Secret Scan
secret_scanScan workspace files for exposed credentials using multiple secret scanners. Detects candidates from file contents and git history without sending data externally.
Instructions
Scan files in the engagement workspace for credentials. No validation.
Runs Kingfisher (primary), Nosey Parker (git history + ML denoising), and gitleaks where installed. Sends no traffic anywhere — every hit is a candidate until secret_validate says otherwise.
path is workspace-relative; paths outside the workspace are refused.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| path | No | . | |
| git_history | No |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
No arguments | |||