Skip to content

Poor working of "Secrets" input scanner; with tweaking any parameters make it work better? #293

@praveentcom

Description

@praveentcom

I tried adding the following scanners in my Docker deployment and got very poor results from the Secrets scanner. It failed to mask almost all of the prompts I tested which contained API keys.

Some sample prompts

  • My name is John Doe and I am a software developer. My API key is tpuf_hmNxzxxxP3yL8R and I need to share it with my team.
  • My API key is sk-1244fjsdjsnw42343 and I need to share it with my team.

(Keys are made gibberish for the purpose of filing this issue)

Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions