scan_git_staged
Detect exposed secrets in the lines staged for your next git commit, reporting file and line details so leaks are caught before publishing.
Instructions
Scan ONLY the lines currently staged for commit (git diff --cached).
This is the pre-commit checkpoint: it inspects exactly the content the next commit would publish, and reports the file and post-commit line number of every added secret. Local diff settings (external diff tools, textconv filters, prefixes, path quoting) are overridden, and git runs no configured programs.
Args: repo_path: Absolute path to a git repository (or any path inside one). max_findings: List at most this many findings, most severe first (default 200, 0 = no limit). When capped, the result adds truncated, total_findings, counts_by_severity, counts_by_pattern and top_files.
Returns: The standard redacted findings report. If nothing is staged the result is clean with an explanatory summary.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| repo_path | Yes | ||
| max_findings | No |