Skip to content

[Yun Tianming] src/util.ts: secrets.set next-action hint prints args.value verbatim #246

Description

@Fermionic-Lyu

Location: src/util.ts:226 (OP_COMMAND['secrets.set']), rendered by nextActionsLines/renderNextActions from many commands.

Kind: secret in terminal output / shell-history advice.

Impact: nextActions arrives in API bodies. If the platform ever populates args.value for a secrets.set hint, the value is printed to stdout verbatim and the user is told to paste it on a command line, landing it in shell history. redactSensitive (src/redact.ts) is wired only to insta feedback and is not applied here.

Evidence:

'secrets.set': (a) => `insta secrets set ${a.name ?? '<NAME>'} ${a.value ?? '<value>'}`,

Fix would touch: this one map entry: render the placeholder <value> unconditionally, or pass the rendered line through redactSensitive.


Found by Yun Tianming: nightly sweep 2026-09-17-1000 at ecfe5168a32e. Report only; no code was changed for this finding.

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions