Credential Access
High
- Category
- Privilege Escalation
- Content
- CMIC does NOT upload reports unless you configure `--upload-url` - CMIC does NOT configure an LLM endpoint unless you set `--use-llm` - `auto` may execute a locally resolved external scanner; use `--engine native` to prevent that - Does NOT access credentials or SSH configs as scan targets unless they are under the path you explicitly scan ## 工作流程
- Confidence
- 70% confidence
- Finding
- Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
