T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/push-to-github.sh:90- Finding
Encrypted Credential Archives Are Uploaded Without Explicit Per-Upload Consent
- Content
View full analysis
/dev/null git push origin HEAD >/dev/null info "Pushed backup to $REMOTE" fi ) ``` ### Technical Analysis When `--secrets` is omitted, the script reads the manifest, locates the associated encrypted secrets archive, and assigns it to `SECRETS_PATH` automatically. It then copies that archive into the repository and pushes it to GitHub. This exceeds the minimum privilege and data-transfer scope required to push an operational archive. It also conflicts with the documented model that secrets archives are intended for local recovery by default and shoul ...[truncated 1643 chars]- Remediation
View remediation
