job7 capitalize: BDR-057, BDR-026 update, LRN-108, journal

BDR-057: secrets by reference not by value; redact at capture, not just at
rest. Documents the two-part job7 posture (MCP ${VAR} expansion + rtk-rewrite
env-dump redaction) and flags the unreconciled contradiction with job6's
same-day (wrong) finding that ${VAR} expansion was unsupported at user scope.

BDR-026 updated: the backup-vector incident (2026-07-02) is closed at the
source rather than by repeated scrubbing — every native auto-backup taken
while the live file held the plaintext value was a fresh leak, so scrubbing
existing backups alone would have recurred forever.

LRN-108: `claude mcp add --env KEY=value` writes the value literally —
double- vs single-quoting around `${VAR}` is the entire difference between
a reference and a plaintext-forever config. The natural way to type the
flag (bash-expand it first) is exactly the trap.

Also refreshed .audit/scan-secrets-claude-home.json to the post-purge state
(15 residual hits, down from 18 pre-D).
This commit is contained in:
Bastien Chanot
2026-07-07 12:58:51 +02:00
parent 5d5b386b9c
commit eade4e603e
4 changed files with 65 additions and 100 deletions
+40 -100
View File
@@ -59,46 +59,6 @@
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/ide/20429.lock:generic-api-key:1"
},
{
"RuleID": "sourcegraph-access-token",
"Description": "Sourcegraph is a code search and navigation engine.",
"StartLine": 579,
"EndLine": 579,
"StartColumn": 17,
"EndColumn": 57,
"Match": "REDACTED\"",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/paste-cache/7d48f52c7499c1a7.txt",
"SymlinkFile": "",
"Commit": "",
"Entropy": 3.6628149,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/paste-cache/7d48f52c7499c1a7.txt:sourcegraph-access-token:579"
},
{
"RuleID": "sourcegraph-access-token",
"Description": "Sourcegraph is a code search and navigation engine.",
"StartLine": 590,
"EndLine": 590,
"StartColumn": 17,
"EndColumn": 57,
"Match": "REDACTED\"",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/paste-cache/7d48f52c7499c1a7.txt",
"SymlinkFile": "",
"Commit": "",
"Entropy": 3.7275672,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/paste-cache/7d48f52c7499c1a7.txt:sourcegraph-access-token:590"
},
{
"RuleID": "github-pat",
"Description": "Uncovered a GitHub Personal Access Token, potentially leading to unauthorized repository access and sensitive content exposure.",
@@ -119,26 +79,6 @@
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/27758e8c-36b5-4816-8141-8b07ba28b0c8.jsonl:github-pat:194"
},
{
"RuleID": "generic-api-key",
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
"StartLine": 10,
"EndLine": 10,
"StartColumn": 676,
"EndColumn": 730,
"Match": "nGITEA_TOKEN=REDACTED\\n",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/960bd2cf-7915-479e-a9d7-616a463789f9.jsonl",
"SymlinkFile": "",
"Commit": "",
"Entropy": 3.7282128,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/960bd2cf-7915-479e-a9d7-616a463789f9.jsonl:generic-api-key:10"
},
{
"RuleID": "jwt",
"Description": "Uncovered a JSON Web Token, which may lead to unauthorized access to web applications and sensitive user data.",
@@ -159,46 +99,6 @@
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/d71e6b88-7632-40e9-b7bc-830fb32fc464/tool-results/bsl3i4eop.txt:jwt:164"
},
{
"RuleID": "aws-access-token",
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
"StartLine": 652,
"EndLine": 652,
"StartColumn": 275,
"EndColumn": 294,
"Match": "REDACTED",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl",
"SymlinkFile": "",
"Commit": "",
"Entropy": 3.5464394,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl:aws-access-token:652"
},
{
"RuleID": "aws-access-token",
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
"StartLine": 652,
"EndLine": 652,
"StartColumn": 671,
"EndColumn": 690,
"Match": "REDACTED",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl",
"SymlinkFile": "",
"Commit": "",
"Entropy": 3.5464394,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl:aws-access-token:652"
},
{
"RuleID": "generic-api-key",
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",
@@ -325,6 +225,46 @@
],
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/f1c9c474-84b6-4484-b53f-25aad840e8fd.jsonl:aws-access-token:52"
},
{
"RuleID": "aws-access-token",
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
"StartLine": 652,
"EndLine": 652,
"StartColumn": 275,
"EndColumn": 294,
"Match": "REDACTED",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl",
"SymlinkFile": "",
"Commit": "",
"Entropy": 3.5464394,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl:aws-access-token:652"
},
{
"RuleID": "aws-access-token",
"Description": "Identified a pattern that may indicate AWS credentials, risking unauthorized cloud resource access and data breaches on AWS platforms.",
"StartLine": 652,
"EndLine": 652,
"StartColumn": 671,
"EndColumn": 690,
"Match": "REDACTED",
"Secret": "REDACTED",
"File": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl",
"SymlinkFile": "",
"Commit": "",
"Entropy": 3.5464394,
"Author": "",
"Email": "",
"Date": "",
"Message": "",
"Tags": [],
"Fingerprint": "/home/bchanot/.claude/projects/-home-bchanot-Documents-claude/4b5c02a9-3acd-4941-951e-134a569afe02.jsonl:aws-access-token:652"
},
{
"RuleID": "generic-api-key",
"Description": "Detected a Generic API Key, potentially exposing access to various services and sensitive operations.",