Trust

Supported detections

Detection is deterministic first: regex and parser-based extraction runs before any LLM call, and an LLM is only used to classify a genuinely ambiguous item, never to invent a relationship a deterministic pass didn't find. Coverage below is honest about what varies by framework and configuration style.

Credentials

Known provider env-var patternsSupportedOPENAI_API_KEY, ANTHROPIC_API_KEY, GITHUB_TOKEN, SLACK_TOKEN, SALESFORCE_CLIENT_ID, DATABASE_URL, SUPABASE_URL, STRIPE_SECRET_KEY, and similar.
Credential value storageNot yet supportedBy design: Wirecheck never stores secret values, only masked identifiers and metadata.

MCP / integration configuration

mcp.json / claude_desktop_config.jsonSupportedParsed as first-class MCP server configuration, including stdio/HTTP/SSE transports.
OAuth grant references in configSupportedLinked to the credential and MCP node they authorize.

Consumers (agents, workflows, jobs)

SDK/framework importsSupported@modelcontextprotocol/*, OpenAI SDK, Anthropic SDK, LangChain, Vercel AI SDK, CrewAI, AutoGen, Mastra, OpenAI Agents SDK.
Webhooks, cron, GitHub Actions, Docker servicesSupportedUsed as consumer-side structural signals.
REST endpoints, database URLs, SaaS SDKsSupportedUsed to resolve who consumes a credential or integration.
Agent detectionPartialA single bare LLM API call is deliberately not classified as an agent. Strong signals (agent SDK/class, tool definitions, system prompt, model + tools, agent loop, function calling, MCP client) are required for HIGH confidence; weaker combinations get MEDIUM confidence and show which signals were found.

Scope and scale

File types scannedSupported*.ts *.tsx *.js *.jsx *.py *.json *.yaml *.yml *.toml *.env.example, Dockerfile, docker-compose.yml, README.md.
Priority pathsSupported/mcp /agents /agent /ai /automation /workflows /tools /scripts /config are scanned first.
Cross-repository dependency mergingPartialA credential or integration referenced by name across multiple connected repositories is merged into one node; this depends on consistent naming, and does not yet resolve renamed references across repos.
UNKNOWN relationship detectionSupportedA reference the deterministic pipeline or LLM classifier cannot resolve stays visible as UNKNOWN rather than being dropped, on every scan, not just the first one.
Local/offline scanningNot yet supportedScans run against a connected GitHub repository; there's no `wirecheck scan .` for an uncommitted working tree yet.
Non-GitHub source controlNot yet supportedGitHub only: GitLab, Bitbucket, and self-hosted Git are not supported yet.

See something that should be detected but isn't? Report it from the finding in the dashboard; every new detector is added against a real repository that hit the gap, with a regression test, not a feature wishlist.