> Automatic secret detection: Scans for API keys, passwords, and tokens before committing

Surely this is done on-device right? Or is the prompt asking the LLM if there are secrets in the changes.

Arguably I trust Github / Gitlab / etc more than OpenAI / Anthropic / etc

The scanning is done on-device. I should've worded it better and said that it scans before any API calls. Too late to edit the post, unfortunately.