Detector libraryCredential access

Credential access

Your agent opened .env.

Catch a sensitive file read inside an ordinary task.

See the problem. Understand the finding.

English narration with captions.

How it gets overlooked

Your coding agent opened .env. Would you catch it? That file can hold API keys and service credentials. Inside a busy session, one sensitive read can look like just another step.

An agent investigates a configuration issue. It reads the project guide, checks a template, then opens the environment file. Each step looks routine. The question is whether that last read was necessary for the task.

What ClawMetry detects

ClawMetry distinguishes a configuration template from a credential shaped location. A captured read of .env raises a credential access warning, with an environment file category you can inspect.

The difference that changes the finding

Triggering example

cat .env

Warning finding

Quiet comparison

cat .env.example

No finding for this detector.

The checked template read stays quiet. The environment file read warns. If an external destination appears in captured tool arguments after that read, the finding becomes critical. A destination before the read does not create that escalation.

Inspect the detector result
{
  "kind": "credential_access",
  "severity": "warning",
  "evidence": {
    "categories": [
      "environment file"
    ],
    "strong_categories": [
      "environment file"
    ],
    "accesses": 1,
    "egress_after": [],
    "dump_secret_names": 0,
    "observed": "tool_arguments",
    "redacted": "paths, commands and secret values are deliberately not recorded"
  }
}
Download inputs and complete results (JSON)
How the example was checked

These examples evaluate the published detector with authored event data or disposable configuration files. The videos illustrate those behaviors. They are not recordings of live agents or the product interface. No command in the examples was executed.

The result establishes behavior for these inputs. It does not establish runtime ingestion, prevention or a real compromise. Inspect the pinned source contract.

What to check next

Review the tool call, compare it with the task and inspect what followed. Was the sensitive file needed, and did an external destination appear next?

  1. Review the tool call
  2. Check the task
  3. Inspect what followed

What this signal establishes

Access is not proof of disclosure. The detector sees recorded tool arguments and output; it is not a syscall or network monitor.

Keep the important moments visible.

Follow agent activity, inspect findings and decide what needs your attention.