Detect hardcoded secrets in source and config, reporting masked previews and never the values themselves.
Single tool 'detect_secrets' has a well-structured schema with proper types, enums, and constraints. Description is clear and security-focused (145 chars), explaining what the tool does and its safety guarantees. All 6 parameters are typed and described. However, the tool lacks error handling guidance, output schema documentation, and tool annotations (readOnlyHint). The description could be more explicit about when to use this tool vs. alternatives, and error cases are not documented.
Detect hardcoded secrets — API keys, passwords, tokens and private keys — in source or configuration text. Reports each finding by type, confidence, key name and 1-based position. Values are never returned: previews are truncated and length-annotated, and the surrounding context line has the secret masked out, so a finding can be located without the credential leaving the machine it was found on.
Output schema not documented. Tool description does not specify the structure of returned findings (fields like type, confidence, key_name, position, preview, context_line).
No error handling guidance. Tool does not document what happens on invalid input (e.g., empty content, invalid sensitivity enum), or how the LLM should recover.
Missing tool annotations. Tool lacks readOnlyHint (true) and idempotentHint (true), which would help agents understand it is safe to call repeatedly without side effects.
Description does not explain when to use this tool or what the LLM should do with findings. Should clarify: 'Use this to scan code/config for hardcoded credentials before committing or deploying.'
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 65 | 2026-07-28+ | v2 |
Parameter 'sensitivity' enum values (low, medium, high) lack descriptions explaining the difference in detection thresholds and false-positive rates.