Scan text for exposed credentials, API keys, private keys, database URLs, and webhook secrets. COMMIT when nothing matches. NO_COMMIT on any finding. POST JSON {"response","agent_id"}.