redact-secret · Evaluation · Qualification
slack-app-level-token
Taxonomy families: slack · App-level token. The status and its evidence, then what each scanner recorded per population.
Support status of the product
Provisional The product’s qualification, derived by the adapter. It is not a scanner observation.
- Route
- No route
- Evidence tier
- T2
- Evidence basis
- corroborated
- Contract tier
- T2
- Fixture profile claimed
- Not recorded
- Fixture profile cells met
- arrival-provisional, stable-documented, stable-empirical
Why the status is not stable
- empirical.corroborated.minimumReferences: 0 < 3 — Corroborated route (#177 amendment, 2026-09-24): at least three verified, dated references, each corroborating the shape the contract freezes. One rule or one example is a single point of failure. (corroborated route)
- empirical.corroborated.minimumOwners: 0 < 3 — The references must come from at least three distinct owners (a scanner vendor, the provider, a third party, this project's research). Two rules from one vendor, or a provider's docs page and its SDK, are one voice. (corroborated route)
- empirical.corroborated.minimumClasses: 0 < 2 — At least two corroboration classes other than a summary class. Peer scanner rules copy one another (#215 found tool shapes 'possibly copied from one source'), so scanner rules alone never qualify: one reference must be provider-owned code, a provider example or an independent implementation. (corroborated route)
- empirical.minimumObservations: 0 < 5 — Observed route (#205): five safe provider-issued observations are the minimum empirical sample. Since the 2026-09-24 amendment of #177 this route is optional: meeting it strengthens a T2 family's evidence basis to empirically-observed, and the corroborated route qualifies without any observation. (observed route, optional)
- empirical.minimumSubjects: 0 < 2 — Observed route: observations must span at least two pseudonymous accounts or projects. (observed route, optional)
- empirical.minimumIssuanceDates: 0 < 2 — Observed route: observations must span at least two issuance dates. (observed route, optional)
- empirical.minimumCorroborationClasses: 0 < 2 — Observed route: two corroboration classes, summary classes excluded, must agree with the observed structure. (observed route, optional)
- empirical.uncertainty: missing — explicit uncertainty is required
- empirical.supportedContexts: none — supported-context limits are required
- empirical.mode: missing — choose shape or context-constrained qualification
Evidence the status was judged on
Floors and fixture-profile cells are read from public-evidence-snapshot alone; a gate reads each gate-bearing population on its own.
- Scored cases
- 40
- Positive cases
- 17
- Positive context axes
- 12
- Benign controls
- 15
- Benign control axes
- 6
- Twin pairs
- 8
- Metamorphic critical failures
- 0
- Mutation unresolved critical
- 0
- Differential unresolved disagreements
- 0
Zero-tolerance gates
The classifier receives the worst gate-bearing population, never a sum. Each population is shown on its own.
| Population | Twin pairs that did not discriminate | Benign controls flagged |
|---|---|---|
public-evidence-snapshot | 0 of 8 | 0 of 15 |
regression-corpus | No pair | No control |
Scanner observations
What each scanner recorded for this family, per population. These are counts and carry no support status; a case that is pending or not measured is not a miss.
| Population | Scanner | Cases | Positive spans | Span outcomes | Leaked | Benign controls flagged | Twin pairs discriminated | Pending / not measured |
|---|---|---|---|---|---|---|---|---|
policy-corpuspolicy route | flare-redact | 0 | No case | No case in this population | No positive span | No control | No pair | None |
policy-corpuspolicy route | gitleaks | 0 | No case | No case in this population | No positive span | No control | No pair | None |
policy-corpuspolicy route | redact-secret | 0 | No case | No case in this population | No positive span | No control | No pair | None |
policy-corpuspolicy route | trufflehog | 0 | No case | No case in this population | No positive span | No control | No pair | None |
public-evidence-snapshotfloors and gates | flare-redact | 40 | 17 | COVERED 1 · OVERBROAD 1 · MISS 15 | 15 spans · 1,455 bytes | 1 of 15 | 1 of 8 | None |
public-evidence-snapshotfloors and gates | gitleaks | 40 | 17 | EXACT 17 | 0 spans · 0 bytes | 0 of 15 | 6 of 8 | None |
public-evidence-snapshotfloors and gates | redact-secret | 40 | 17 | EXACT 17 | 0 spans · 0 bytes | 0 of 15 | 8 of 8 | None |
public-evidence-snapshotfloors and gates | trufflehog | 40 | 17 | MISS 17 | 17 spans · 1,649 bytes | 0 of 15 | 0 of 8 | None |
regression-corpusgates | flare-redact | 0 | No case | No case in this population | No positive span | No control | No pair | None |
regression-corpusgates | gitleaks | 0 | No case | No case in this population | No positive span | No control | No pair | None |
regression-corpusgates | redact-secret | 0 | No case | No case in this population | No positive span | No control | No pair | None |
regression-corpusgates | trufflehog | 0 | No case | No case in this population | No positive span | No control | No pair | None |
Cases
Each case of this family, per population, with what every scanner recorded for it and the case’s own facts.