Skip to content
Benchmarks

redact-secret · Report · Detector

Mistral API keys

  • 68 fixtures
  • Format evidence: T2 · Tool-corroborated
  • Run 2026-10-07
  • Mode published · redact-secret 0.1.0-beta.14

Format evidence

Context-gated arrival family (#384, product redact-secret#868; research #781). No Mistral page or SDK code states a prefix, length or alphabet (the SDK does no validation), so nothing reaches T1. Three tool rules that read as one assertion (osv-scalibr, betterleaks, pleno-dlp) agree on exactly 32 alphanumeric characters with a mandatory Mistral context, and none is a pinned peer. GitHub lists a partner pattern without publishing its shape. The value is recognised only beside a same-line mistral or codestral name, an api.mistral.ai host or a Mistral SDK constructor, so its positives score as project policy and its twins keep the value and change only the context. A bare 32-character run is indistinguishable from an MD5, a request id or another provider's key, so no bare-value claim is made. The realtime token (#780, an rt_ shape) and the Codestral key shape are not members of this family.

What the run recorded, by group

Detector views overlap, so their groups are never summed across detectors. Other scanners are reference values on the same inputs, in run order.
Groups of Mistral API keys fixtures
GroupFixturesLeaked or false alarmsNear-twinsOutcomesOther scanners, same cell
Must not flag · Tool-corroborated18False alarmsat most 17.6%0 of 18 controls flagged18 quiet · 0 flagged
  • flare-redact at most 17.6%
  • gitleaks at most 17.6%
  • trufflehog at most 17.6%
Must not flag · Project policy25False alarmsat most 13.3%0 of 25 controls flagged25 quiet · 0 flagged
  • flare-redact at most 13.3%
  • gitleaks at most 19.5%
  • trufflehog at most 13.3%
Project policy · Project policy25Secret spans left readableat most 13.3%0 of 25 spansNear-twins told apartat least 81.6%17 of 17 pairs25 redacted · 0 too much · 0 partly exposed · 0 missed
  • flare-redact at most 97.8%
  • gitleaks at most 30.0%
  • trufflehog at most 100.0%
68 of 68 rows
Fixtures
68
Left readable
0
Redacted too much
0
False alarms
0

Fixtures for this detector

68 fixtures. Choose "Every scanner" to see each scanner's outcome for the same rows.
Fixtures in Mistral API keys
FixtureKind and evidenceredact-secret
mistral-api-key-actions-env-literalmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-auth-failure-logmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-camel-constmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-compose-envmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-curl-headermistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-docker-run-envmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-dotenvmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-dotenv-altmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-exportmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-http-request-headermistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-inline-env-commandmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-json-configmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-k8s-env-valuemistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-key-shape-baremistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-key-shape-quotedmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-key-shape-unicode-crlfmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-langchain-kwargmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-litellm-yamlmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-other-host-curl-twinmistral · missing-context-markerMust not flagT3 · Project policy · twinQuiet
mistral-api-key-printenv-outputmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-proxy-logmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-python-ctormistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-python-environ-assignmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-toml-config-keymistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-tool-callmistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-ts-ctormistral · documented-format-literalProject policyT3 · Project policyRedacted
mistral-api-key-actions-secret-referencemistral · templated-referenceMust not flagT3 · Project policyQuiet
mistral-api-key-angle-key-placeholdermistral · documentation-placeholderMust not flagT3 · Project policyQuiet
mistral-api-key-bare-in-prose-near-missmistral · format-near-missMust not flagT2 · Tool-corroboratedQuiet
mistral-api-key-bare-line-near-missmistral · format-near-missMust not flagT2 · Tool-corroboratedQuiet
mistral-api-key-base64-text-encoded-valuemistral · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
mistral-api-key-data-uri-encoded-valuemistral · benign-encoded-valueMust not flagT2 · Tool-corroboratedQuiet
mistral-api-key-docs-ctor-placeholdermistral · documentation-placeholderMust not flagT3 · Project policyQuiet
mistral-api-key-embedded-run-near-missmistral · format-near-missMust not flagT2 · Tool-corroboratedQuiet
mistral-api-key-env-reference-referencemistral · templated-referenceMust not flagT3 · Project policyQuiet
mistral-api-key-id-named-compose-twinmistral · missing-context-markerMust not flagT3 · Project policy · twinQuiet
mistral-api-key-id-named-env-alt-twinmistral · missing-context-markerMust not flagT3 · Project policy · twinQuiet
mistral-api-key-id-named-env-twinmistral · missing-context-markerMust not flagT3 · Project policy · twinQuiet
mistral-api-key-id-named-export-twinmistral · missing-context-markerMust not flagT3 · Project policy · twinQuiet
mistral-api-key-id-named-json-twinmistral · missing-context-markerMust not flagT3 · Project policy · twinQuiet
mistral-api-key-id-named-kwarg-twinmistral · missing-context-markerMust not flagT3 · Project policy · twinQuiet
mistral-api-key-id-named-tool-call-twinmistral · missing-context-markerMust not flagT3 · Project policy · twinQuiet
mistral-api-key-key-guidance-prosemistral · prose-mentionMust not flagT3 · Project policyQuiet
mistral-api-key-key-shape-bare-twinmistral · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
mistral-api-key-key-shape-quoted-twinmistral · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
mistral-api-key-key-shape-unicode-crlf-twinmistral · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
mistral-api-key-label-prosemistral · benign-lookalikeMust not flagT3 · Project policyQuiet
mistral-api-key-long-value-twinmistral · wrong-lengthMust not flagT2 · Tool-corroborated · twinQuiet
mistral-api-key-maskmistral · benign-lookalikeMust not flagT3 · Project policyQuiet
mistral-api-key-missing-keywordmistral · benign-lookalikeMust not flagT2 · Tool-corroboratedQuiet