Credential Access
- Category
- Privilege Escalation
- Confidence
- 60% confidence
- Finding
Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.
- Content
python findings = [] env = project_root / ".env" if not env.exists(): findings.append("WARN: .env file is missing") return findings text = env.read_text(encoding="utf-8") if "OPENAI_API_KEY" not in text and "DASHSCOPE_API_KEY" not in text:
