What is Tessary's secret_leak classifier?
It’s a deterministic check that reads everything an agent emits, including inner calls whose output reaches logs and downstream prompts, and flags credentials sitting where they shouldn’t.
It looks for the shape of a live credential: provider API keys, private-key block headers, session tokens, and password-like assignments such as api_key= or password:. Ordinary prose about passwords doesn’t trigger it, because the check is anchored on what a credential looks like rather than on the word showing up nearby.
A detection carries redacted evidence, the pattern name and a short snippet, never the secret itself. That is also the limit: it tells you a credential was emitted, not what the credential was or who now has it. The detection writes a finding, and triage rules on it.