T09 · Insecure Skill Coding Practices
- Location
scripts/scan.sh:84- Finding
Credential Disclosure Through Unredacted Git Remote URLs
- Content
View full analysis
/dev/null || echo "") remote_url="" [[ -n "$remote" ]] && remote_url=$(git -C "$dir" config "remote.${remote}.url" 2>/dev/null || echo "") # Dirty count: modified + untracked files dirty_count=$(git -C "$dir" status --porcelain 2>/dev/null | wc -l | tr -d ' ') # Upstream tracking: ahead/behind counts has_upstream=false ahead=0 behind=0 if git -C "$dir" rev-parse --abbrev-ref "@{u}" >/dev/null 2>&1; then has_upstream=true counts=$(git -C "$dir" rev-list --count --left-right "HEAD...@{u}" 2>/dev/null || echo "0 0") ahead=$(echo "$counts" | awk '{print $1}') behind=$(echo "$counts" | awk '{print $2}') fi # Comma separator between objects $first && first=false || echo "," # Build JSON object path_clean="${dir%/}" name=$(basename "$dir") printf ' {"path":"%s","name":"%s","branch":"%s","remote":"%s","remote_url":"%s","dirty_count":%d,"has_upstream":%s,"ahead":%d,"behind":%d' \ "$(json_escape "$path_clean")" \ "$(json_escape "$name")" \ "$(json_escape "$branch")" \ "$(json_escape "$remote")" \ "$(json_escape "$remote_url")" \ ``` ### Technical Analysis The script reads the complete URL associated with the current branch's Git remote and emits it into the JSON report. Git supports remote URLs containing user information, passwords, personal access tokens, or other embedded credentials, for example: ```text https://username:token@example.com/organization/repository.git ``` No credential detection or redaction occurs before `remote_url` is passed to `printf`. The synchronization logic only needs remote identity and repository status; exposing authentication material is not required for the declared workflow. Because the report is intended fo ...[truncated 1231 chars]- Remediation
View remediation
