tryb

Local inspector

TRB-072v1.0.0 · live_secret_detected

Live secret detected

Live secret detected identifies credential material is exposed or relies on an insufficiently protected secret.

CWE mapping

CWE-798

insufficient recognition

Assurance

The analyzer verified the reported property directly from the supplied input.

Conditional: Operational impact can still depend on where and how this value is used.

Inert example

Displayed as text only. tryb does not execute this example.

[inert example for live_secret_detected]

Remediation

rotate-or-revoke. Assume exposed key material may no longer be private.

Verify: Revoke or rotate it at the issuer, then verify the old material no longer works.

What to verify next

Compare the finding with the destination system's validation and trust policy.

Run the local analyzer