Credential Access
- Category
- Privilege Escalation
- Confidence
- 96% confidence
- Finding
Referencing ~/.aws/credentials in combination with inline secret examples encourages direct interaction with a well-known credential store. In the context of a skill with exec and write capabilities, this is more dangerous because an agent may be induced to read, modify, or expose credential material from that location.
- Content
md export AWS_PROFILE=production aws ec2 describe-instances # ... # 配置多个Profile (在~/.aws/credentials中) # [production] # aws_access_key_id = AKIAXXXXXXXX # aws_secret_access_key = YOUR_API_KEY
