Credential Access
- Category
- Privilege Escalation
- Confidence
- 70% confidence
- Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- Content
md For Supabase, distinguish token **capabilities** from **resource scope**: "Full access" to one project cannot create another project or manage its organization. A `/profile` 403 can mean a project-scoped token, not an invalid key. Explain the required scope; don't blindly ask for another Full access token. A passing account check doesn't prove every later endpoint permission. ### 4. Plan: `plan --json` Explain the steps by provider, in plain language, and call out:
