Skip to content

Epic: Credential handling & local attack surface #146

Description

@yorkable

Epic. Threat model: single-user dev CLI on a workstation — but the API key grants full org access to a healthcare-adjacent platform, so key confidentiality is the prize. No slam-dunk P1 here; the exposure is a cluster of cheap-to-close key-leak paths. (Verified clean: 0600 config perms, loopback bind, TLS on, no InsecureSkipVerify, no pull_request_target misuse, no browser-launch command injection.)

Issues

Suggested order

124 and 125 are the cheapest key-leak closers (S each). 123 is the highest-impact but M. 126 pairs with the api-contract path fixes. 127 last.

Filed from a full code review, June 2026.

Metadata

Metadata

Assignees

No one assigned

    Labels

    epicEpic tracking issueepic:securityEpic — credential handling and local attack surface

    Type

    No type

    Fields

    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions