@@ -162,6 +162,7 @@ describe("sanitizer", () => {
162162 [ "slack-token-app" , `xoxa-${ "abc123" . repeat ( 2 ) } ` ] ,
163163 [ "slack-token-refresh" , `xoxr-${ "abc123" . repeat ( 2 ) } ` ] ,
164164 [ "slack-token-session" , `xoxs-${ "abc123" . repeat ( 2 ) } ` ] ,
165+ [ "age-secret-key" , `AGE-SECRET-KEY-1${ "A" . repeat ( 58 ) } ` ] ,
165166 ] ) ( "scanForSecrets detects %s embedded in prose" , ( expectedName , sampleSecret ) => {
166167 const body = `Note from setup: my key is ${ sampleSecret } . Do not share.` ;
167168 const warnings = scanForSecrets ( body , "/tmp/leaky.md" ) ;
@@ -192,6 +193,18 @@ describe("sanitizer", () => {
192193 expect ( warnings . some ( ( w ) => w . includes ( "anthropic-api-key" ) ) ) . toBe ( true ) ;
193194 } ) ;
194195
196+ test ( "redactSecretLiterals rewrites an age secret key pasted as a whole JSON value" , ( ) => {
197+ // An MCP env block like { AGENTSYNC_KEY: "AGE-SECRET-KEY-1..." } must be
198+ // redacted, not just aborted, so the rest of the structured config survives.
199+ const ageKey = `AGE-SECRET-KEY-1${ "A" . repeat ( 58 ) } ` ;
200+ const input = { env : { AGENTSYNC_KEY : ageKey } } ;
201+ const result = redactSecretLiterals ( input ) ;
202+ const value = result . value as { env : { AGENTSYNC_KEY : string } } ;
203+ expect ( value . env . AGENTSYNC_KEY ) . not . toBe ( ageKey ) ;
204+ expect ( value . env . AGENTSYNC_KEY . startsWith ( "$AGENTSYNC_REDACTED" ) ) . toBeTrue ( ) ;
205+ expect ( result . warnings . length ) . toBeGreaterThan ( 0 ) ;
206+ } ) ;
207+
195208 test ( "scanForSecrets does NOT false-positive on long alphanumeric runs in prose" , ( ) => {
196209 const prose =
197210 "Commit 0123456789abcdef0123456789abcdef0123456789abcdef contains a fix. " +
0 commit comments