sast_hardcoded_secrets
Scan source code files for hardcoded secrets such as AWS keys, GitHub tokens, and private keys using over 20 regex patterns to identify exposed credentials.
Instructions
Scan all string literals and template literals for hardcoded secrets using 20+ regex patterns: AWS keys, GitHub tokens, Slack tokens, Stripe keys, private keys, JWTs, database URLs, and more.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| path | Yes | Directory path containing source files to analyze |