What does IH-CRED-003 flag?
Flags instructions that ask the user to paste a secret into the chat, or tell the agent to store, print or log a secret into memory, context or the transcript.
- ask the user for, paste your, echo, print, log, store or save, followed within about 80 characters by api key, token, password, secret or seed phrase, and then by chat, memory, context, transcript or conversation.
- ask the user to paste, enter or provide their api key, token, password or secret.
- Lines that point to an environment variable are skipped unless they also ask for the secret.
Why it matters
Transcripts and agent memory get copied, synced and fed back to models. A secret placed there leaves the user's control. Writing rules into long-term memory is a reported abuse technique.
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-CRED-003 fire on a safe skill?
- A warning such as “never store your api key in memory” can match.
- Setup flows that genuinely need a one-time token typed into a trusted interface.
How do I fix an IH-CRED-003 finding?
- Tell the user to set an environment variable or use the secret store.
- Never echo, log or repeat the value.
CLI guidance: Tell the user to set an environment variable or use the secret store, and do not echo the value.
How do I tune or allow IH-CRED-003?
Rewrite warnings so they name the safe path (environment variable or secret store). If a match is still a false positive, lower the severity for that project with ruleOverrides.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-CRED-003.
What can IH-CRED-003 miss?
- Requests phrased differently or in another language.
- Asking for a secret through a website or form instead of the chat.
- Asking the user to send money or approve a transaction, which is not a secret request.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
Related rules
ironheights rules list.