critical
suspicious.exposed_secret_literal
- Location
- bridge.js:469
- Finding
- File appears to expose a hardcoded API secret or token.
- Evidence
...(includePrivateKey && signer?.privateKey ? { privateKey: [REDACTED] } : {}),
AdvisoryAudited by Static analysis on May 16, 2026.
Detected: suspicious.exposed_secret_literal, suspicious.potential_exfiltration
...(includePrivateKey && signer?.privateKey ? { privateKey: [REDACTED] } : {}),private_key: [REDACTED],
privateKey: [REDACTED],
rawTranscript = await fs.readFile(entry.sessionFile, "utf8");