keyhog-scanner 0.5.41

keyhog-scanner: high-performance SIMD-accelerated secret detection engine
Documentation
schema_version = 1
detector_id = "github-webhook-secret"
service = "github"
severity = "high"

[[positive]]
text = "GITHUB_WEBHOOK_SECRET=N-hyshMKLyl_Pj_laamriw0VaNok"
credential = "N-hyshMKLyl_Pj_laamriw0VaNok"
reason = "Canonical anchor + synthesized body satisfying detector's primary regex."

[[positive]]
text = "GITHUB_WEBHOOK_SECRET=\"N-hyshMKLyl_Pj_laamriw0VaNok\""
credential = "N-hyshMKLyl_Pj_laamriw0VaNok"
reason = "Quoted-value variant of the canonical positive."

[[negative]]
text = "GITHUB_WEBHOOK_SECRET=YOUR_API_KEY_HERE_PLACEHOLDER_VALUE"
reason = "Placeholder-keyword body (suppression gate matches PLACEHOLDER prefix)."

[[negative]]
text = "GITHUB_WEBHOOK_SECRET=N-hysEXAMPLEEXAMPLEVaNok"
reason = "EXAMPLE token marker inside the body (suppression gate strips it)."

[[evasion]]
text = "# GITHUB_WEBHOOK_SECRET=N-hyshMKLyl_Pj_laamriw0VaNok"
credential = "N-hyshMKLyl_Pj_laamriw0VaNok"
reason = "Adversarial envelope (credential must still surface under this detector)."

[perf]
fixture_bytes = 4096
max_microseconds = 25000
note = "Standard single-file budget."

[scale]
fixture_bytes = 1048576
min_findings = 1
max_seconds = 2.0
note = "1 MiB filler + planted credential."