Trust
Supported detections
Detection is deterministic first: regex and parser-based extraction runs before any LLM call, and an LLM is only used to classify a genuinely ambiguous item, never to invent a relationship a deterministic pass didn't find. Coverage below is honest about what varies by framework and configuration style.
Credentials
| Known provider env-var patterns | Supported | OPENAI_API_KEY, ANTHROPIC_API_KEY, GITHUB_TOKEN, SLACK_TOKEN, SALESFORCE_CLIENT_ID, DATABASE_URL, SUPABASE_URL, STRIPE_SECRET_KEY, and similar. |
| Credential value storage | Not yet supported | By design: Wirecheck never stores secret values, only masked identifiers and metadata. |
MCP / integration configuration
| mcp.json / claude_desktop_config.json | Supported | Parsed as first-class MCP server configuration, including stdio/HTTP/SSE transports. |
| OAuth grant references in config | Supported | Linked to the credential and MCP node they authorize. |
Consumers (agents, workflows, jobs)
| SDK/framework imports | Supported | @modelcontextprotocol/*, OpenAI SDK, Anthropic SDK, LangChain, Vercel AI SDK, CrewAI, AutoGen, Mastra, OpenAI Agents SDK. |
| Webhooks, cron, GitHub Actions, Docker services | Supported | Used as consumer-side structural signals. |
| REST endpoints, database URLs, SaaS SDKs | Supported | Used to resolve who consumes a credential or integration. |
| Agent detection | Partial | A single bare LLM API call is deliberately not classified as an agent. Strong signals (agent SDK/class, tool definitions, system prompt, model + tools, agent loop, function calling, MCP client) are required for HIGH confidence; weaker combinations get MEDIUM confidence and show which signals were found. |
Scope and scale
| File types scanned | Supported | *.ts *.tsx *.js *.jsx *.py *.json *.yaml *.yml *.toml *.env.example, Dockerfile, docker-compose.yml, README.md. |
| Priority paths | Supported | /mcp /agents /agent /ai /automation /workflows /tools /scripts /config are scanned first. |
| Cross-repository dependency merging | Partial | A credential or integration referenced by name across multiple connected repositories is merged into one node; this depends on consistent naming, and does not yet resolve renamed references across repos. |
| UNKNOWN relationship detection | Supported | A reference the deterministic pipeline or LLM classifier cannot resolve stays visible as UNKNOWN rather than being dropped, on every scan, not just the first one. |
| Local/offline scanning | Not yet supported | Scans run against a connected GitHub repository; there's no `wirecheck scan .` for an uncommitted working tree yet. |
| Non-GitHub source control | Not yet supported | GitHub only: GitLab, Bitbucket, and self-hosted Git are not supported yet. |
See something that should be detected but isn't? Report it from the finding in the dashboard; every new detector is added against a real repository that hit the gap, with a regression test, not a feature wishlist.