Credential Access
- Category
- Privilege Escalation
- Confidence
- 90% confidence
- Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- Content
md Nothing under `~/Clawic/data/` ever holds a secret value — not the files named here, not files you create, not text the user pastes in and asks you to keep. Store the pointer in its place, in this shape: `<kind>:<locator>`. `env:TODOIST_TOKEN` · `keychain:work-mail` · `1password:Personal/Calendar` · `bitwarden:Work/VPN` · `file:~/.ssh/id_ed25519` · `profile:work` When the user pastes something to save — an automation recipe, an exported list, a login note, a meeting dial-in — replace each secret value before writing and leave the pointer visible: `api_token: <env:TODOIST_TOKEN>`. Say in one line that you did it.
