keyFile setup uses echo; API key leaks to shell history
Finding PUB-F013 · 6c46a1b6fcb5 · discovered by pentest-public-51classes-20260611
LOWconfirmednon-human-identity-abuseopus48artifact backed
- Target
- OhanaSec/jc-pentest-harness
- Target URL
- not recorded
- Run status
- completed · api-multi-model
- Framework
- nhi-container-cicd
- Priority score
- 0.2200
- Reachability
- unknown
- Chain depth
- 1
- PoC available
- no
- Asset
- not recorded
- Discovered
- Jun 11, 2026, 02:20 PM
Description
Documented keyFile setup uses echo, which writes the API key into shell history in plaintext.
Validation
No validation rationale recorded.
Remediation
Use printf with a heredoc or a secrets manager; document history hygiene.
Evidence Boundary
This page shows persisted finding evidence, validator rationale, target context, and run linkage. Raw prompts, raw target responses, provider payloads, secrets, cookies, and authorization headers are not rendered publicly. Use the linked run page for class execution evidence, run logs, cost events, and pipeline errors.