IH-CRED-002highCredentials

Hard-coded secret

Private keys and live tokens checked into a skill can be copied by anyone who reads the skill.

What does IH-CRED-002 flag?

Flags secrets written into the skill: private key headers, known token formats, and long random-looking values assigned to secret-like names.

  • PEM private key headers (RSA, EC, OpenSSH, DSA and encrypted keys).
  • AWS access key IDs that start with AKIA, GitHub tokens (ghp_, github_pat_, gho_) and Slack tokens (xoxb-, xoxa-, xoxp-, xoxr-, xoxs-).
  • A quoted value of 20 or more characters assigned to a name such as api_key, secret, token, password, access_key or private_key, when its Shannon entropy is at least 4 bits per character.

Why it matters

Anyone who downloads the skill gets the key. A skill that ships someone's live key is also a warning sign in itself. Evidence in reports keeps only the first four characters, so the report does not leak the secret again.

Severity: High (40 points). A private key header is reported as critical (100 points), which forces a block verdict.

Examples

Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.

High-entropy value
Flagged
api_key = "<20+ random characters>"
Short placeholder
Not flagged
token = "short"
Public key
Not flagged
-----BEGIN PUBLIC KEY-----

Can IH-CRED-002 fire on a safe skill?

  • Documented example keys, such as the sample AWS key IDs in vendor docs, match the format.
  • Long random test fixtures or hashes assigned to a name like token.

How do I fix an IH-CRED-002 finding?

  • Remove the secret and rotate it. Deleting it from the latest version is not enough, because copies and history keep it.
  • Load secrets from the environment or a secret store.

CLI guidance: Remove the secret, rotate it, and load it from the environment or a secret store.

How do I tune or allow IH-CRED-002?

For a known test fixture, exclude the fixture file with ignoreGlobs rather than turning the rule off.

{
  "ignoreGlobs": [
    "docs/known-example.md"
  ]
}

Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-CRED-002.

What can IH-CRED-002 miss?

  • Token formats that are not on the list, which covers most providers.
  • Secrets that are split, encoded, or shorter than 20 characters.
  • Secrets inside binary files or files over the size limit.

No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.

Scores and thresholds shown are the CLI defaults; your config can change them. List every rule from the terminal with ironheights rules list.

All 35 rules