JC·HARNESS

keyFile setup uses echo; API key leaks to shell history

Finding PUB-F013 · 6c46a1b6fcb5 · discovered by pentest-public-51classes-20260611

LOWconfirmednon-human-identity-abuseopus48artifact backed
Target
OhanaSec/jc-pentest-harness
Target URL
not recorded
Run status
completed · api-multi-model
Framework
nhi-container-cicd
Priority score
0.2200
Reachability
unknown
Chain depth
1
PoC available
no
Asset
not recorded
Discovered
Jun 11, 2026, 02:20 PM

Description

Documented keyFile setup uses echo, which writes the API key into shell history in plaintext.

Validation

No validation rationale recorded.

Remediation

Use printf with a heredoc or a secrets manager; document history hygiene.

Evidence Boundary

This page shows persisted finding evidence, validator rationale, target context, and run linkage. Raw prompts, raw target responses, provider payloads, secrets, cookies, and authorization headers are not rendered publicly. Use the linked run page for class execution evidence, run logs, cost events, and pipeline errors.