feat(enrichment): detect Pinecone and Tavily API keys in secret-scan#3273
Conversation
|
🚨 Contributor flagged. Click here for more info: Superagent Dashboard |
|
Superagent didn't find any vulnerabilities or security issues in this PR. |
|
Warning 🟨🟨🟨🟨🟨🟨🟨🟨🟨🟨🟨🟨 ⏸️ Gittensory review result - manual review recommendedReview updated: 2026-07-05 00:37:19 UTC
⏸️ Suggested Action - Manual Review Review summary Nits — 3 non-blocking
Review context
Contributor next steps
Signal definitions
🟩 Safe / merged · 🟦 Advisory · 🟨 Held for review · 🟥 Blocked / closed 💰 Earn for open-source contributions like this. Gittensor lets GitHub contributors earn for the work they already do — register to start earning →. Checked by Gittensory, a quiet PR intelligence layer for OSS maintainers.
|
Add high-confidence pcsk_{label}_{secret} and tvly- token patterns with
identifier-continuation tail guards and dedicated regression tests.
Co-authored-by: Cursor <cursoragent@cursor.com>
ad840e8 to
3181cbb
Compare
Summary
pcsk_{5-6 char label}_{63 char secret}) and Tavily API keys (tvly-+ base62 body).Motivation
Pinecone and Tavily credentials are commonly leaked in AI agent configs and env files. The secret-scan analyzer covers many AI/SaaS tokens but missed these documented formats.
Test plan
_suffixcontinuation negativesecret-scan.test.tssuite passes (66 tests)Made with Cursor