Skip to content

Text-only scanning — secrets visible in screenshots/images aren't detected (opt-in OCR + images_unscanned note?) #2

Description

@VestedJosh

Limitation: scans text only — secrets visible in screenshots/images aren't seen

scan.go reads a fixed set of text extensions (.json, .jsonl, .txt, .log, .md, .env, …). Secrets that appear only as pixels — a password field or an API token visible in a screenshot, a photo of a credential, a PDF render — are invisible to the scanner.

Why it matters

For pipelines that attach screenshots to a report/issue (e.g. a bug recorder that captures the screen), the screenshot is often the highest-risk leak vector: a token or password can be plainly readable on screen even though it was never typed as text the scanner can see. A clean text scan can give false confidence that "no secrets are present."

Possible directions

  • Optional OCR pass over .png/.jpg/.pdf (e.g. Tesseract when available), then run the same pattern set over the extracted text. Gate behind a flag (--ocr) since it adds a dependency and cost.
  • At minimum, when images are present in the scanned tree, surface a note in results.json (e.g. images_unscanned: N) so callers know screenshots were not covered and a human should eyeball them.

Current mitigation

Consumers should pair sweeper with a "don't display secrets while recording" policy and treat a clean text scan as necessary but not sufficient when images are involved.

Filed from the A2000 recorder→issue pipeline, which attaches screenshots to the GitHub issue and relies on sweeper for the text scan.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions