Auditor
Payment gateway secret keys are read from the environment or a secret store, never committed.
1.0.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative; every model call stays under the engine prompt cap (spec.promptMaxChars = AUDITOR_AI_PROMPT_MAX_CHARS): assess mode sends the candidate set in parts and aggregates the verdicts (a HIGH in any part is a FAIL, an unsatisfied part is a FAIL).)
| { id: 'stripe-secret-live', re: /\b(?:sk|rk)_live_[0-9A-Za-z]{20,}\b/g, severity: 'high' }, |
| { id: 'stripe-webhook-secret', re: /\bwhsec_[0-9A-Za-z]{20,}\b/g, severity: 'high' }, |
| { id: 'gateway-secret-assignment', re: /\b(?:stripe|paypal|braintree|adyen|...)[\w.-]{0,40}?(?:secret|private[_-]?key|api[_-]?key|...)\w*\s*(?::|=|=>)\s*['"]([A-Za-z0-9+/=_.-]{16,})['"]/gi }, |
| // placeholders (x, *, your, changeme, example) and pk_ publishable keys never count; committed .env with a gateway secret -> FAIL |
The full script is disclosed on request in a read-only viewer (never published on GitHub); the attestation binds to this exact hash.