critical
suspicious.exposed_secret_literal
- Location
- tests/unit/security.test.ts:202
- Finding
- File appears to expose a hardcoded API secret or token.
- Evidence
const { redacted } = redactSecrets('Authorization: Bearer [REDACTED]');
AdvisoryAudited by Static analysis on May 16, 2026.
Detected: suspicious.exposed_secret_literal, suspicious.install_untrusted_source, suspicious.nonstandard_network
const { redacted } = redactSecrets('Authorization: Bearer [REDACTED]');"baseUrl": "http://127.0.0.1:11434"
const ws = new WebSocket('ws://127.0.0.1:18789/acp', {