## Why Current discovery rotations spend substantial scanner time on query terms that have accumulated meaningful exposure without linking to a single strict-usable credential for any provider. Removing only this globally zero-yield cohort reduces avoidable discovery and scan work while preserving every query with demonstrated usable yield. ## What Changes - Remove 38 sufficiently exposed, globally zero-yield search terms from the configured GitHub, GitLab, DockerHub, npm, PyPI, package-git, and Postman rotations. - Remove query-scoped overrides whose corresponding query is retired. - Preserve source-operational sentinel queries and every term linked to at least one historical strict-usable credential for any provider. - Preserve historical queue rows, scan results, credential lineage, deduplication state, and all runtime concurrency limits. - Define a repeatable evidence rule for future pruning instead of using raw findings or provider-specific yield alone. ## Capabilities ### New Capabilities - `discovery-keyword-pruning`: Evidence-based, all-provider retirement of sufficiently tested zero-yield discovery terms. ### Modified Capabilities - `openai-discovery-coverage`: Retire the literal `openai` core query after its bounded rollout produced no strict-usable credential for any provider. ## Impact The change affects `app/config.yaml`, focused query-configuration tests, and authority-managed source rotation after a coordinated restart. It removes 219 configured query occurrences but introduces no schema migration, dependency, queue rewrite, credential recheck, detector change, or scan-concurrency change.