Review agent · Secrets & crypto

Secrets & data exposure

Judges whether a flagged value is really a secret and whether sensitive data leaks through logs or errors.

config/settings.py1STRIPE_KEY = "sk_live_••••••"23log.info("auth %s", token)Secretswhat this review answersCredentials or keys in source?Secrets or PII in logs and errors?Placeholder, fixture or public ID?$ verdict REAL ISSUE$ fix secrets manager, then rotate▍

Illustrative example of how this agent reviews a finding.

Why this agent matters

A leaked credential needs no exploit — whoever finds it just logs in. The 2016 Uber breach started with cloud keys found in a code repository.

Secret scanners are deliberately noisy: test fixtures, example keys and placeholders all match. This agent decides whether the value is a real secret and whether it crosses a boundary unsafely. Secret values are redacted before it ever sees them.

What it checks

  • Credentials and private keys in source or config
  • Secrets or PII written to logs or error responses
  • Sensitive data stored in cleartext
  • Insufficiently protected credentials

When it marks a finding as a likely false positive

  • The value is a placeholder, test fixture or public identifier
  • The data never leaves a trusted boundary

The fix it suggests

  • Moving secrets to a secrets manager or environment variables
  • Rotating anything that was committed
  • Scrubbing logs and error messages

Scope and limits

This agent validates findings reported by Semgrep, Gitleaks and Trivy; it doesn't hunt for new bugs on its own. A finding reaches it when its CWE or rule/path keywords match this vulnerability class. It sees only the minimal code around the finding, with secrets redacted, and returns a verdict with a confidence score, a plain-English explanation and a suggested patch.

Common questions

Does OpenRouting send my secrets to the AI?

No. Secret values are replaced with [REDACTED] before any model call. The agent assesses how the value is handled, not the value itself.

Is deleting a committed secret enough?

No. It remains in git history, which Gitleaks scans. Rotate the credential; that is the only real fix.

Related agents

  • Cryptography — Checks that cryptographic primitives fit their purpose and keys, IVs and randomness are handled correctly.

See all 20 review agents → · Agent setup reviewer · How the pipeline works

Run the Secrets & data exposure agent on your repository

100 free credits, no credit card. Every finding comes with a verdict and a fix.

Get started free