Does mentioning a password in conversation trigger secret_leak?

No. secret_leak is anchored on what a live credential looks like, not on words like “password” or “API key” showing up in a sentence. A user asking how to reset their password, or an agent explaining what an API key is, doesn’t trip it.

What does trip it is the shape of an actual secret: a provider key prefix, a private-key block header, a session token, or an assignment like api_key= or password: followed by something that looks like a live value. That’s deliberate. A rule broad enough to catch every mention of the word “password” would flag a large share of ordinary support conversations and bury the real detections in noise.

It also means a fake or example credential shaped like a real one can still trigger a flag. The check reads the pattern, not whether the value actually works.

keep reading

More on this.

Two ways to run Tessary.

Tessary is an open-source agent reliability platform. Cloud and self-hosted run the same workflow on the OpenTelemetry traces your agent already emits.

Tessary Cloud

We host it for you. Send your first trace with nothing to deploy and no model key.

what's includedper organization
traces
10,000 per calendar month
stored trace data
1 GB
retention
30 days
model credit
$10, one-time, for triage and root-cause analysis
credit card
not required

Self-hosted Tessary

Run the open-source code on your own infrastructure with one command. Add your own model key for triage and root-cause analysis.

Self-host Tessary for me by following https://github.com/tessaryai/tessary/blob/main/setup.md

docker compose -f oci://docker.io/tessaryai/tessary:compose up -d -y