Credential Access
- Category
- Privilege Escalation
- Confidence
- 70% confidence
- Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- Content
md - `hodman messengers status` discovers the selected project's supported channels and current connection health without exposing credentials. - `hodman messengers mattermost setup|status` returns Mattermost prerequisites, state and the protected Project Settings deep link. Ask the user to enter the server URL and bot token in that UI; never ask them to paste the token into chat or print it in CLI output. - `hodman messengers slack setup|status` returns Slack Socket Mode prerequisites, state and the protected Project Settings deep link. Both Slack tokens remain UI-only and write-only. - `hodman messengers teams setup|status` returns Microsoft Teams prerequisites, state and the protected Project Settings deep link. Entra tenant ID, Microsoft App ID, client secret and access tokens remain UI-only/write-only and must never be accepted or printed by these commands. - `hodman messengers telegram ...` manages the selected project's platform Telegram channel. Use it when the user wants to talk to the Hodman project agent in Telegram, approve an observed chat, or send a bounded notification to an already approved chat. - `hodman connectors ...` manages tenant-level App Connections and their source-project grants. These grants allow one project's project CLI to be called by another project; they do not connect Telegram or broaden Inbox access.
