OptionalmaskEvidence?: booleanRedact matched text in Threat.evidence. Set for detectors whose
matches are secrets, so a scan can't leak what it just found.
OptionalreplaceText?: stringOptionalsanitizeMode?: "none" | "remove" | "replace"ReadonlycategoryWhich trap category this detector addresses
ReadonlyidUnique identifier for this detector
ReadonlynameHuman-readable name
Protected ReadonlytrapProtectedredactLast chance to alter matched text before it becomes Threat.evidence.
Evidence travels: into ScanResult, the CLI's JSON/SARIF output, audit
records, and whatever the caller logs. For most detectors the matched text
IS the finding and must be preserved verbatim. For a detector whose matches
are themselves secrets, echoing them would leak the credential into exactly
the CI logs and audit trails the scan was meant to protect. Override to
redact; the default is identity.
Sanitization is unaffected — it works from Threat.location, not evidence.
Return sanitized content with threats neutralized
Scan content and return any threats found
Optionaloptions: DetectorOptions
Generic detector driven by the pattern database. Replaces all hardcoded detector classes for pattern-based detection.