Checks & Toolchains

Built-in secret scanner and protected paths

What's scanned for leaked credentials automatically, and how to keep specific files off-limits.

The secret scanner

A secret scan runs as one of the built-in gates on every ticket. You don't add a script to your repository for it, and you can't accidentally ship without it. It checks the diff against 13 built-in patterns covering common credential and token formats, and a genuine secret on any changed line blocks shipping the same way a failing test would.

Allowlisting a line. If a scanner match is a false positive (a documentation example, a placeholder value), mark that specific line with a pragma: allowlist secret comment. That line is skipped; a real key elsewhere in the same file is still caught.

Turn the scanner off, or add your own patterns, in Settings → Checks.

Protected paths

Independent of what any ticket asks for, protected paths are files and directories the agent is never allowed to modify: things like .env files, a secrets directory, CI configuration, or a lockfile you manage by hand. A ticket that tries to touch one, even indirectly, gets blocked at that write, not caught after the fact in review.

Add your own in Settings → Checks. A glob per line is enough, for example .env* or infra/**.