Scan configurations, repositories, and environment files for exposed API credentials, private certificates, and authentication tokens.