TRB-072v1.0.0 · live_secret_detected
Live secret detected
Live secret detected identifies credential material is exposed or relies on an insufficiently protected secret.
CWE mapping
CWE-798insufficient recognition
Assurance
The analyzer verified the reported property directly from the supplied input.
Conditional: Operational impact can still depend on where and how this value is used.
Inert example
Displayed as text only. tryb does not execute this example.
[inert example for live_secret_detected]Remediation
rotate-or-revoke. Assume exposed key material may no longer be private.
Verify: Revoke or rotate it at the issuer, then verify the old material no longer works.
What to verify next
Compare the finding with the destination system's validation and trust policy.