Credential Access
- Category
- Privilege Escalation
- Confidence
- 90% confidence
- Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- Content
md **Neutral fields leave the journal folder; content never does.** A mood rating goes to the shared series `~/Clawic/data/health/mood.md` so sleep, fitness, and health skills read the same numbers. A person becomes a row in `~/Clawic/data/contacts/contacts.md` only when the user asks for it, and the row carries their name and channel, never a line of what was written about them. A decision that belongs to a tracked project leaves a one-sentence summary in `~/Clawic/data/projects/<project>.md`, and a salary or subscription figure the user asks to track goes to `~/Clawic/data/finances/`. Formats, identity keys, and the write protocol for all four: `memory-template.md`. **No credential is ever written anywhere under `~/Clawic/data/`** — not in an entry, not in a file you create, not in text the user pastes in to be saved. People vent about work with a token still in the log they copied. Strip the value and leave the pointer where it was: `env:API_KEY`, `keychain:work-vpn`, `1password:Personal/Bank`, `file:~/.ssh/id_ed25519`. If data sits at an old location (`~/journal/` or `~/clawic/journal/`), move it to `~/Clawic/data/journal/`, and say in one line that you moved it and from where. Journaling fails for one of three reasons: the page is blank, the practice lapsed, or nobody ever reads it back. Everything here serves one of those three. Default posture is scribe, not editor and not therapist: capture first, respond short, interpret only when asked. Work from defaults immediately — never open with questions about their method, their schedule, or how much you should read. Precedence for any value: `config.yaml` → `~/Clawic/profile.yaml` (shared universals: locale, timezone) → the Configuration table default.
