Skip to content
Benchmarks

redact-secret · Report

Findings

Findings this benchmark handed to the product, newest first. Ledger last reviewed 2026-10-07; last measured release 0.1.0-beta.14, when 48 of 56 fixed and verified records were confirmed against the accepted run and 8 kept their status because the run could not confirm them. A snapshot of lifecycle records, not live issue status.

  • 64 findings
  • Snapshot 2026-10-07
Findings handed to the product
FindingStatusFixturesRecorded
#1236 · Square placeholders are still reported: EAAA-your-access-token, EAAA<your-production-access-token>, sandbox-sq0csb-<your-sandbox-application-secret>Flagged a safe valuePromoted
  • square-token-your-access-token-placeholder
  • square-token-angle-brackets-placeholder
  • square-oauth-application-secret-angle-brackets-placeholder
2026-10-06Measured on 0.1.0-beta.13
#1042 · Placeholders are still reported: vcp_/vca_/vcr_ x-run and rpa_ word fixtures, ClickHouse mykeysecret, Paddle ellipsis, Bitwarden x-runFlagged a safe valueVerified
  • vercel-personal-access-token-x-run-placeholder
  • vercel-app-access-token-x-run-placeholder
  • vercel-app-refresh-token-x-run-placeholder
  • runpod-api-key-word-fixture-placeholder
  • paddle-api-key-ellipsis-placeholder
  • bitwarden-secrets-manager-access-token-x-run-placeholder
  • clickhouse-cloud-api-secret-docs-placeholders-placeholder
2026-09-30Measured on 0.1.0-beta.11
#1041 · generic-token redacts the placeholder phrase placeholder-not-a-key under secret_access_key (newly reached since #1026)Flagged a safe valueVerified
  • rust-secrecy-config
2026-09-30Measured on 0.1.0-beta.11
#1038 · Python subscript assignments os.environ["NAME"] = "<literal>" are never read as an assignment: credential values under MISTRAL_API_KEY, CO_API_KEY, API_TOKEN are missedLeft a secret readableVerified
  • mistral-api-key-python-environ-assign
2026-09-30Measured on 0.1.0-beta.11
#1018 · A complete, unmasked Cohere key under a masked_-led name (LiteLLM proxy debug log) is not reportedLeft a secret readableVerified
  • cohere-api-key-litellm-proxy-debug
2026-09-30Measured on 0.1.0-beta.11
#1017 · deepgram-api-key misses the JS SDK createClient("<key>") and the WebSocket token subprotocol, and types adjacent-line Deepgram context as generic-tokenLeft a secret readableVerified
  • deepgram-api-key-create-client
  • deepgram-api-key-websocket-subprotocol
2026-09-30Measured on 0.1.0-beta.11
#1016 · Kubernetes env name:/value: pairs are never read as an assignment: credential values under DEEPGRAM_API_KEY, CO_API_KEY, API_TOKEN are missedLeft a secret readableVerified
  • deepgram-api-key-k8s-env-value
  • cohere-api-key-k8s-env-value
  • mistral-api-key-k8s-env-value
2026-09-30Measured on 0.1.0-beta.11
#1015 · generic-token redacts the sk-ant-admin01-<your-key> placeholder that it leaves alone for sk-ant-api01-/sk-ant-api03-Flagged a safe valueVerified
  • anthropic-admin01-key-angle-key-placeholder
2026-09-30Measured on 0.1.0-beta.11
#949 · generic-token warns on provider-prefixed placeholders (signkey-test-<digits>, re_<digits>, re_your<word>)Flagged a safe valueVerified
  • inngest-signing-key-sdk-short-placeholder
  • resend-api-key-digits-placeholder
  • resend-api-key-your-key-placeholder
2026-09-28Measured on 0.1.0-beta.10
#936 · Policy: keyword co-occurrence spans in the Beta.11 family evidence warn instead of redact (confidence-gated context families)Left a secret readablePolicy
  • new-relic-license-key-python-newrelic-ini
  • new-relic-license-key-terraform-tfvars-eu
  • new-relic-license-key-agent-startup-json
  • deepgram-api-key-worker-json-log
  • heroku-api-key-legacy-platform-api-ruby
  • heroku-api-key-legacy-git-config-remote
  • confluent-cloud-api-secret-legacy-client-config-create
  • twilio-auth-token-validator-debug
2026-09-28Measured on 0.1.0-beta.10
#935 · connection-string misses the password in dialect+driver:// URLs (postgresql+psycopg://)Left a secret readableVerified
  • connection-string-sqlalchemy-ipv6
2026-09-28Measured on 0.1.0-beta.10
#934 · heroku-api-key-legacy and stripe-token redact repeated-filler documentation placeholders (all-zero UUID, sk_test_ + x run)Flagged a safe valueVerified
  • heroku-api-key-legacy-zero-uuid-placeholder
  • stripe-token-docs-x-body-placeholder
2026-09-28Measured on 0.1.0-beta.10
#933 · Context-gated legacy keys missed when the provider context is on the previous line (heroku authorizations:info, Schema Registry basic.auth.user.info, twilio profiles:list)Left a secret readableVerified
  • heroku-api-key-legacy-authorizations-info
  • confluent-cloud-api-secret-legacy-schema-registry-user-info
  • twilio-auth-token-profiles-auth-token
2026-09-28Measured on 0.1.0-beta.10
#932 · Deepgram/Cohere keyword-gated keys missed in same-line forms the gate does not recognise (HTTPie Token header, Go/Java SDK calls, LiteLLM log)Left a secret readableVerified
  • deepgram-api-key-httpie-token
  • deepgram-api-key-go-client-literal
  • cohere-api-key-java-builder-token
2026-09-28Measured on 0.1.0-beta.10
#931 · mailchimp-api-key misses a complete -us<dc> key with no Mailchimp keyword on the value line (Basic-auth tuple, prose, apikey header)Left a secret readableVerified
  • mailchimp-api-key-python-requests-auth
  • mailchimp-api-key-ticket-paragraph
  • mailchimp-api-key-debug-request-headers
2026-09-28Measured on 0.1.0-beta.10
#911 · generic-token redacts secret-reference names and identifiers in ordinary config/source (untargeted real-world-shapes)Flagged a safe valueVerified
  • helm-values-search-api
  • k8s-billing-externalsecret
  • ansible-group-vars-gameservers
  • swift-keychain-wrapper
  • pytest-fake-fixtures
  • lua-openresty-hmac
  • agent-summary-korean-rotation
2026-09-28Measured on 0.1.0-beta.10
#825 · Policy: short values under high-signal names warn instead of redact (beta9 adversarial pack)Left a secret readablePolicy
  • composed-yaml-block-scalar-json
  • rfc6750-token-response-json
  • composed-prefixed-key-name-secret
  • np-generic-password-dollar
  • np-generic-user-password-pair
2026-09-25Measured on 0.1.0-beta.8
#824 · Policy: warn on short literals under high-signal names in benign code (`"somefakekey"`, `"#add-password"`)Flagged a safe valuePolicy
  • ds-fake-in-value
  • np-css-selector
2026-09-25Measured on 0.1.0-beta.8
#823 · Policy: keyword-scanner shapes outside the contextual-assignment contract (reversed comparison, C++ constructor argument, `db_pass`)Left a secret readablePolicy
  • ds-keyword-reversed-comparison
  • ds-cpp-string-constructor
  • ds-keyword-non-ascii-secret
2026-09-25Measured on 0.1.0-beta.8
#822 · Policy: submitted-range misses outside the raw-input contract (RFC display-wrapped JWT and JWK figures; a percent-encoded URL with no access_token parameter under standard parsing)Left a secret readablePolicy
  • rfc7519-jwt-display-breaks
  • rfc7515-jwk-k-display-break
  • composed-percent-encoded-url-in-json
2026-09-25Measured on 0.1.0-beta.8
#821 · JWK secret members (`"k"`, `"d"`, `"p"`, `"q"`, `"dp"`, `"dq"`, `"qi"`) are not detectedLeft a secret readableVerified
  • composed-jwk-k-single-line
2026-09-25Measured on 0.1.0-beta.8
#820 · connection-string misses the password in http(s)/ftp URL userinfo (`https://user:pass@host/`)Left a secret readableVerified
  • composed-userinfo-password-url
2026-09-25Measured on 0.1.0-beta.8
#819 · RFC 8959 `secret-token:` URIs are redacted without their scheme, and missed with an upper-case scheme or behind another assignmentLeft a secret readableVerified
  • rfc8959-secret-token-folded-bearer
  • rfc8959-secret-token-prose
  • composed-secret-token-uppercase-scheme
2026-09-25Measured on 0.1.0-beta.8
#818 · Authorization header credentials missed: `Proxy-Authorization`, Basic/Token not at line start, header-anchored Bearer values of 12-15 bytesLeft a secret readableVerified
  • rfc7617-basic-utf8-proxy
  • composed-curl-single-quoted-json
  • composed-zero-width-inside-bearer
2026-09-25Measured on 0.1.0-beta.8
#817 · generic-token flags non-secret references and identifiers under credential names (HTML-escaped placeholder, quoted `$VAR`, `env.X`, string concatenation, AWS ARN)Flagged a safe valueVerified
  • np-html-escaped-placeholder
  • np-echo-concatenated-reference
  • np-env-attribute-reference
  • np-java-getter-concatenation
  • np-iam-managed-policy-arn
2026-09-25Measured on 0.1.0-beta.8
#816 · generic-token misses credential parameters in URL query strings, fragments and form bodies (`?access_token=`, `&client_secret=`, `code_verifier=`)Left a secret readableVerified
  • rfc6750-query-access-token
  • rfc6750-get-request-line
  • rfc6749-implicit-fragment-display-break
  • rfc6749-authorization-code-location
  • rfc7636-code-verifier
  • rfc6749-refresh-request-body
  • rfc6749-token-request-basic-and-code
2026-09-25Measured on 0.1.0-beta.8
#815 · generic-token misses assignments with escaped JSON quotes, `:=`, Objective-C `@"..."`, or braces inside the valueLeft a secret readableVerified
  • composed-json-string-in-json-log
  • ds-keyword-template-chars-in-secret
  • ds-keyword-go-short-assign
  • ds-objc-at-string
2026-09-25Measured on 0.1.0-beta.8
#756 · generic-token flags YOUR_API_KEY-style documentation placeholders assigned to a credential-like name (apiKey: "YOUR_API_KEY", Api-Key: YOUR_API_KEY)Flagged a safe valueFixed
  • mailchimp-api-key-docs-template-placeholder
  • pinecone-api-key-header-placeholder-placeholder
2026-09-24Measured on 0.1.0-beta.7
#754 · new-relic-license-key misses current-generation FFFFNRAL license keys when no New Relic keyword is on the same line (license_key:, X-License-Key:, licenseKey:)Left a secret readableFixed
  • new-relic-license-key-newrelic-yml
  • new-relic-license-key-newrelic-js-config
  • new-relic-license-key-log-api-license-header
  • new-relic-license-key-helm-bundle-values
2026-09-24Measured on 0.1.0-beta.7
#749 · google-api-key: an AIza key inside a Firebase web config is not reported, because the #520 B3a client-config exemption drops it. The maintainer reversed B3a in #749; this record supersedes the undecided product-520 observation.Left a secret readableFixed
  • google-api-key-firebase-web-config
2026-09-24Measured on 0.1.0-beta.7
#747 · telegram-bot-token reports an Atlassian account id (<digits>:<uuid>) as a bot tokenFlagged a safe valueFixed
  • atlassian-api-token-account-id-public-id
2026-09-24Measured on 0.1.0-beta.7
#746 · generic-token warns on Twilio SK/AC SIDs (public identifiers) after a 'credentials:' labelFlagged a safe valueFixed
  • twilio-api-key-secret-wrong-companion-near-miss
2026-09-24Measured on 0.1.0-beta.7
#745 · bearer-token redacts upper-snake placeholders of 16+ characters (YOUR_ACCESS_TOKEN, YOUR_OAUTH_TOKEN)Flagged a safe valueFixed
  • bearer-token-your-access-token-placeholder
2026-09-24Measured on 0.1.0-beta.7
#744 · twilio-auth-token and confluent-cloud-api-secret-legacy flag labelled hex digests (md5=, @sha256:) on a provider lineFlagged a safe valueFixed
  • twilio-auth-token-package-md5-encoded-value
  • confluent-cloud-api-secret-legacy-image-digest-encoded-value
2026-09-24Measured on 0.1.0-beta.7
#743 · heroku-api-key-legacy misses the legacy UUID in multi-line .netrc and 'heroku auth:token' outputLeft a secret readableFixed
  • heroku-api-key-legacy-netrc-multi-line
  • heroku-api-key-legacy-auth-token-output
2026-09-24Measured on 0.1.0-beta.7
#743 · heroku-api-key-legacy flags a Heroku app UUID in a Platform API URL pathFlagged a safe valueFixed
  • heroku-api-key-legacy-app-url-path-public-id
2026-09-24Measured on 0.1.0-beta.7
#742 · supabase-token accepts sb_secret_ values outside the documented 22 + '_' + 8 layout (twin false positives)Flagged a safe valueFixed
  • supabase-token-short-random-twin
  • supabase-token-long-checksum-twin
  • supabase-token-dash-delimiter-twin
2026-09-24Measured on 0.1.0-beta.7
#741 · atlassian-api-token leaves the '=' + 8-hex suffix of 192-character tokens unredacted (partial redaction)Left a secret readableFixed
  • atlassian-api-token-env
