From 0db3515dc53f9083141abf55767930a084927bfc Mon Sep 17 00:00:00 2001 From: utkusen Date: Thu, 2 Apr 2026 21:46:13 +0100 Subject: [PATCH] adding hardcoded secrets --- .../skills/sast-hardcodedsecrets/SKILL.md | 408 ++++++++++++++++++ 1 file changed, 408 insertions(+) create mode 100644 sast-files/.agents/skills/sast-hardcodedsecrets/SKILL.md diff --git a/sast-files/.agents/skills/sast-hardcodedsecrets/SKILL.md b/sast-files/.agents/skills/sast-hardcodedsecrets/SKILL.md new file mode 100644 index 0000000..1bdf96c --- /dev/null +++ b/sast-files/.agents/skills/sast-hardcodedsecrets/SKILL.md @@ -0,0 +1,408 @@ +--- +name: sast-hardcodedsecrets +description: >- + Detect hardcoded sensitive data (API keys, access tokens, private keys, + passwords, etc.) in publicly accessible code — frontend JavaScript, mobile + apps, client-side bundles, and HTML templates. Uses a three-phase approach: + recon (find secret candidates), batched verify (confirm real secrets in public + code paths, 3 candidates each), and merge (consolidate batch results). + Requires sast/architecture.md (run sast-analysis first). Outputs findings to + sast/hardcodedsecrets-results.md. Use when asked to find hardcoded secrets, + leaked API keys, or exposed credentials. +--- + +# Hardcoded Secrets in Public Code Detection + +You are performing a focused security assessment to find hardcoded sensitive data that is exposed in publicly accessible code. This skill uses a three-phase approach with subagents: **recon** (find all potential secret candidates), **batched verify** (confirm each is a real secret in publicly reachable code, in parallel batches of 3), and **merge** (consolidate batch reports into one file). + +**Prerequisites**: `sast/architecture.md` must exist. Run the analysis skill first if it doesn't. + +--- + +## What Are Hardcoded Secrets in Public Code + +Hardcoded secrets are sensitive credentials — API keys, access tokens, private keys, passwords, signing secrets, database connection strings — embedded directly in source code as string literals. + +This skill focuses specifically on secrets that end up in **publicly accessible code**, meaning an attacker can extract them **without any server-side access**. A secret hardcoded in backend server code is bad practice but not directly exploitable by an external attacker inspecting the deployed application. A secret hardcoded in frontend JavaScript or a mobile app binary **is** directly extractable. + +The core question: *Can an external attacker obtain this secret from the deployed application without server access?* + +### What to Report (Publicly Accessible Code) + +These code paths are accessible to attackers after deployment: + +- **Frontend JavaScript/TypeScript** — any `.js`, `.ts`, `.jsx`, `.tsx` file that runs in the browser. This includes: + - React, Angular, Vue, Svelte components and pages + - Next.js client components (files with `"use client"` or files under `app/` without `"use server"`) + - Nuxt.js pages and client plugins + - Vanilla JS in `public/`, `static/`, or `assets/` directories + - Webpack/Vite/Rollup entry points and their imported modules + - Any file imported by a client-side entry point (even if it lives in a `utils/` or `lib/` folder) +- **Mobile application code** — extractable via reverse engineering (decompiling APK, inspecting IPA): + - Android: Java/Kotlin source files + - iOS: Swift/Objective-C source files + - React Native: JavaScript bundles + - Flutter: Dart source files + - Xamarin: C# source files +- **HTML files and templates served to clients** — inline `