scan_secrets
Scan files and directories for leaked secrets, API keys, and credentials. Detects exposed .env files and missing .gitignore coverage with line numbers and remediation steps.
Instructions
Scan files and directories for leaked secrets, API keys, tokens, and credentials. Detects high-entropy strings, known API key patterns (AWS, Stripe, OpenAI, GitHub, Supabase), exposed .env files, and missing .gitignore coverage. Returns findings with exact line numbers and remediation steps.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| path | Yes | File or directory path to scan | |
| recursive | No | Scan subdirectories | |
| format | No | Output format: markdown (human) or json (machine-readable for agents) | markdown |