Detect hardcoded secrets in source and config. Reports masked previews, never the values.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts — it cannot prove the absence of malicious code.
Detect hardcoded secrets in source and config. Reports masked previews, never the values.