Limitation: scans text only — secrets visible in screenshots/images aren't seen
scan.go reads a fixed set of text extensions (.json, .jsonl, .txt, .log, .md, .env, …). Secrets that appear only as pixels — a password field or an API token visible in a screenshot, a photo of a credential, a PDF render — are invisible to the scanner.
Why it matters
For pipelines that attach screenshots to a report/issue (e.g. a bug recorder that captures the screen), the screenshot is often the highest-risk leak vector: a token or password can be plainly readable on screen even though it was never typed as text the scanner can see. A clean text scan can give false confidence that "no secrets are present."
Possible directions
- Optional OCR pass over
.png/.jpg/.pdf (e.g. Tesseract when available), then run the same pattern set over the extracted text. Gate behind a flag (--ocr) since it adds a dependency and cost.
- At minimum, when images are present in the scanned tree, surface a note in
results.json (e.g. images_unscanned: N) so callers know screenshots were not covered and a human should eyeball them.
Current mitigation
Consumers should pair sweeper with a "don't display secrets while recording" policy and treat a clean text scan as necessary but not sufficient when images are involved.
Filed from the A2000 recorder→issue pipeline, which attaches screenshots to the GitHub issue and relies on sweeper for the text scan.
Limitation: scans text only — secrets visible in screenshots/images aren't seen
scan.goreads a fixed set of text extensions (.json,.jsonl,.txt,.log,.md,.env, …). Secrets that appear only as pixels — a password field or an API token visible in a screenshot, a photo of a credential, a PDF render — are invisible to the scanner.Why it matters
For pipelines that attach screenshots to a report/issue (e.g. a bug recorder that captures the screen), the screenshot is often the highest-risk leak vector: a token or password can be plainly readable on screen even though it was never typed as text the scanner can see. A clean text scan can give false confidence that "no secrets are present."
Possible directions
.png/.jpg/.pdf(e.g. Tesseract when available), then run the same pattern set over the extracted text. Gate behind a flag (--ocr) since it adds a dependency and cost.results.json(e.g.images_unscanned: N) so callers know screenshots were not covered and a human should eyeball them.Current mitigation
Consumers should pair sweeper with a "don't display secrets while recording" policy and treat a clean text scan as necessary but not sufficient when images are involved.
Filed from the A2000 recorder→issue pipeline, which attaches screenshots to the GitHub issue and relies on sweeper for the text scan.