Security tool · js

jsluice

Extracts URLs, paths, and secrets from JavaScript by parsing the AST (not regex) - far more accurate than LinkFinder for modern bundles.

javascriptendpointssecretsast
Stable IDtool:jsluiceLast updatedLast verifiedLegacy review pendingProvenanceSource-linked

Where jsluice fits

Extracts URLs, paths, and secrets from JavaScript by parsing the AST (not regex) - far more accurate than LinkFinder for modern bundles.

Detection-first use

Start with the least intrusive template that can distinguish your hypothesis from a normal response. Preserve raw output and a negative control.

Installation references

Install with goAuthorization required
go install github.com/BishopFox/jsluice/cmd/jsluice@latest
Positive signal
Tool-specific output that supports the stated hypothesis.
Negative control
No result, or identical behavior against a known-safe control.
Intrusiveness
Review flags and target scope before execution.

Command templates

Extract URLsAuthorization required

Populate placeholders only with assets that are explicitly in scope.

cat {input} | jsluice urls
Positive signal
Tool-specific output that supports the stated hypothesis.
Negative control
No result, or identical behavior against a known-safe control.
Intrusiveness
Review flags and target scope before execution.
Extract secretsAuthorization required

Populate placeholders only with assets that are explicitly in scope.

cat {input} | jsluice secrets
Positive signal
Tool-specific output that supports the stated hypothesis.
Negative control
No result, or identical behavior against a known-safe control.
Intrusiveness
Review flags and target scope before execution.

Continue the workflow

Attribution and verification

Version history: normalized permanent page created 2026-08-20. Upstream activity and popularity are separate signals and do not establish tool safety.