Credential Access
- Category
- Privilege Escalation
- Confidence
- 70% confidence
- Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- Content
md | **Viktor (viktor.com)** | Viktor workspaces | Integrations, Add Custom, MCP Server, paste the MCP URL and sign in; or Add Custom, API with base URL `https://app.issuebadge.com/api/v1` and a bearer token. See the `issuebadge-viktor` skill. | | **Agent CLI** | Shell-based agents | `pip install cli-anything-issuebadge`, set `ISSUEBADGE_API_KEY`, run `cli-anything-issuebadge --json <group> <command>` | OAuth discovery, if you implement a client yourself: an unauthenticated call to the MCP URL returns 401 with a `WWW-Authenticate` header pointing at `/.well-known/oauth-protected-resource`; that names `https://app.issuebadge.com` as the authorization server; read `/.well-known/oauth-authorization-server` there; register with `POST /oauth/register` (dynamic client registration); run the authorization-code flow with PKCE S256; exchange at `/oauth/token`. Access tokens last one year. Never ask the user to paste an API key into a chat when an OAuth-capable client is available. Never print, log or echo a key or token back to the user.
