Triage possible secrets in the repository. Use when a security.secret_detected event arrives, or before sharing code. Confirms findings with scan_secrets, classifies them by rule id and orders remediation: revoke first, rewrite history only with consent.