Credential Access
- Category
- Privilege Escalation
- Confidence
- 70% confidence
- Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- Content
md | Item | What this skill needs | |---|---| | Credentials | `VERCEL_TOKEN`: an access token you create in the Vercel dashboard, scoped to the one team. Env var only; §1 passes it to curl on stdin, never in argv (visible in `ps`). Never committed. | | Network out | `api.vercel.com` (read-only GET), `openapi.vercel.sh` (schema), a DoH resolver. The §4 relay also calls **your** forward URL. | | Data persisted | Only the §4 relay: raw webhook events in `SPOOL_DIR` until a 2xx forward, then deleted. If events carry personal data (emails, names), you need a legal basis, keep only the fields you forward, and purge `*.bad` quarantine files on a schedule you set (suggested: 7 days). | | Writes | None in §1-§3, §5. Every deploy command is run by you, not by this skill. |
