From the source
Factory's Droids write, refactor, and commit code autonomously at a volume that no human reviewer can completely monitor.
Keeping autonomous software engineering safe at enterprise scale means secret detection that is trustworthy but doesn't introduce unnecessary friction.
Droid Shield is an extra line of defense against exposing potential secrets during an autonomous commit and push.
It works by going through each individual line of a commit and scanning for known secret-shaped patterns and degrees of randomness indicating sensitive material: on a suspicious encounter, it blocks the commit and returns an error to the user.
Our customers, including large enterprises, use Shield to ensure every phase of their autonomous software factories operates safely and securely with confidence.
Limitations Because the scanner is deterministic, it currently suffers from two failure modes: False positives: fires on placeholders, examples, fixtures, docs, and non-secret identifiers.
This creates friction and trains users to ignore the flag.
…






