Credential Access
- Category
- Privilege Escalation
- Confidence
- 70% confidence
- Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- Content
md ## GH_TOKEN Scoping Use a **fine-grained personal access token** scoped to the specific repo: - Grant: `contents: write` (push to feature branches), `actions: read` (view CI logs) - Do NOT grant org-wide or admin permissions - Set an expiration date and rotate after use
