Skip to content

fix: mask generic secrets and cloud account ids in scan reports - #11

Merged
kashyap-techsuite merged 3 commits into
mainfrom
fix/scan-report-secret-masking-v2
Oct 7, 2026
Merged

kashyap-techsuite merged 3 commits into
mainfrom
fix/scan-report-secret-masking-v2

Conversation

@kashyap-techsuite

Copy link
Copy Markdown

Masks keys from unlisted providers, cloud account ids and ssh -o User logins in the scan report, and documents what the report still leaves readable.

kashyap-techsuite and others added 2 commits October 7, 2026 19:01
Adds a report pass, redact-secrets, between the path and identifier passes. It masks the
value after a name ending in _KEY or -key, an Authorization header carrying a raw, Basic or
Token credential, and any run of 32 or more base62/base64url characters that looks random,
as [REDACTED:secret:generic]. The fallback also applies after a single "=" (VAR=value,
--flag=value) and skips UUIDs, hex digests, integrity values, data URIs, runs ending in
base64 padding, labels joined to a hash, runs of eight or more digits, and runs made mostly
of ordinary words (kebab-case, snake_case, camelCase and PascalCase identifiers, short-segment
deployment names such as pods and releases that hold three or more deployment words). It needs a
digit, a letter and at least 4.0 bits of entropy per character.

The identifier pass now redacts cloud account identifiers: any *ACCOUNT_ID, CF_ACCOUNT,
CLOUDFLARE_ACCOUNT and project variable, account_id, --account-id/--account/--owner-id
values shaped like an account, the account field of an arn:, a bare 32-hex operand of
wrangler, and --project for gcloud, gsutil, bq and firebase. ssh -o User= (quoted or glued)
redacts the login, and a flag ending in -key takes its value as a secret.

Matching stays linear: tests time every pass of the report composition on 200,000-character
repeats of underscores, quotes, digits, account names and similar shapes.

Branch and folder names stay readable; tests pin that. The report copy and README describe
the new passes and state that masking is best effort. Adds the new spelling words to the package
word list. Regenerates plugin/scripts/guard-scan.mjs.

Co-Authored-By: Claude <noreply@anthropic.com>
Adds a short section after the action table: what the guardrails address in the
OWASP Top 10 lists and where the pack-to-risk table is, that a warn guardrail
lets the action run and only ask and block stop it, and the risks Guard does not
address because it sees commands and file paths, not prompts or file contents.

Co-Authored-By: Claude <noreply@anthropic.com>
@kashyap-techsuite
kashyap-techsuite merged commit da3f083 into main Oct 7, 2026
3 checks passed
@agenttrail-public-release

Copy link
Copy Markdown

🎉 This PR is included in version 0.4.2 🎉

The release is available on:

Your semantic-release bot 📦🚀

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants