If you run coding agents that commit autonomously, this shows a practical pattern for cutting both false negatives and false-positive noise in secret scanning — small fine-tuned classifiers bracketing a deterministic regex scanner, at lower cost and latency than calling a frontier model, with the weights released so you can run it yourself.
“Droid Shield is an extra line of defense against exposing potential secrets during an autonomous commit and push.”
“We are releasing the model weights in the interest of compounding future work on software security and privacy.”
“The model must decide from context alone whether the scanner hit should stay blocked or be cleared as a false alarm.”
“We mask every known credential span across the entire window, so the model learns to judge without ever seeing the secret value(s).”
Checking sign-in…
Loading comments…