Intent-Code Divergence
Medium
- Confidence
- 94% confidence
- Finding
- The example logs `Connecting to database as $DB_USERNAME`, which exposes a secret-derived identifier in CI logs. While a username is typically less sensitive than a password or token, it still reveals account names and environment details that can aid reconnaissance or correlate with other leaked credentials.
