scan_git_history
Scan Git history to find exposed secrets, including deleted credentials, tagging each finding with the commit hash that introduced it.
Instructions
Scan the lines added by the most recent commits (git log -p).
Each finding is tagged with the short hash of the commit that introduced it. A secret that was later deleted is still reported — history retains it, so the credential must be rotated regardless.
Args: repo_path: Absolute path to a git repository (or any path inside one). max_commits: How many commits back to inspect (default 50). all_branches: Walk every branch, tag and the stash instead of only the history of HEAD (default false). max_findings: List at most this many findings, most severe first (default 200, 0 = no limit). When capped, the result adds truncated, total_findings, counts_by_severity, counts_by_pattern and top_files.
Returns: The standard redacted findings report, with a "commit" field on each finding.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| repo_path | Yes | ||
| max_commits | No | ||
| all_branches | No | ||
| max_findings | No |