docs(agents): stop enumerating where the credentials live #26
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/agents-stop-enumerating-secret-locations"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
AGENTS.mdnamed the 1Password store, both vaults it reaches, this app's item, the sharedregistry-credential item, and a negative fact about a vault that does not exist. This
repository serves that file publicly on both remotes.
Clark swept the twenty other public repositories in the estate: 0
op://references,0 files naming a vault beside a 1Password reference. The only other vault-word hit is a
matrix-mcpCHANGELOG line about a retired cluster with the hostname already sanitised, andhis instrument found it, so it could match. This is one file, not a class.
Why deleted rather than reworded
Not primarily because it is sensitive. Because this project's own rule is that nothing
goes in
AGENTS.mdwhich can be read from the running system, and every name in thatparagraph is recoverable from the cluster's own ExternalSecrets. It should not have been
there on the day it was written, and its being public is what made anyone look.
The replacement is the two commands that answer it. Both were run verbatim as written
before committing, which is the point of putting a command in a file rather than its
output:
A reader recovers the store, both items and all four key mappings. Nothing is lost, and
what remains cannot go stale, which the deleted paragraph could and eventually would.
What this does not do
It does not unpublish anything. The paragraph stays in history, which has been
anonymously fetchable on GitHub since 2026-08-17 and on Forge since 2026-09-01T23:49:16Z.
This stops the file serving those names at the path anyone reads first, and that is the
whole of its effect.
It does not decide the question. Whether the store, vault and item names belong in a
public repository at all is on #22 and is not mine. If the answer is that they are fine,
this change costs nothing and the file is still better for pointing at the cluster.
Severity, recorded on #22 rather than rated here
It is reconnaissance, not a credential: no
op://paths, no values, names in prose, plus anegative fact that saves a reader a guess. Its weight comes from what sits behind those
names, which Clark reports is a separate exposure on another host. Neither is dangerous
alone and together they are a shorter path than either. That belongs on #22 in those words
and not as a number here.
Also fixes a continuation line that had been indented under the wrong bullet since the
CLAUDE.mdmerge in #24.