> ## Documentation Index
> Fetch the complete documentation index at: https://envtrap.vercel.app/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Introduction

> Zero-configuration runtime secret leak detector and egress firewall for Node.js 18+.

<img className="block" src="https://mintcdn.com/envtrap-fffa9110/2ZAodveVaED35qeD/logo.png?fit=max&auto=format&n=2ZAodveVaED35qeD&q=85&s=bd901e36dda9233c6b8b5a63afe00ed9" alt="envtrap logo" style={{ width: "140px", marginBottom: "2rem" }} width="272" height="270" data-path="logo.png" />

# What is envtrap?

**envtrap** is a runtime security engine and egress firewall for **Node.js** applications. It wraps your process and intercepts every outbound egress channel in real time — before secrets, tokens, database credentials, or sensitive environment variables can be exfiltrated by malicious code, compromised npm dependencies, or insider threats.

Unlike static analysis tools (SAST) that scan source code at build time, envtrap operates **at execution time** inside the live Node.js runtime — inspecting actual outbound traffic, child processes, DNS queries, and terminal output streams as they happen.

***

## Why Runtime Egress Protection?

Modern Node.js applications rely on hundreds of deeply nested transitive npm dependencies. While developers audit their direct dependencies, malicious packages, typosquats, and compromised updates regularly introduce exfiltration vectors:

* **Supply Chain Attacks**: A compromised package reads `process.env` and sends keys to an external command-and-control server.
* **Silent Telemetry Leaks**: Third-party developer tools, logging agents, or analytics SDKs accidentally include sensitive headers or credentials in outbound telemetry payloads.
* **DNS Tunneling**: Sophisticated malware exfiltrates stolen keys encoded directly inside hostname resolution queries (e.g. `sk_live_xyz.attacker.com`).
* **Subprocess Leaks**: A utility script or build tool invokes a system shell command with `process.env` passed to untrusted subprocesses.
* **Accidental Console Dumps**: Crash handlers and debug statements print raw environment objects to central logging aggregators.

### How envtrap Compares

| Security Layer | What It Does | Why It Leaves You Vulnerable |
| :- | :- | :- |
| **SAST / Linters** | Scans source code for static patterns | Blind to dynamic credentials, runtime variables, and third-party dependency behavior |
| **Git Secrets Scanners** | Catches committed secrets in git history | Blind to secrets provided at runtime via vaults, `.env`, or container environments |
| **WAF / Ingress Firewalls** | Filters inbound HTTP requests | Only guards incoming traffic; completely ignores outbound egress leaving the process |
| **EDR / Antivirus** | Detects known binary malware signatures | Cannot distinguish legitimate application traffic from an npm package leaking an API key |
| **envtrap** | **Monitors live process egress channels in real time** | **Intercepts and blocks outbound secret exfiltration before bytes leave your machine** |

***

## The 5 Monitored Channels

envtrap guards every exit point through five distinct runtime channels:

<CardGroup cols={2}>
  <Card title="HTTPS / HTTP Network Proxy" icon="shield-halved">
    Intercepts outbound HTTP/HTTPS requests through an in-memory TLS MITM proxy. Inspects URLs, headers, and request bodies before packets reach the external network.
  </Card>

  <Card title="DNS Resolution Auditing" icon="globe">
    Hooks core `node:dns` methods to detect secrets embedded inside target hostnames and analyzes Shannon entropy to catch DNS tunneling exfiltration.
  </Card>

  <Card title="Subprocess Isolation" icon="terminal">
    Monitors `spawn`, `exec`, `execFile`, and `fork` across both ESM and CommonJS, preventing credentials from leaking into unvetted child processes via `options.env`.
  </Card>

  <Card title="Standard Output Scanning" icon="desktop">
    Scans every chunk written to `process.stdout` in real time, automatically replacing secret strings with non-reversible SHA-256 fingerprint placeholders.
  </Card>

  <Card title="Standard Error & IPC Parsing" icon="triangle-exclamation">
    Inspects `process.stderr` error output, redacting credentials from crash dumps and parsing out-of-band IPC alerts from runtime hooks.
  </Card>

  <Card title="Live Secret Synchronization" icon="arrows-rotate">
    Proxies `process.env` in the application thread so dynamically-rotated credentials are immediately broadcasted to the ESM loader thread without a restart.
  </Card>
</CardGroup>

***

## Zero Instrumentation

envtrap requires **no code changes**, **no SDK imports**, and **no configuration**:

<Tabs>
  <Tab title="Before">
    ```bash theme={null}
    node app.js
    ```

    Your process runs unprotected. Any package in your dependency tree has unrestricted read access to `process.env` and can transmit your credentials to any remote server.
  </Tab>

  <Tab title="After">
    ```bash theme={null}
    envtrap run node app.js
    ```

    Your application runs inside envtrap's runtime guard. Network requests, DNS lookups, subprocess spawns, and stdout/stderr streams are intercepted and enforced against your policy.
  </Tab>
</Tabs>

<Tip>
  envtrap automatically sets `NO_PROXY` for local loopback addresses (`127.0.0.1`, `localhost`, `::1`). Local Redis, Docker containers, databases, and sidecars will never experience proxy overhead.
</Tip>

***

## Next Steps

<CardGroup cols={2}>
  <Card title="Quickstart" icon="bolt" href="/docs/quickstart">
    Get envtrap running with your Node.js application in under 60 seconds.
  </Card>

  <Card title="Runtime Interception" icon="microchip" href="/docs/how-it-works/runtime-interception">
    Learn how in-memory MITM TLS proxies, ESM loader hooks, and CJS patching work under the hood.
  </Card>

  <Card title="Secret Detection & Entropy" icon="fingerprint" href="/docs/how-it-works/secret-detection">
    Understand deterministic regex matching, Shannon entropy calculation, and memory safety limits.
  </Card>

  <Card title="Configuration Guide" icon="sliders" href="/docs/configuration/envtrap-json">
    Explore `envtrap.json` settings, custom channel modes, domain whitelisting, and path exclusions.
  </Card>
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.