Source Secret Scanner
Find high-confidence credential patterns in pasted source and selected local text files without uploading or validating them.
Handle findings as sensitive: results can contain false positives and scanners can miss secrets. Never test a suspected credential. If exposure is plausible, follow your incident process: restrict access, revoke/rotate through the provider, inspect authorized logs, remove it from history and artifacts, and avoid copying it into tickets or chat. Scanning makes no network requests and uses no persistence or logging.
Limits: pasted text 2 MiB; up to 20 files, 1 MiB each and 5 MiB total; 5,000 candidates across all sources. Files are read locally. Binary-looking and invalid UTF-8 files are rejected.
sha256: compares the exact match digest. glob: supports literal text plus */? (20 entries, matches up to 500 characters). Other lines are exact values. Keep allowlists narrow; they can hide real findings.
Shannon entropy is calculated over the literal ASCII token characters, not decoded bytes. Hashes, IDs, and generated text can trigger it.
Findings
| Severity | Confidence | Rule | Location | Masked evidence | Context |
|---|