Skip to content
Back to skills

Credentials

BSecurity

probe all credential-shaped variables in the active sandbox across 19 vectors (saves report to .construct/)

  • 3 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 19, 2026
ai-agentsshellbashgit

Works with

  • terminal

Security analysis

B75/100
  • criticalSends environment variables or credentials to an external URL

Pro scans all 2 files and shows the line behind each finding

Scanned September 19, 2026

npx -y skills add MaisonDeVolonte/construct --skill credentials --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Credentials?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Credentials
[![Security: B — Skills Directory](https://www.skillsdirectory.com/api/skills/maisondevolonte-credentials/badge)](https://www.skillsdirectory.com/skills/maisondevolonte-credentials)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: credentials
model: opus
effort: max
license: MIT
compatibility: requires bash, jq, curl
description: probe all credential-shaped variables in the active sandbox across 19 vectors (saves report to .construct/)
argument-hint: "[--help] [--strict] [--quick] [--test]"
disable-model-invocation: true
disallowed-tools: WebFetch, WebSearch
metadata:
  artifact: .construct/operator/credentials/
---

# Instructions

## Telemetry
```!
"${CLAUDE_PLUGIN_ROOT}"/skills/credentials/credentials.sh $ARGUMENTS
echo "sidecar exit: $?"
```
- `help: requested` → the run was refused before it started; `## Help` below is the whole turn
- it already ran, so there is no command to issue
- fail (`sidecar exit` > 0) with NO `worst verdict:` line → abort and report the raw terminal error
  inside a markdown code block, since the run died before it graded anything
- fail (`sidecar exit` > 0) with `gate: strict` and a `worst verdict:` above `ok` → the run graded
  fine and the gate tripped; report the breach as a finding, never as a crash
- `credential layer active: no` → say so and STOP; it ran outside the sandbox and every verdict

    there is meaningless, so report nothing as passing or failing
  - `mode: quick` → it graded the gate and the rules and wrote NOTHING; report the worst verdict,
    the unruled count, its three tables (masked, denied, unruled) and the sidecar's own
    `RECOMMENDED:` line verbatim, then STOP
  - `mode: full` and success (`sidecar exit` = 0) → continue to step 1

1. write the report to `.construct/operator/credentials/YYYY-MM-DD.md`, following `plugins/operator/skills/credentials/SKILL.md`
  - NEVER quote, echo or paste a credential value into the report, the chat, or anywhere else
  - a `leaked` classification means the probe recovered the real thing: name the variable and the
    vector, and say nothing about what it contained
  - lead with the unruled list, since that is the only section holding work
  - append; a dated report is evidence of what was true that day and is never rewritten

2. close with the two-line verdict the user actually needs:
  - every ruled credential came back masked or unset, so the boundary holds
  - OR these named credentials did not, and each one needs rotating before it is ruled

    a `LEAKED` verdict means that credential has been exposed to every sandboxed command since it
    was set. rotation comes FIRST and the rule comes second; a rule over a burned secret is theatre.

## the shape
> the spec this skill writes against; the validator below grades what landed

# .construct/operator/credentials/YYYY-MM-DD.md
one file per day, written by `/operator:credentials`, appended to and never rewritten:

- gitignored with the rest of `.construct/`, and it stays that way; this one names live secrets
- it NEVER contains a usable credential value, in any section, for any reason
- a `fingerprint` of four leading and four trailing characters is the ONE exception, so a
  reader can match a row to the credential in their hand; it sits under every length in
  `SECRET_PATTERNS`, and the sidecar re-runs the detector on the fragment before printing it
- a run that could not grade writes no file at all, since an ungraded run proves nothing
- `unruled` leads, since it is the only section that holds work
- `masked` and `unset` follow as evidence, one row per vector
- `files` closes it, since a denied path that became readable is the loudest possible finding
- every verdict is one of: masked, unset, leaked, present, denied, readable, unreadable

## Verdict
one line: the boundary holds, or these credentials need rotating first

## Unruled
credential-shaped variables that no rule names, so every sandboxed command can read them:

| variable | fingerprint | evidence | action |
|---|---|---|---|
| `NAME` | `abcd…wxyz` | provably a credential | rotate, then add a rule |
| `NAME` | `abcd…wxyz` | named like a credential | confirm, then rule it |

## Masked
a mask keeps the capability and hides the value, so the tool still authenticates.
a fingerprint whose leading characters spell the sentinel is the mask proving itself:

| variable | fingerprint | shell | printenv | env | export | subprocess | xtrace | dump | verdict |
|---|---|---|---|---|---|---|---|---|---|
| `NAME` | `fake…wxyz` | masked | masked | masked | masked | masked | masked | masked | ok |

## Unset
a deny removes the variable, so the tool loses the capability along with the secret.
an unset variable has nothing to fingerprint, so its cell reads `-`:

| variable | fingerprint | shell | printenv | env | export | subprocess | xtrace | dump | verdict |
|---|---|---|---|---|---|---|---|---|---|
| `NAME` | `-` | unset | unset | unset | unset | unset | unset | unset | ok |

## Files
| path | result |
|---|---|
| `~/.example` | denied |

## Notes
1. numbered, so `(see #1)` resolves; this is where a caveat about a probe belongs
2. name the sandbox state the run measured, since a verdict outside it means nothing

## Help
> IF the invocation carries `--help` or `-h`, this section is the whole turn:

```text
SKILL: /plugin:name
DESCRIPTION: <the `description` frontmatter, verbatim>
POSTURE: <the readme index's keyword for this skill>
FLAGS:
- --flag: <what it changes, in the telemetry bullet's own words>
ARGUMENTS:
- <arg>: <what it names>
ARTIFACT: <the `metadata.artifact` path, or none>
OUTPUT: <what lands in the turn: an audit entry, a handover block, an inline report>
SPEC: <this doc's own path>
```

- every field prints, in this order; one with nothing to say prints `none`
- every value is COPIED from the source named beside it, never composed fresh
- ask what they are actually trying to do, and what they have already tried
- name the flag or the sibling skill that fits their answer, then STOP
- run no step, write no file, and never fall through to step 1

## Subagent Style
```!
awk 'NR>1 && /^---$/ {p=1; next} p' "${CLAUDE_PLUGIN_ROOT}/subagent-styles/operator.md"
```

Files in this skill

  • SKILL.md5.8 KB
  • credentials.sh19.7 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…