What does IH-CRED-002 flag?
Flags secrets written into the skill: private key headers, known token formats, and long random-looking values assigned to secret-like names.
- PEM private key headers (RSA, EC, OpenSSH, DSA and encrypted keys).
- AWS access key IDs that start with AKIA, GitHub tokens (ghp_, github_pat_, gho_) and Slack tokens (xoxb-, xoxa-, xoxp-, xoxr-, xoxs-).
- A quoted value of 20 or more characters assigned to a name such as api_key, secret, token, password, access_key or private_key, when its Shannon entropy is at least 4 bits per character.
Why it matters
Anyone who downloads the skill gets the key. A skill that ships someone's live key is also a warning sign in itself. Evidence in reports keeps only the first four characters, so the report does not leak the secret again.
Severity: High (40 points). A private key header is reported as critical (100 points), which forces a block verdict.
Examples
Illustrative shapes with placeholders in angle brackets. They show what the rule looks at; they are not runnable and not taken from real malware.
Can IH-CRED-002 fire on a safe skill?
- Documented example keys, such as the sample AWS key IDs in vendor docs, match the format.
- Long random test fixtures or hashes assigned to a name like token.
How do I fix an IH-CRED-002 finding?
- Remove the secret and rotate it. Deleting it from the latest version is not enough, because copies and history keep it.
- Load secrets from the environment or a secret store.
CLI guidance: Remove the secret, rotate it, and load it from the environment or a secret store.
How do I tune or allow IH-CRED-002?
For a known test fixture, exclude the fixture file with ignoreGlobs rather than turning the rule off.
Every key is described in Configuration. To print this rule from the CLI, run ironheights rules show IH-CRED-002.
What can IH-CRED-002 miss?
- Token formats that are not on the list, which covers most providers.
- Secrets that are split, encoded, or shorter than 20 characters.
- Secrets inside binary files or files over the size limit.
No finding means no rule matched. It is not proof of safety. Files larger than 1 MiB are skipped without being read; the verdict is then incomplete, not no findings, but the file is still not checked. See Limitations.
Related rules
ironheights rules list.