AbstractAbstract ReadonlycategoryWhich trap category this detector addresses
Abstract ReadonlyidUnique identifier for this detector
Abstract ReadonlynameHuman-readable name
Protected Abstract ReadonlytrapAbstractfindProtectedredactLast chance to alter matched text before it becomes Threat.evidence.
Evidence travels: into ScanResult, the CLI's JSON/SARIF output, audit
records, and whatever the caller logs. For most detectors the matched text
IS the finding and must be preserved verbatim. For a detector whose matches
are themselves secrets, echoing them would leak the credential into exactly
the CI logs and audit trails the scan was meant to protect. Override to
redact; the default is identity.
Sanitization is unaffected — it works from Threat.location, not evidence.
AbstractsanitizeReturn sanitized content with threats neutralized
Scan content and return any threats found
Optionaloptions: DetectorOptions
The interface every detector (pattern-based, ML, or custom) implements.