critical
suspicious.env_credential_access
- Location
- dist/gateway-Cs3-_on9.js:76
- Finding
- Environment variable access combined with network send.
- Evidence
const home = process.env.HOME || process.env.USERPROFILE || "";
AdvisoryAudited by Static analysis on May 10, 2026.
Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal
const home = process.env.HOME || process.env.USERPROFILE || "";
const isDebug = () => !!process.env.QQBOT_DEBUG;
clientSecret: [REDACTED]
clientSecret = [REDACTED];
clientSecret: [REDACTED]
clientSecret: [REDACTED],
clientSecret: [REDACTED],
clientSecret: [REDACTED]