File appears to expose a hardcoded API secret or token.
- Code
- suspicious.exposed_secret_literal
- Location
- skills/identity-aiops/references/cli-reference.md:28
- Evidence
Master password: `[REDACTED]` (non-interactive/MCP) or an
Security audit
Security checks for vulnerabilities and agentic risk
This plugin is a clearly disclosed identity-operations tool for Keycloak and authentik, with high-impact admin actions that appear purpose-aligned but require careful least-privilege setup.
Install only with a least-privileged Keycloak service account or authentik token. Start with view-only roles unless you intentionally want the agent to disable users, revoke sessions, require resets, change redirect URIs, or rotate secrets. Review the local ~/.identity-aiops audit, undo, and encrypted secret storage behavior before use.
SkillSpector was not run because this plugin release contains no bundled skills.
Detected: suspicious.exposed_secret_literal, suspicious.prompt_injection_instructions
Master password: `[REDACTED]` (non-interactive/MCP) or an
Copy this into your agent's system prompt: