redact-secret · Report
Findings
Findings this benchmark handed to the product, newest first. Ledger last reviewed 2026-10-07; last measured release 0.1.0-beta.14, when 48 of 56 fixed and verified records were confirmed against the accepted run and 8 kept their status because the run could not confirm them. A snapshot of lifecycle records, not live issue status.
| Finding | Status | Fixtures | Recorded |
|---|---|---|---|
| #1236 · Square placeholders are still reported: EAAA-your-access-token, EAAA<your-production-access-token>, sandbox-sq0csb-<your-sandbox-application-secret>Flagged a safe value | Promoted |
| 2026-10-06Measured on 0.1.0-beta.13 |
| #1042 · Placeholders are still reported: vcp_/vca_/vcr_ x-run and rpa_ word fixtures, ClickHouse mykeysecret, Paddle ellipsis, Bitwarden x-runFlagged a safe value | Verified |
| 2026-09-30Measured on 0.1.0-beta.11 |
| #1041 · generic-token redacts the placeholder phrase placeholder-not-a-key under secret_access_key (newly reached since #1026)Flagged a safe value | Verified |
| 2026-09-30Measured on 0.1.0-beta.11 |
| #1038 · Python subscript assignments os.environ["NAME"] = "<literal>" are never read as an assignment: credential values under MISTRAL_API_KEY, CO_API_KEY, API_TOKEN are missedLeft a secret readable | Verified |
| 2026-09-30Measured on 0.1.0-beta.11 |
| #1018 · A complete, unmasked Cohere key under a masked_-led name (LiteLLM proxy debug log) is not reportedLeft a secret readable | Verified |
| 2026-09-30Measured on 0.1.0-beta.11 |
| #1017 · deepgram-api-key misses the JS SDK createClient("<key>") and the WebSocket token subprotocol, and types adjacent-line Deepgram context as generic-tokenLeft a secret readable | Verified |
| 2026-09-30Measured on 0.1.0-beta.11 |
| #1016 · Kubernetes env name:/value: pairs are never read as an assignment: credential values under DEEPGRAM_API_KEY, CO_API_KEY, API_TOKEN are missedLeft a secret readable | Verified |
| 2026-09-30Measured on 0.1.0-beta.11 |
| #1015 · generic-token redacts the sk-ant-admin01-<your-key> placeholder that it leaves alone for sk-ant-api01-/sk-ant-api03-Flagged a safe value | Verified |
| 2026-09-30Measured on 0.1.0-beta.11 |
| #949 · generic-token warns on provider-prefixed placeholders (signkey-test-<digits>, re_<digits>, re_your<word>)Flagged a safe value | Verified |
| 2026-09-28Measured on 0.1.0-beta.10 |
| #936 · Policy: keyword co-occurrence spans in the Beta.11 family evidence warn instead of redact (confidence-gated context families)Left a secret readable | Policy |
| 2026-09-28Measured on 0.1.0-beta.10 |
| #935 · connection-string misses the password in dialect+driver:// URLs (postgresql+psycopg://)Left a secret readable | Verified |
| 2026-09-28Measured on 0.1.0-beta.10 |
| #934 · heroku-api-key-legacy and stripe-token redact repeated-filler documentation placeholders (all-zero UUID, sk_test_ + x run)Flagged a safe value | Verified |
| 2026-09-28Measured on 0.1.0-beta.10 |
| #933 · Context-gated legacy keys missed when the provider context is on the previous line (heroku authorizations:info, Schema Registry basic.auth.user.info, twilio profiles:list)Left a secret readable | Verified |
| 2026-09-28Measured on 0.1.0-beta.10 |
| #932 · Deepgram/Cohere keyword-gated keys missed in same-line forms the gate does not recognise (HTTPie Token header, Go/Java SDK calls, LiteLLM log)Left a secret readable | Verified |
| 2026-09-28Measured on 0.1.0-beta.10 |
| #931 · mailchimp-api-key misses a complete -us<dc> key with no Mailchimp keyword on the value line (Basic-auth tuple, prose, apikey header)Left a secret readable | Verified |
| 2026-09-28Measured on 0.1.0-beta.10 |
| #911 · generic-token redacts secret-reference names and identifiers in ordinary config/source (untargeted real-world-shapes)Flagged a safe value | Verified |
| 2026-09-28Measured on 0.1.0-beta.10 |
| #825 · Policy: short values under high-signal names warn instead of redact (beta9 adversarial pack)Left a secret readable | Policy |
| 2026-09-25Measured on 0.1.0-beta.8 |
| #824 · Policy: warn on short literals under high-signal names in benign code (`"somefakekey"`, `"#add-password"`)Flagged a safe value | Policy |
| 2026-09-25Measured on 0.1.0-beta.8 |
| #823 · Policy: keyword-scanner shapes outside the contextual-assignment contract (reversed comparison, C++ constructor argument, `db_pass`)Left a secret readable | Policy |
| 2026-09-25Measured on 0.1.0-beta.8 |
| #822 · Policy: submitted-range misses outside the raw-input contract (RFC display-wrapped JWT and JWK figures; a percent-encoded URL with no access_token parameter under standard parsing)Left a secret readable | Policy |
| 2026-09-25Measured on 0.1.0-beta.8 |
| #821 · JWK secret members (`"k"`, `"d"`, `"p"`, `"q"`, `"dp"`, `"dq"`, `"qi"`) are not detectedLeft a secret readable | Verified |
| 2026-09-25Measured on 0.1.0-beta.8 |
| #820 · connection-string misses the password in http(s)/ftp URL userinfo (`https://user:pass@host/`)Left a secret readable | Verified |
| 2026-09-25Measured on 0.1.0-beta.8 |
| #819 · RFC 8959 `secret-token:` URIs are redacted without their scheme, and missed with an upper-case scheme or behind another assignmentLeft a secret readable | Verified |
| 2026-09-25Measured on 0.1.0-beta.8 |
| #818 · Authorization header credentials missed: `Proxy-Authorization`, Basic/Token not at line start, header-anchored Bearer values of 12-15 bytesLeft a secret readable | Verified |
| 2026-09-25Measured on 0.1.0-beta.8 |
| #817 · generic-token flags non-secret references and identifiers under credential names (HTML-escaped placeholder, quoted `$VAR`, `env.X`, string concatenation, AWS ARN)Flagged a safe value | Verified |
| 2026-09-25Measured on 0.1.0-beta.8 |
| #816 · generic-token misses credential parameters in URL query strings, fragments and form bodies (`?access_token=`, `&client_secret=`, `code_verifier=`)Left a secret readable | Verified |
| 2026-09-25Measured on 0.1.0-beta.8 |
| #815 · generic-token misses assignments with escaped JSON quotes, `:=`, Objective-C `@"..."`, or braces inside the valueLeft a secret readable | Verified |
| 2026-09-25Measured on 0.1.0-beta.8 |
| #756 · generic-token flags YOUR_API_KEY-style documentation placeholders assigned to a credential-like name (apiKey: "YOUR_API_KEY", Api-Key: YOUR_API_KEY)Flagged a safe value | Fixed |
| 2026-09-24Measured on 0.1.0-beta.7 |
| #754 · new-relic-license-key misses current-generation FFFFNRAL license keys when no New Relic keyword is on the same line (license_key:, X-License-Key:, licenseKey:)Left a secret readable | Fixed |
| 2026-09-24Measured on 0.1.0-beta.7 |
| #749 · google-api-key: an AIza key inside a Firebase web config is not reported, because the #520 B3a client-config exemption drops it. The maintainer reversed B3a in #749; this record supersedes the undecided product-520 observation.Left a secret readable | Fixed |
| 2026-09-24Measured on 0.1.0-beta.7 |
| #747 · telegram-bot-token reports an Atlassian account id (<digits>:<uuid>) as a bot tokenFlagged a safe value | Fixed |
| 2026-09-24Measured on 0.1.0-beta.7 |
| #746 · generic-token warns on Twilio SK/AC SIDs (public identifiers) after a 'credentials:' labelFlagged a safe value | Fixed |
| 2026-09-24Measured on 0.1.0-beta.7 |
| #745 · bearer-token redacts upper-snake placeholders of 16+ characters (YOUR_ACCESS_TOKEN, YOUR_OAUTH_TOKEN)Flagged a safe value | Fixed |
| 2026-09-24Measured on 0.1.0-beta.7 |
| #744 · twilio-auth-token and confluent-cloud-api-secret-legacy flag labelled hex digests (md5=, @sha256:) on a provider lineFlagged a safe value | Fixed |
| 2026-09-24Measured on 0.1.0-beta.7 |
| #743 · heroku-api-key-legacy misses the legacy UUID in multi-line .netrc and 'heroku auth:token' outputLeft a secret readable | Fixed |
| 2026-09-24Measured on 0.1.0-beta.7 |
| #743 · heroku-api-key-legacy flags a Heroku app UUID in a Platform API URL pathFlagged a safe value | Fixed |
| 2026-09-24Measured on 0.1.0-beta.7 |
| #742 · supabase-token accepts sb_secret_ values outside the documented 22 + '_' + 8 layout (twin false positives)Flagged a safe value | Fixed |
| 2026-09-24Measured on 0.1.0-beta.7 |
| #741 · atlassian-api-token leaves the '=' + 8-hex suffix of 192-character tokens unredacted (partial redaction)Left a secret readable | Fixed |
| 2026-09-24Measured on 0.1.0-beta.7 |
| #740 · heroku-api-key misses the documented 41-character HRKU-<uuid> OAuth token generationLeft a secret readable | Fixed |
| 2026-09-24Measured on 0.1.0-beta.7 |
| #739 · generic-token flags the public Confluent Cloud API key ID in an "apiKey" fieldFlagged a safe value | Policy |
| 2026-09-24Measured on 0.1.0-beta.7 |
| #738 · confluent-cloud-api-secret does not validate the documented CRC32 checksum, so checksum-invalid cflt values are flaggedFlagged a safe value | Fixed |
| 2026-09-24Measured on 0.1.0-beta.7 |
| #730 · generic-token redacts a {keychain:...} secret-store reference assigned to "apiKey"Flagged a safe value | Fixed |
| 2026-09-24Measured on 0.1.0-beta.7 |
| #727 · generic-token flags an xAI key-metadata ACL scope string ("api-key:endpoint:chat") in a public-id controlFlagged a safe value | Fixed |
| 2026-09-24Measured on 0.1.0-beta.7 |
| #714 · heroku-api-key-legacy flags the HEROKU_APP_ID public-id controlFlagged a safe value | Fixed |
| 2026-09-24Measured on 0.1.0-beta.7 |
| #702 · Legacy bare-UUID Pinecone API key missed under provider-named identifiers (PINECONE_API_KEY=, pinecone_api_key:, api_key=) while the same UUID under apiKey/Api-Key is redactedLeft a secret readable | Fixed |
| 2026-09-24Measured on 0.1.0-beta.7 |
| #428 · Promote the SendGrid generic-key whole-span contract (trailing dash, embedded underscore) out of regressions.test.mjsLeft a secret readable | Fixed |
| 2026-09-24Measured on 0.1.0-beta.5 |
| #428 · Promote the reference-syntax literal-credential positive controls out of regressions.test.mjsLeft a secret readable | Fixed |
| 2026-09-24Measured on 0.1.0-beta.5 |
| #404 · SendGrid API key with CRLF/Unicode-prefixed content only partially redacted (3-byte boundary short)Left a secret readable | Fixed |
| 2026-09-24Measured on 0.1.0-beta.4 |
| #264 · generic-token flags a partially masked console value (gsk_ + 48 asterisks + 4 visible characters) after a "Secret:" labelFlagged a safe value | Fixed |
| 2026-09-24Measured on 0.1.0-beta.7 |
| #708 · docker-token rejects the 27-byte dckr_oat_ body that Docker's own API reference showsLeft a secret readable | Fixed |
| 2026-09-23Measured on 0.1.0-beta.7 |
| #707 · microsoft-entra-client-secret misses secrets whose first character is '-'Left a secret readable | Fixed |
| 2026-09-23Measured on 0.1.0-beta.7 |
| #672 · new-relic-license-key current shape (32-hex + FFFFNRAL) goes undetectedLeft a secret readable | Fixed |
| 2026-09-23Measured on 0.1.0-beta.6 |
| #671 · datadog-application-key: ddapp_-prefixed application keys (current format) go undetectedLeft a secret readable | Fixed |
| 2026-09-23Measured on 0.1.0-beta.6 |
| #670 · discord-bot-token current shapes (26/6/38, 24/6/38) go undetectedLeft a secret readable | Fixed |
| 2026-09-23Measured on 0.1.0-beta.6 |
| #553 · D5: bearer-token and sendgrid-token twin/differential findings — fixture encodes a superseded or conflated expectation, no detector defectFlagged a safe value | Policy |
| 2026-09-21Measured on 0.1.0-beta.5 |
| #552 · D4: generic-token markdown-inline-code assignment boundary — the confirmed, independent share of the 168 metamorphic failuresLeft a secret readable | Fixed |
| 2026-09-21Measured on 0.1.0-beta.5 |
| #551 · D3: Fix the shared boundary false positive — 42 confirmed entries across 7 families, one root causeFlagged a safe value | Fixed |
| 2026-09-21Measured on 0.1.0-beta.5 |
| #408 · Cloudflare token shape 1 (bare/quoted/unicode-crlf) goes undetected against release candidateLeft a secret readable | Fixed |
| 2026-09-18Measured on 0.1.0-beta.4 |
| #407 · Docker token shape 1 (bare/quoted/unicode-crlf) goes undetected against release candidateLeft a secret readable | Fixed |
| 2026-09-18Measured on 0.1.0-beta.4 |
| #406 · Slack token shape 1 (bare/quoted/unicode-crlf) goes undetected against release candidateLeft a secret readable | Fixed |
| 2026-09-18Measured on 0.1.0-beta.4 |
| #405 · OpenAI token shapes 1-3 (bare/quoted/unicode-crlf) go undetected against release candidateLeft a secret readable | Fixed |
| 2026-09-18Measured on 0.1.0-beta.4 |
| #294 · Define and fix contextual secret detection inside nested quoted textLeft a secret readable | Fixed |
| 2026-09-16Measured on 0.1.0-beta.3 |
| #293 · Preserve Azure App Service Key Vault references in contextual detectionFlagged a safe value | Fixed |
| 2026-09-16Measured on 0.1.0-beta.3 |
| #292 · Preserve Windows environment references and SQL bind parameters in contextual detectionFlagged a safe value | Fixed |
| 2026-09-16Measured on 0.1.0-beta.3 |