scan_file
Scan a single file for exposed API keys, tokens, private keys, or high-entropy strings and return redacted findings; skip binary or files over 5 MB.
Instructions
Scan a single file for exposed secrets.
UTF-8, UTF-16 and UTF-32 text is decoded by byte-order mark. Binary files (null-byte heuristic) and files larger than 5 MB are skipped and reported as such in the summary.
Args: path: Absolute path to the file to scan. max_findings: List at most this many findings, most severe first (default 200, 0 = no limit). When capped, the result adds truncated, total_findings, counts_by_severity, counts_by_pattern and top_files.
Returns: The standard redacted findings report (see scan_text). Returns an error result if the file does not exist.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| path | Yes | ||
| max_findings | No |