Skip to content
| Marketplace
Sign in
Visual Studio Code>Other>Secrets-in-Output ScannerNew to Visual Studio Code? Get it now.
Secrets-in-Output Scanner

Secrets-in-Output Scanner

AtulHritik

| (0) | Free
Catches secrets an agent accidentally writes back out in commit messages and PR descriptions.
Installation
Launch VS Code Quick Open (Ctrl+P), paste the following command, and press enter.
Copied to clipboard
More Info

Secrets-in-Output Scanner

Catches secrets an agent accidentally writes back out in commit messages and PR descriptions.

Price: $9/seat-mo

Included free

  • Commit-message secret scanning with inline warning banner
  • One-click [REDACTED] redaction in the commit-message box

Unlocked with a license

  • PR-description field scanning
  • Terminal scrollback scanning (Shell Integration API, best-effort)

Getting a license

Open the Secrets-in-Output Scanner sidebar (activity bar icon) and click Get License. After purchase you'll receive a license key — paste it into the sidebar and click Activate License. Keys are machine-locked; use Move to another machine… in the sidebar before reinstalling on a new device.

Settings

  • secretsInOutputScanner.includeEntropyHeuristic (licensed only, default false): also flags generic high-entropy strings in addition to known secret formats.

Roadmap (not implemented yet)

  • Keychain/secret-manager fingerprint matching: planned as an unimplemented v3 feature to cut false positives against values already tracked in a user's secret manager.
  • Contact us
  • Jobs
  • Privacy
  • Manage cookies
  • Terms of use
  • Trademarks
  • Your Privacy Choices
  • Consumer Health Privacy
© 2026 Microsoft