Use when a secret/credential scanner (gitleaks, trufflehog, hsb-snapshot, custom regex scanners, etc.) flags findings and you must decide whether each is a safe documentation/example placeholder or a potentially live secret — especially when deciding whether to grant a "skip the scan" / "--no-secrets-check"-style exception. Also use when asked to review scan output without revealing secret values.