keyhog-core 0.5.50

keyhog-core: shared data model and detector specifications for the KeyHog secret scanner
Documentation
# Docs: https://apidocs.hashnode.com/
# Format: Personal Access Token (PAT) - alphanumeric string for GraphQL API
# Verify: POST to gql.hashnode.com with Authorization header
# Prefix: none (requires context anchoring)

[detector]
id = "hashnode-api-token"
name = "Hashnode Personal Access Token"
service = "hashnode"
severity = "medium"
ml = { match_mode = "lift", entropy_mode = "disabled", weight = 1.0, context_radius_lines = 5 }
match_confidence = { literal_prefix_weight = 0.35, context_anchor_weight = 0.20, entropy_weight = 0.20, high_entropy_partial_weight = 0.12, moderate_entropy_threshold = 3.0, moderate_entropy_weight = 0.05, low_entropy_penalty_floor = 2.0, low_entropy_min_match_length = 10, low_entropy_penalty_multiplier = 0.60, keyword_nearby_weight = 0.10, sensitive_file_weight = 0.10, companion_weight = 0.05, very_high_entropy_margin = 1.2999999999999998, named_anchor_floor = 0.55, assignment_context_multiplier = 1.0, string_literal_context_multiplier = 0.9, unknown_context_multiplier = 0.8, documentation_context_multiplier = 0.3, comment_context_multiplier = 0.4, test_context_multiplier = 0.3, encrypted_context_multiplier = 0.05, soft_context_suppression_threshold = 0.5, encrypted_context_suppression_threshold = 0.8, post_match = { placeholder_multiplier = 0.05, minimum_byte_diversity = 0.1, low_diversity_multiplier = 0.1, maximum_repeat_ratio = 0.8, degenerate_run_min_length = 10, degenerate_repeat_multiplier = 0.1, fixture_path_multiplier = 0.5, ml_context_reapply_below = 0.95 } }
# "pat" removed: over-broad (path/pattern/patch/compatible contain it) and
# redundant: the regex self-anchors on hashnode/personal_access_token (both
# still keywords), never on a bare "pat". Recall-neutral.
keywords = ["hashnode", "HASHNODE", "personal_access_token"]

[[detector.patterns]]
regex = '''(?:hashnode|HASHNODE|personal[_\-\s]*access[_\-\s]*token|HASHNODE[_\-\s]*TOKEN)[=:\s"\']+([a-f0-9]{32,})'''
description = "Hashnode Personal Access Token with context anchor"
group = 1

[[detector.tests]]
test_positive = "hashnode=1c4ce02cf2dfde95457503bd91cfa2fb"
test_negative = "hashnode=YOUR_API_KEY_HERE_PLACEHOLDER_VALUE"