feat(enrichment): detect Cohere API keys and Intercom access tokens in secret-scan#3272
Conversation
…n secret-scan Add high-confidence co_ and dG9rOm token patterns with identifier-continuation tail guards, fragment-based fixtures, and truncation negatives. Co-authored-by: Cursor <cursoragent@cursor.com>
|
🚨 Contributor flagged. Click here for more info: Superagent Dashboard |
|
Superagent didn't find any vulnerabilities or security issues in this PR. |
|
Warning 🟨🟨🟨🟨🟨🟨🟨🟨🟨🟨🟨🟨 ⏸️ Gittensory review result - manual review recommendedReview updated: 2026-07-05 00:11:37 UTC
⏸️ Suggested Action - Manual Review Review summary Nits — 5 non-blocking
Review context
Contributor next steps
Signal definitions
🟩 Safe / merged · 🟦 Advisory · 🟨 Held for review · 🟥 Blocked / closed 💰 Earn for open-source contributions like this. Gittensor lets GitHub contributors earn for the work they already do — register to start earning →. Checked by Gittensory, a quiet PR intelligence layer for OSS maintainers.
|
Summary
co_+ 48 base62 chars) and Intercom access tokens (dG9rOm+ base64 body).(?![A-Za-z0-9_])/(?![A-Za-z0-9+/=])) consistent with the Twilio/Mapbox patterns from merged feat(enrichment): detect Discord bot tokens and Twilio SIDs in secret-scan #3263/feat(enrichment): detect Resend API keys and Mapbox secret tokens in secret-scan #3267.Motivation
Cohere and Intercom credentials are commonly leaked in env files and backend configs. The secret-scan analyzer already covers many AI/SaaS tokens but missed these documented formats.
Test plan
_suffixidentifier-continuation negativesecret-scan.test.tssuite passes (62 tests)Made with Cursor