scan_text
Scan text or code for exposed secrets such as API keys, tokens, and private keys, returning redacted findings so leaks are caught before committing.
Instructions
Scan a snippet of text or code for exposed secrets.
33 detectors: GitHub/GitLab/npm/PyPI tokens, OpenAI (incl. sk-proj-), Anthropic, OpenRouter, Groq, NVIDIA and Hugging Face keys, AWS, Azure, Google, DigitalOcean, Stripe, Shopify, SendGrid, Twilio, Slack, Discord and Telegram credentials, JWTs, private and age keys, credentialed connection strings and URLs, generic password/secret/token assignments, plus high-entropy strings. Placeholders ($VAR, ${VAR}, {{ templates }}, %(name)s, changeme, masked values...) are skipped, and a line carrying "secret-sentinel: ignore" or "pragma: allowlist secret" is counted in "suppressed" instead of reported.
Args: text: The raw text to scan (code, config, diff output, logs...). source_name: Label used in each finding's "file" field. max_findings: List at most this many findings, most severe first (default 200, 0 = no limit). When capped, the result adds truncated, total_findings, counts_by_severity, counts_by_pattern and top_files.
Returns: {"clean": bool, "findings": [{"file", "line", "pattern", "severity", "redacted", "advice"}], "files_scanned": int, "summary": str} Secret values are ALWAYS redacted (at most 4 chars, never more than a quarter of the value, + length); the full value is never included.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| text | Yes | ||
| source_name | No | input | |
| max_findings | No |