scan_directory
Recursively scans a directory tree for exposed secrets, skipping common non-source files. Returns redacted findings with relative paths.
Instructions
Recursively scan a directory tree for exposed secrets.
Automatically skips .git, node_modules, virtualenvs and conda envs under any name, site-packages, tool caches (.tox, .nox, .mypy_cache, .pytest_cache, .ruff_cache), pycache, dist, build, minified JS bundles, lockfiles, binaries, files over 5 MB, and simple patterns from the root .gitignore (best-effort: no negations, no ** globs).
Args: path: Absolute path to the directory to scan. max_files: Stop after scanning this many files (default 500). max_findings: List at most this many findings, most severe first (default 200, 0 = no limit). When capped, the result adds truncated, total_findings, counts_by_severity, counts_by_pattern and top_files.
Returns: The standard redacted findings report; finding paths are relative to the scanned root, using forward slashes.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| path | Yes | ||
| max_files | No | ||
| max_findings | No |