Secret Sweeper
A diff lands on the board. Flag every line that is a live leaked credential. Then pick the correct first remediation step. Placeholders, public keys and revoked tokens are bait β flagging them costs you.
Core loop
Flag lines β Enter to sweep β learn β route the fix. Under ten seconds when you know it.
Flag lines β Enter to sweep β learn β route the fix. Under ten seconds when you know it.
Run out of shields and you are out.
A missed live secret is a breach. A false positive just burns points and your combo. You get more shields at the lower tiers.
A missed live secret is a breach. A false positive just burns points and your combo. You get more shields at the lower tiers.
Combo
A perfect diff (every leak, zero false positives) stacks the multiplier up to 3Γ. One sloppy sweep resets it.
A perfect diff (every leak, zero false positives) stacks the multiplier up to 3Γ. One sloppy sweep resets it.
Controls
1β9 toggle a line Β· Enter sweep / continue Β· 1β4 pick a remediation Β· tap anything on touch.
Scoring: leak found +100 Β· false positive β60 Β· missed leak β120 & a breach Β· perfect diff +50Γcombo Β· remediation +120 / β50 Β· leftover seconds Γ6. Everything is then multiplied by the tier: Γ0.6 at 100 up to Γ1.6 at 500.
β
β
Click a line, or press its number. Flag only live credentials.
What this drills
- Push protection reach. Partner/provider patterns are blocked at push time; generic passwords and base64 blobs are not, unless you author a custom pattern with push protection enabled on it.
- Custom patterns. Regex plus optional before/after context, defined at repo, org or enterprise scope β always dry-run before enabling.
- Revoke before purge. Rotating the credential is always step one. Rewriting history does not un-leak anything.
- History, forks and cached views. Deleting the line in a new commit leaves the secret in every earlier commit, every fork, and cached commit views.
- Validity checks & partner patterns. Active vs inactive tokens, and provider notification for partner patterns.
- False positives that look lethal. Public keys, placeholders, documentation example keys, password hashes, encrypted SOPS/Ansible-vault blobs, Key Vault URIs, passwordless connection strings.
- Secrets in CI/CD. Pipeline YAML, .npmrc/nuget.config, Dockerfile ARG defaults, log masking and the tricks that defeat it.
- Bypass & audit. "It is only a test" is a logged bypass, not a suppression. Delegated bypass routes it to a reviewer.
Whiteboards: Secret Scanning Β· Enablement, Policy & Rollout Β· Dependabot & Supply Chain Β· The Pizza Parlor