Credential Access
- Category
- Privilege Escalation
- Confidence
- 88% confidence
- Finding
The skill explicitly recommends diagnostic commands that enumerate keychain contents and signing identities during troubleshooting. Even though framed as debugging, this can expose sensitive environment/configuration details and credential metadata in logs or agent output, which may aid credential discovery or lateral movement if logs are accessible.
- Content
md env | grep IDENTITY || echo "IDENTITY not in environment" # Layer 3: Signing script echo "=== Keychain state: ===" security list-keychains security find-identity -v
