Agent Utilities
← Security checks

security.secret-scan · v1.0.0

Secret Scan
for your agent.

Detect five families of credential patterns with fully masked findings.

$0.0005 / call500 micro-dollar credits
131,072 bytes max input65,536 bytes max output
Works on supplied inputNo external network fetch

Example input

{
  "text": "No credentials in this example."
}

Example output

{
  "findings": [],
  "rulesVersion": "1.1.0",
  "limitReached": false,
  "caveat": "Fixed pattern scan; absence of findings does not establish safety."
}

Generated from the actual handler using this example input; this is a preview, not a paid API call. Paid responses wrap the result with a receipt and recovery expiry.

Call it from your agent

Add credits in the workspace and keep your API key in private environment storage. Use the same request ID and exact body to recover a lost response within ten minutes.

// Node.js 22+. Read the key from your private environment.
const requestId = Date.now() + '_' + crypto.randomUUID();
const response = await fetch('https://agent-utilities.agent-utilities.workers.dev/v1/tools/security.secret-scan', {
  method: 'POST',
  headers: {
    'Content-Type': 'application/json',
    'Authorization': 'Bearer ' + process.env.AGENT_UTILITIES_API_KEY,
    'Idempotency-Key': requestId
  },
  body: JSON.stringify({
  "text": "No credentials in this example."
})
});
const data = await response.json();
if (!response.ok) throw new Error(data.error?.message ?? 'Request failed');
console.log(data);
// On response loss, retry this SAME requestId, tool and body.
// Do not rerun the line that generates requestId for a retry.
Input JSON Schema
{
  "type": "object",
  "properties": {
    "text": {
      "type": "string",
      "maxLength": 100000
    }
  },
  "required": [
    "text"
  ],
  "additionalProperties": false
}
Output JSON Schema
{
  "type": "object",
  "properties": {
    "findings": {
      "type": "array",
      "items": {
        "type": "object",
        "properties": {
          "rule": {
            "type": "string"
          },
          "start": {
            "type": "number"
          },
          "end": {
            "type": "number"
          },
          "line": {
            "type": "number"
          },
          "masked": {
            "type": "string"
          }
        },
        "required": [
          "rule",
          "start",
          "end",
          "line",
          "masked"
        ],
        "additionalProperties": false
      }
    },
    "rulesVersion": {
      "type": "string"
    },
    "limitReached": {
      "type": "boolean"
    },
    "caveat": {
      "type": "string"
    }
  },
  "required": [
    "findings",
    "rulesVersion",
    "limitReached",
    "caveat"
  ],
  "additionalProperties": false
}

Before you integrate

Prices are experimental. The service currently allows 1,000 new calls per day across all accounts. Failed operations return reserved credits. This tool may process sensitive content; use sanitized samples when possible. Successful results are encrypted for ten-minute retry recovery. Review data handling and service limits.

Related tools

security $0.0005 / call

Secret Redact

Replace detected credential patterns with redaction markers.

security.secret-redact

security $0.0003 / call

JWT Inspect

Decode untrusted JWT claims and optionally compare timestamps; never verifies a signature.

security.jwt-inspect

security $0.0005 / call

CSP Audit

Parse a supplied Content Security Policy and flag selected risky or missing directives.

security.csp-audit