │ ├── secrets.ts # Secret regex & Shannon entropy heuristics
│ │ ├── walk.ts # Async walker, symlinks & edge cases
│ │ ├── zip.ts # Streaming archiver & cancellation
│ │ ├── digest.ts # Markdown text digest generator
│ │ └── logger.ts # Local rotating diagnostic logger
│ └── tests/ # Comprehensive Vitest test suites
├── apps/
│ ├── desktop/ # Electron + React 18 + TypeScript + Tailwind desktop app
│ │ ├── src/main/ # Electron main process & IPC handlers
│ │ ├── src/preload/ # Strictly isolated contextBridge API
│ │ └── src/renderer/ # React control panel UI & design system
│ └── web/ # Next.js static landing page & docs
└── .github/workflows/ # CI/CD multi-platform packaging
contextIsolation: truenodeIntegration: falsesandbox: true- Privileged filesystem operations exist exclusively in the main process, exposed to the renderer through a narrow, strongly-typed
contextBridgeAPI (window.xipper.*). - Matched secret candidate strings are never rendered or logged — only the file path, line number, and rule category are reported.
- Node.js >= 20.0.0
- pnpm >= 9.0.0
# Clone the repository
git clone https://github.com/Kesavaraja67/xipper.git
cd xipper
# Install workspace dependencies
pnpm install
# Run core engine tests
pnpm testpnpm dev:desktoppnpm dev:webpnpm build# Build desktop installer for current OS
pnpm package:desktop| Scenario | Handled Behavior |
|---|---|
No .gitignore present |
Degrades gracefully to universal and stack defaults; never requires git. |
| Unknown project type | Falls back to universal default exclusion list (.git, *.log, .tmp, etc.). |
Nested .gitignore files |
Scoped accurately to subdirectories per gitignore specifications. |
| Symlinks | Detected and excluded by default; prevents recursive loops and escaping project root. |
| Inaccessible files | Non-blocking warning recorded; walker continues smoothly without crashing. |
| Windows MAX_PATH (>240 chars) | Handled with \\?\ prefix normalization on Windows. |
| Cancellation mid-export | Immediately aborts archiver stream and removes partial .zip from disk. |
| Disk full / write errors | Catches ENOSPC, removes partial file, and surfaces clear diagnostic warning. |
MIT © 2026 Xipper Contributors.