Auditor
No primary account number or CVV pattern appears in source, fixtures, migrations, seed data or log statements.
1.0.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative; every model call stays under the engine prompt cap (spec.promptMaxChars = AUDITOR_AI_PROMPT_MAX_CHARS): assess mode sends the candidate set in parts and aggregates the verdicts (a HIGH in any part is a FAIL, an unsatisfied part is a FAIL).)
| const CARD_RUN = /(?<![\w.\-+/#])(?:\d[ -]?){12,18}\d(?![\w.\-+/])/g; // 13-19 digits, single separators allowed |
| // FAIL if Luhn-valid, issuer-plausible and not a published test number |
| const CVV_NAME = /\b(?:cvv2?|cvc2?|cvn|card_?verification(?:_?(?:code|value|number))?|security_?code)\b/i; |
| // FAIL if declared as a column in a schema, migration, model, seed or SQL file |
| // FAIL if a log statement names card-number or CVV data |
The full script is disclosed on request in a read-only viewer (never published on GitHub); the attestation binds to this exact hash.