Desktop app (Windows)
The dagsec app is the dashboard from app.dagsec.net plus the parts that only work on your own computer:
- Connections: finds Claude Code, Cursor and Gemini CLI and connects them to dagsec in one click, without an API key in any settings file.
- Local scan: scans a repository on this computer. Free on every plan; your code never leaves the machine.
- Commit protection: a pre-commit hook that stops a commit adding a secret to code, offline.
- Notifications: a Windows notification when dagsec stops an install. The app waits in the tray and updates itself.
Windows 10 and 11, 64-bit. macOS is on the way.
Install
- Download dagsec-setup.exe (about 11 MB) and run it. It installs for your user only; no administrator rights needed.
- If Windows SmartScreen says it protected your PC, choose More info, then Run anyway. The app isn't code-signed yet, so Windows doesn't recognise the publisher. Every release is published at github.com/hasanerman/dagsec-desktop.
- Open dagsec and choose Sign in with GitHub. Sign-in finishes in your browser and returns to the app; the session is kept in the Windows credential store.
Connect your AI coding tools
Open Connections. The app lists each tool it finds:
| State | Meaning |
|---|---|
| Not installed | The tool isn't set up for your Windows user |
| Not connected | Installed; Connect adds dagsec |
| Old setup found | A hook with your key in the file, or the Claude Code plugin; Upgrade replaces it |
| Update available | Connected by an older app version; Upgrade adds what's new |
| Connected | Every install the agent runs is checked |
Connect first shows every file it will change and the exact change, then waits for you. When you confirm:
- Each file is backed up beside itself as
<name>.dagsec-backup-<time>before it is written. - Only dagsec's own entries are added or removed; the rest of your settings stay as they are.
- The first connection creates an API key named Desktop app (your computer's name) and keeps it in the Windows credential store. The tools' files point at the app's helper program,
dagsec-hook.exe, which reads the key from there.
What each tool gets:
| Tool | Install check | Package lookups (MCP) | Skill |
|---|---|---|---|
| Claude Code | ~/.claude/settings.json | ~/.claude.json | ~/.claude/skills/dagsec |
| Cursor | ~/.cursor/hooks.json | ~/.cursor/mcp.json | |
| Gemini CLI | ~/.gemini/settings.json | ~/.gemini/settings.json |
Restart the tool after connecting so it reads the new settings. If you had installed the Claude Code plugin, connecting turns it off so installs aren't checked twice.
Doctor
Connections → Doctor → Run checks tests the server, your sign-in, the helper program, this computer's API key and the MCP server, without installing anything or writing to your audit log. If the key was revoked, Create a new key for this computer replaces it; the tools' files don't change.
Local scan
Local scan → Browse…, pick a folder with a .git directory, then Scan. The bar shows the step it's on: reading the git history, scoring dependencies, looking up vulnerabilities, checking whether leaked keys still work.
The result looks like a scan on app.dagsec.net, with the same checks. The difference is where it runs:
| Local scan | Scan on app.dagsec.net | |
|---|---|---|
| Where the code is read | This computer | dagsec server, deleted after the scan |
| Plan | Free on every plan, no quota | Counts against your plan |
| Private repositories | Any repository you have checked out | The ones you grant the GitHub App |
| History | The last 30, on this computer only | In your account |
The scan asks package registries and OSV.dev about your dependencies, and GitHub, Stripe and Slack whether a leaked credential still works, the same as the command line. Nothing is sent to dagsec.
Commit protection
With a repository's folder in the Local scan box, Commit protection → Turn on installs a git pre-commit hook in that repository. Before each commit it scans only what you staged:
- A secret added to code stops the commit, with the file and line.
- A secret in tests, docs or examples is shown and let through, as in a scan.
- If the check itself fails, the commit goes ahead with a warning.
secret config.py:1 AWS access key ID (AKIA********)
dagsec stopped this commit: it adds 1 secret(s) to code.
Move the value to an environment variable or a secrets manager, then stage the file again.
If it is not a real secret, commit once with: git commit --no-verifyIf the repository already has a pre-commit hook, or sets core.hooksPath (husky, the pre-commit framework), the app won't overwrite it. It shows the one line to add to your existing hook instead.
Tray, notifications and updates
- Closing the window keeps dagsec running in the tray, next to the clock. Click the icon to open it again; Quit dagsec in its menu closes it.
- When dagsec stops an install in one of your tools, or your team gets a notification, Windows shows it within about 20 seconds.
- dagsec checks for a new version when it starts and every six hours, and tells you when one is ready. Settings → Updates → Install and restart installs it. Every update is signed, and the app refuses one whose signature doesn't match. Your connections and commit protection stay as they are.
Uninstall
Remove dagsec from Windows Settings → Apps → Installed apps. Uninstalling:
- disconnects Claude Code, Cursor and Gemini CLI (their settings files are backed up first),
- removes the commit protection hooks the app installed,
- forgets the saved sign-in and API key.
The API key itself stays in your account until you revoke it on the API keys page.
Troubleshooting
The installer says it can't write dagsec-hook.exe. An older installer couldn't replace the helper while Claude Code or Cursor was using it. Current installers stop it first; with an old one, run taskkill /F /IM dagsec-hook.exe and choose Retry.
A tool isn't blocking after connecting. Restart the tool, then run the Doctor. Claude Code and Cursor read their settings only at start.
No Windows notifications. Check that notifications are on for dagsec in Windows Settings → System → Notifications, and that Do not disturb is off.