  • atlassian-api-token-curl-basic
  • atlassian-api-token-python-client-yaml
  • atlassian-api-token-jira-client
  • atlassian-api-token-pipelines-variable
  • atlassian-api-token-settings-json
  • atlassian-api-token-acli-login
  • atlassian-api-token-compose-env
  • atlassian-api-token-debug-log
  • atlassian-api-token-ticket-paste
2026-09-24Measured on 0.1.0-beta.7
#740 · heroku-api-key misses the documented 41-character HRKU-<uuid> OAuth token generationLeft a secret readableFixed
  • heroku-api-key-env-g1
  • heroku-api-key-authorizations-create-g1
2026-09-24Measured on 0.1.0-beta.7
#739 · generic-token flags the public Confluent Cloud API key ID in an "apiKey" fieldFlagged a safe valuePolicy
  • confluent-cloud-api-secret-secrets-manager-json
  • confluent-cloud-api-secret-secrets-manager-json-alphabet-twin
2026-09-24Measured on 0.1.0-beta.7
#738 · confluent-cloud-api-secret does not validate the documented CRC32 checksum, so checksum-invalid cflt values are flaggedFlagged a safe valueFixed
  • confluent-cloud-api-secret-env-cloud-secret-checksum-twin
  • confluent-cloud-api-secret-kafka-client-properties-checksum-byte-order-twin
  • confluent-cloud-api-secret-cli-api-key-create-json-checksum-prefix-included-twin
2026-09-24Measured on 0.1.0-beta.7
#730 · generic-token redacts a {keychain:...} secret-store reference assigned to "apiKey"Flagged a safe valueFixed
  • fireworks-ai-api-key-keychain-reference-reference
2026-09-24Measured on 0.1.0-beta.7
#727 · generic-token flags an xAI key-metadata ACL scope string ("api-key:endpoint:chat") in a public-id controlFlagged a safe valueFixed
  • xai-api-key-key-metadata-public-id
2026-09-24Measured on 0.1.0-beta.7
#714 · heroku-api-key-legacy flags the HEROKU_APP_ID public-id controlFlagged a safe valueFixed
  • heroku-api-key-legacy-public-id
2026-09-24Measured on 0.1.0-beta.7
#702 · Legacy bare-UUID Pinecone API key missed under provider-named identifiers (PINECONE_API_KEY=, pinecone_api_key:, api_key=) while the same UUID under apiKey/Api-Key is redactedLeft a secret readableFixed
  • pinecone-api-key-legacy-dotenv
  • pinecone-api-key-legacy-export
  • pinecone-api-key-legacy-legacy-init
  • pinecone-api-key-legacy-yaml-config
  • pinecone-api-key-legacy-actions-env
  • pinecone-api-key-legacy-compose-env
  • pinecone-api-key-legacy-langchain
  • pinecone-api-key-legacy-terraform-output
  • pinecone-api-key-legacy-shell-key
2026-09-24Measured on 0.1.0-beta.7
#428 · Promote the SendGrid generic-key whole-span contract (trailing dash, embedded underscore) out of regressions.test.mjsLeft a secret readableFixed
  • trailing-dash-generic-key
  • url-safe-generic-key
2026-09-24Measured on 0.1.0-beta.5
#428 · Promote the reference-syntax literal-credential positive controls out of regressions.test.mjsLeft a secret readableFixed
  • api-key
  • password
  • dotted-password
  • quoted-password
  • client-secret
  • unicode-crlf
2026-09-24Measured on 0.1.0-beta.5
#404 · SendGrid API key with CRLF/Unicode-prefixed content only partially redacted (3-byte boundary short)Left a secret readableFixed
  • sendgrid-token-segmented-unicode-crlf
2026-09-24Measured on 0.1.0-beta.4
#264 · generic-token flags a partially masked console value (gsk_ + 48 asterisks + 4 visible characters) after a "Secret:" labelFlagged a safe valueFixed
  • groq-api-key-masked-console-placeholder
2026-09-24Measured on 0.1.0-beta.7
#708 · docker-token rejects the 27-byte dckr_oat_ body that Docker's own API reference showsLeft a secret readableFixed
  • docker-token-oat-27-bare
  • docker-token-oat-27-quoted
  • docker-token-oat-27-unicode-crlf
2026-09-23Measured on 0.1.0-beta.7
#707 · microsoft-entra-client-secret misses secrets whose first character is '-'Left a secret readableFixed
  • microsoft-entra-client-secret-leading-dash-bare
  • microsoft-entra-client-secret-leading-dash-quoted
  • microsoft-entra-client-secret-leading-dash-unicode-crlf
2026-09-23Measured on 0.1.0-beta.7
#672 · new-relic-license-key current shape (32-hex + FFFFNRAL) goes undetectedLeft a secret readableFixed
