Does secret_leak see credentials in inner tool calls, or only the final response?

Everything, not just the final answer. secret_leak reads every span in a trace, including the inner tool calls a user never sees, and checks any output that reaches logs or gets fed into a downstream prompt as it happens.

That matters because a leaked credential rarely shows up in the polished final message. It shows up in the tool call that read a config file, the intermediate step that echoed a header back into the agent’s own context, or a retry that logged a raw response after a failed request. A classifier that only checked the final response would miss most of that.

The tradeoff is the same one every Tessary classifier makes: it’s a narrow, cheap check on one property, run on every span instead of a sample, not a review of what the trace as a whole was trying to do.

keep reading

More on this.

Two ways to run Tessary.

Tessary is an open-source agent reliability platform. Cloud and self-hosted run the same workflow on the OpenTelemetry traces your agent already emits.

Tessary Cloud

We host it for you. Send your first trace with nothing to deploy and no model key.

what's includedper organization
traces
10,000 per calendar month
stored trace data
1 GB
retention
30 days
model credit
$10, one-time, for triage and root-cause analysis
credit card
not required

Self-hosted Tessary

Run the open-source code on your own infrastructure with one command. Add your own model key for triage and root-cause analysis.

Self-host Tessary for me by following https://github.com/tessaryai/tessary/blob/main/setup.md

docker compose -f oci://docker.io/tessaryai/tessary:compose up -d -y