job7 capitalize: BDR-057, BDR-026 update, LRN-108, journal
BDR-057: secrets by reference not by value; redact at capture, not just at
rest. Documents the two-part job7 posture (MCP ${VAR} expansion + rtk-rewrite
env-dump redaction) and flags the unreconciled contradiction with job6's
same-day (wrong) finding that ${VAR} expansion was unsupported at user scope.
BDR-026 updated: the backup-vector incident (2026-07-02) is closed at the
source rather than by repeated scrubbing — every native auto-backup taken
while the live file held the plaintext value was a fresh leak, so scrubbing
existing backups alone would have recurred forever.
LRN-108: `claude mcp add --env KEY=value` writes the value literally —
double- vs single-quoting around `${VAR}` is the entire difference between
a reference and a plaintext-forever config. The natural way to type the
flag (bash-expand it first) is exactly the trap.
Also refreshed .audit/scan-secrets-claude-home.json to the post-purge state
(15 residual hits, down from 18 pre-D).
This commit is contained in:
@@ -59,46 +59,6 @@
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/ide/20429.lock:generic-api-key:1"
|
||||
},
|
||||
{
|
||||
"RuleID": "sourcegraph-access-token",
|
||||
"Description": "Sourcegraph is a code search and navigation engine.",
|
||||
"StartLine": 579,
|
||||
"EndLine": 579,
|
||||
"StartColumn": 17,
|
||||
"EndColumn": 57,
|
||||
"Match": "REDACTED\"",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/paste-cache/7d48f52c7499c1a7.txt",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.6628149,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/paste-cache/7d48f52c7499c1a7.txt:sourcegraph-access-token:579"
|
||||
},
|
||||
{
|
||||
"RuleID": "sourcegraph-access-token",
|
||||
"Description": "Sourcegraph is a code search and navigation engine.",
|
||||
"StartLine": 590,
|
||||
"EndLine": 590,
|
||||
"StartColumn": 17,
|
||||
"EndColumn": 57,
|
||||
"Match": "REDACTED\"",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/paste-cache/7d48f52c7499c1a7.txt",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.7275672,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/paste-cache/7d48f52c7499c1a7.txt:sourcegraph-access-token:590"
|
||||
},
|
||||
{
|
||||
"RuleID": "github-pat",
|
||||
"Description": "Uncovered a GitHub Personal Access Token, potentially leading to unauthorized repository access and sensitive content exposure.",
|
||||
@@ -119,26 +79,6 @@
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/27758e8c-36b5-4816-8141-8b07ba28b0c8.jsonl:github-pat:194"
|
||||
},
|
||||
{
|
||||
"RuleID": "generic-api-key",
|
||||
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
|
||||
"StartLine": 10,
|
||||
"EndLine": 10,
|
||||
"StartColumn": 676,
|
||||
"EndColumn": 730,
|
||||
"Match": "nGITEA_TOKEN=REDACTED\\n",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/960bd2cf-7915-479e-a9d7-616a463789f9.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.7282128,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/960bd2cf-7915-479e-a9d7-616a463789f9.jsonl:generic-api-key:10"
|
||||
},
|
||||
{
|
||||
"RuleID": "jwt",
|
||||
"Description": "Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.",
|
||||
@@ -159,46 +99,6 @@
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/d71e6b88-7632-40e9-b7bc-830fb32fc464/tool-results/bsl3i4eop.txt:jwt:164"
|
||||
},
|
||||
{
|
||||
"RuleID": "aws-access-token",
|
||||
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
|
||||
"StartLine": 652,
|
||||
"EndLine": 652,
|
||||
"StartColumn": 275,
|
||||
"EndColumn": 294,
|
||||
"Match": "REDACTED",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.5464394,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl:aws-access-token:652"
|
||||
},
|
||||
{
|
||||
"RuleID": "aws-access-token",
|
||||
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
|
||||
"StartLine": 652,
|
||||
"EndLine": 652,
|
||||
"StartColumn": 671,
|
||||
"EndColumn": 690,
|
||||
"Match": "REDACTED",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.5464394,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl:aws-access-token:652"
|
||||
},
|
||||
{
|
||||
"RuleID": "generic-api-key",
|
||||
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
|
||||
@@ -325,6 +225,46 @@
|
||||
],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:aws-access-token:52"
|
||||
},
|
||||
{
|
||||
"RuleID": "aws-access-token",
|
||||
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
|
||||
"StartLine": 652,
|
||||
"EndLine": 652,
|
||||
"StartColumn": 275,
|
||||
"EndColumn": 294,
|
||||
"Match": "REDACTED",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.5464394,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl:aws-access-token:652"
|
||||
},
|
||||
{
|
||||
"RuleID": "aws-access-token",
|
||||
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
|
||||
"StartLine": 652,
|
||||
"EndLine": 652,
|
||||
"StartColumn": 671,
|
||||
"EndColumn": 690,
|
||||
"Match": "REDACTED",
|
||||
"Secret": "REDACTED",
|
||||
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl",
|
||||
"SymlinkFile": "",
|
||||
"Commit": "",
|
||||
"Entropy": 3.5464394,
|
||||
"Author": "",
|
||||
"Email": "",
|
||||
"Date": "",
|
||||
"Message": "",
|
||||
"Tags": [],
|
||||
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl:aws-access-token:652"
|
||||
},
|
||||
{
|
||||
"RuleID": "generic-api-key",
|
||||
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
|
||||
|
||||
Reference in New Issue
Block a user