cerbia.core.scanners.CanaryLeakScanner looks for configured marker tokens in text, including normalized representations that hide a token with HTML entities, URL encoding, or zero-width characters. Use it to detect a marker that should never appear in generated content.
| Parameter | Default | Meaning |
|---|---|---|
|
|
Tokens to monitor. An empty list produces no findings. |
|
|
Minimum contiguous token fragment considered a partial leak. |
|
|
Compare tokens after lowercasing. |
|
|
Finding severity. |
|
|
Finding action. |
|
|
Accepted content types; |
An exact token yields risk 1.0; a partial fragment without an exact match yields risk 0.75. The scanner returns match spans for detected fragments.
scanners:
- scanner: cerbia.core.scanners.CanaryLeakScanner
init_args:
canary_tokens: ["marker-12345678"]
case_insensitive: true