  • new-relic-license-key-current-format-bare
  • new-relic-license-key-current-format-quoted
  • new-relic-license-key-current-format-unicode-crlf
2026-09-23Measured on 0.1.0-beta.6
#671 · datadog-application-key: ddapp_-prefixed application keys (current format) go undetectedLeft a secret readableFixed
  • datadog-application-key-prefixed-env-marker-bare
  • datadog-application-key-prefixed-env-marker-quoted
  • datadog-application-key-prefixed-env-marker-unicode-crlf
2026-09-23Measured on 0.1.0-beta.6
#670 · discord-bot-token current shapes (26/6/38, 24/6/38) go undetectedLeft a secret readableFixed
  • discord-bot-token-three-segments-current-new-bot-bare
  • discord-bot-token-three-segments-current-new-bot-quoted
  • discord-bot-token-three-segments-current-new-bot-unicode-crlf
  • discord-bot-token-three-segments-current-reset-bot-bare
  • discord-bot-token-three-segments-current-reset-bot-quoted
  • discord-bot-token-three-segments-current-reset-bot-unicode-crlf
2026-09-23Measured on 0.1.0-beta.6
#553 · D5: bearer-token and sendgrid-token twin/differential findings — fixture encodes a superseded or conflated expectation, no detector defectFlagged a safe valuePolicy
  • bearer-token-header-bare-twin
  • bearer-token-header-quoted-twin
  • bearer-token-header-unicode-crlf-twin
  • base62-bearer-twin
  • base62-generic-key-twin
2026-09-21Measured on 0.1.0-beta.5
#552 · D4: generic-token markdown-inline-code assignment boundary — the confirmed, independent share of the 168 metamorphic failuresLeft a secret readableFixed
  • generic-token-api-key-markdown-inline-code-boundary
  • generic-token-password-markdown-inline-code-boundary
  • generic-token-client-secret-markdown-inline-code-boundary
2026-09-21Measured on 0.1.0-beta.5
#551 · D3: Fix the shared boundary false positive — 42 confirmed entries across 7 families, one root causeFlagged a safe valueFixed
  • linear-token-oauth-trailing-identifier-embedding
  • linear-token-oauth-dash-identifier-embedding
  • slack-token-rotation-trailing-identifier-embedding
  • slack-token-rotation-dash-identifier-embedding
2026-09-21Measured on 0.1.0-beta.5
#408 · Cloudflare token shape 1 (bare/quoted/unicode-crlf) goes undetected against release candidateLeft a secret readableFixed
  • cloudflare-token-shape-1-bare
  • cloudflare-token-shape-1-quoted
  • cloudflare-token-shape-1-unicode-crlf
2026-09-18Measured on 0.1.0-beta.4
#407 · Docker token shape 1 (bare/quoted/unicode-crlf) goes undetected against release candidateLeft a secret readableFixed
  • docker-token-shape-1-bare
  • docker-token-shape-1-quoted
  • docker-token-shape-1-unicode-crlf
2026-09-18Measured on 0.1.0-beta.4
#406 · Slack token shape 1 (bare/quoted/unicode-crlf) goes undetected against release candidateLeft a secret readableFixed
  • slack-token-shape-1-bare
  • slack-token-shape-1-quoted
  • slack-token-shape-1-unicode-crlf
2026-09-18Measured on 0.1.0-beta.4
#405 · OpenAI token shapes 1-3 (bare/quoted/unicode-crlf) go undetected against release candidateLeft a secret readableFixed
  • openai-token-shape-1-bare
  • openai-token-shape-1-quoted
  • openai-token-shape-1-unicode-crlf
  • openai-token-shape-2-bare
  • openai-token-shape-2-quoted
  • openai-token-shape-2-unicode-crlf
  • openai-token-shape-3-bare
  • openai-token-shape-3-quoted
  • openai-token-shape-3-unicode-crlf
2026-09-18Measured on 0.1.0-beta.4
#294 · Define and fix contextual secret detection inside nested quoted textLeft a secret readableFixed
  • generic-token-api-key-quoted
  • generic-token-password-quoted
  • generic-token-client-secret-quoted
2026-09-16Measured on 0.1.0-beta.3
#293 · Preserve Azure App Service Key Vault references in contextual detectionFlagged a safe valueFixed
  • azure-keyvault
2026-09-16Measured on 0.1.0-beta.3
#292 · Preserve Windows environment references and SQL bind parameters in contextual detectionFlagged a safe valueFixed
  • windows-env
  • sql-bind
2026-09-16Measured on 0.1.0-beta.3