Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
23 commits
Select commit Hold shift + click to select a range
6fb4006
fix(pi): make scanner output redaction linear
yashrajp22 Oct 5, 2026
97e292c
Merge branch 'main' into yashraj/fix-pi-redaction-runtime-20261005
github-actions[bot] Oct 5, 2026
84b6c78
Merge branch 'main' into yashraj/fix-pi-redaction-runtime-20261005
github-actions[bot] Oct 5, 2026
752334c
Merge branch 'main' into yashraj/fix-pi-redaction-runtime-20261005
github-actions[bot] Oct 5, 2026
36ede42
Merge branch 'main' into yashraj/fix-pi-redaction-runtime-20261005
github-actions[bot] Oct 5, 2026
f6f47d8
Merge branch 'main' into yashraj/fix-pi-redaction-runtime-20261005
github-actions[bot] Oct 5, 2026
5ebda66
Merge branch 'main' into yashraj/fix-pi-redaction-runtime-20261005
github-actions[bot] Oct 5, 2026
8256dcd
Merge branch 'main' into yashraj/fix-pi-redaction-runtime-20261005
github-actions[bot] Oct 5, 2026
cd20c62
Merge branch 'main' into yashraj/fix-pi-redaction-runtime-20261005
github-actions[bot] Oct 5, 2026
31fdf49
test(pi): enforce synchronous redaction runtime budget
yashrajp22 Oct 5, 2026
6cfb020
Merge branch 'main' into yashraj/fix-pi-redaction-runtime-20261005
github-actions[bot] Oct 5, 2026
53fb1f7
Merge branch 'main' into yashraj/fix-pi-redaction-runtime-20261005
github-actions[bot] Oct 5, 2026
4ba9a2d
Merge branch 'main' into yashraj/fix-pi-redaction-runtime-20261005
github-actions[bot] Oct 5, 2026
5103abe
Merge branch 'main' into yashraj/fix-pi-redaction-runtime-20261005
github-actions[bot] Oct 5, 2026
ad02245
Merge branch 'main' into yashraj/fix-pi-redaction-runtime-20261005
github-actions[bot] Oct 5, 2026
3941940
Merge branch 'main' into yashraj/fix-pi-redaction-runtime-20261005
github-actions[bot] Oct 5, 2026
cd77729
Merge branch 'main' into yashraj/fix-pi-redaction-runtime-20261005
github-actions[bot] Oct 6, 2026
568b0ee
Merge branch 'main' into yashraj/fix-pi-redaction-runtime-20261005
github-actions[bot] Oct 6, 2026
405d56a
Merge branch 'main' into yashraj/fix-pi-redaction-runtime-20261005
github-actions[bot] Oct 6, 2026
d1f8057
Merge branch 'main' into yashraj/fix-pi-redaction-runtime-20261005
github-actions[bot] Oct 6, 2026
eef43f1
Merge branch 'main' into yashraj/fix-pi-redaction-runtime-20261005
github-actions[bot] Oct 6, 2026
9f2a048
Merge branch 'main' into yashraj/fix-pi-redaction-runtime-20261005
github-actions[bot] Oct 6, 2026
1d908c2
Merge branch 'main' into yashraj/fix-pi-redaction-runtime-20261005
github-actions[bot] Oct 6, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 2 additions & 2 deletions extensions/skillspector.ts
Original file line number Diff line number Diff line change
Expand Up @@ -41,8 +41,8 @@ function redactSecrets(value: string): string {
return value
.replace(/(sk-ant-[A-Za-z0-9_-]{12,})/g, "[REDACTED_ANTHROPIC_KEY]")
.replace(/(sk-[A-Za-z0-9_-]{20,})/g, "[REDACTED_OPENAI_KEY]")
.replace(/([A-Za-z0-9_]*API_KEY[=:]\s*)[^\s]+/gi, "$1[REDACTED]")
.replace(/([A-Za-z0-9_]*TOKEN[=:]\s*)[^\s]+/gi, "$1[REDACTED]");
// Start only at a word boundary; retrying at every character is quadratic.
.replace(/\b([A-Za-z0-9_]*(?:API_KEY|TOKEN)[=:]\s*)[^\s]+/gi, "$1[REDACTED]");
}

function truncateText(value: string, maxChars = 12000): { text: string; truncated: boolean } {
Expand Down
32 changes: 32 additions & 0 deletions tests/unit/test_pi_extension.mjs
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ import { copyFileSync, existsSync, linkSync, mkdirSync, mkdtempSync, readFileSyn
import { registerHooks } from "node:module";
import { tmpdir } from "node:os";
import { dirname, join, resolve } from "node:path";
import { performance } from "node:perf_hooks";
import test from "node:test";
import { pathToFileURL } from "node:url";

Expand Down Expand Up @@ -74,6 +75,37 @@ test("uses installed absolute executable and preserves scan arguments without ou
assert.equal(ctx.calls[0].options.cwd, ctx.workspace);
});

test("redacts long scanner output without retrying every word character", { timeout: 5000 }, async (t) => {
Comment thread
yashrajp22 marked this conversation as resolved.
const ctx = await setup(t, () => ({
code: 0,
stdout: "A".repeat(100_000),
stderr: "B".repeat(100_000),
}));
const started = performance.now();
const result = await ctx.scan();
const elapsed = performance.now() - started;
assert.ok(elapsed < 1000, `redaction took ${elapsed.toFixed(1)} ms`);
assert.equal(result.details.stdoutTruncated, true);
assert.equal(result.details.stderrTruncated, true);
assert.ok(result.content[0].text.length < 19_000);
});

test("redacts complete secrets before truncating at display boundaries", async (t) => {
const ctx = await setup(t, () => ({
code: 0,
stdout: " ".repeat(11_990) + "sk-" + "x".repeat(32),
stderr: "NPM_TOKEN=synthetic-token\nCUSTOM_API_KEY: synthetic-key\napi_key=lower-key",
}));
const result = await ctx.scan();
const text = result.content[0].text;
for (const secret of ["sk-", "synthetic-token", "synthetic-key", "lower-key"]) {
assert.equal(text.includes(secret), false);
}
assert.match(text, /NPM_TOKEN=\[REDACTED\]/);
assert.match(text, /CUSTOM_API_KEY: \[REDACTED\]/);
assert.match(text, /api_key=\[REDACTED\]/);
});

test("finds the Windows virtualenv executable without a PATH fallback", async (t) => {
const ctx = await setup(t);
rmSync(ctx.bin);
Expand Down