scan_secrets
Recursively scans decompiled APK or decoded output directories for hardcoded AWS, Google, Slack, GitHub, Stripe, JWT, and private-key secrets, returning file, line, and type matches.
Instructions
Recursively scan a directory (typically decompile_apk or decode_apk output) for likely hardcoded secrets: AWS access keys, Google API keys, private key headers, Slack/GitHub/Stripe tokens, JWTs, and Firebase Cloud Messaging keys. A curated high-precision starting set, not exhaustive, and not a replacement for a maintained secret scanner. Only reads files; skips files over 2 MB. Returns { dirPath, filesScanned, matchCount, matches: [{ file, line, text, name }], truncated } where name is the secret type, file is relative to dirPath, line is 1-based, and text is the trimmed line (max 300 chars). For your own patterns use search_code.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| dirPath | Yes | Absolute path of the directory to scan, e.g. the outputDir from decompile_apk. Must exist. | |
| workspace | No | Workspace name (not id). Created if it doesn't exist, and this call is recorded as a job in its history. Defaults to "default". | |
| extensions | No | Only scan files with these extensions - lowercase, with the leading dot, e.g. [".java", ".xml"]. Omit to scan every file except known binary types (.apk, .dex, .zip, .jar, .so, images, fonts). | |
| maxResults | No | Stop after this many matches. Default and maximum 200. |