How it gets overlooked
Your coding agent opened .env. Would you catch it? That file can hold API keys and service credentials. Inside a busy session, one sensitive read can look like just another step.
An agent investigates a configuration issue. It reads the project guide, checks a template, then opens the environment file. Each step looks routine. The question is whether that last read was necessary for the task.
What ClawMetry detects
ClawMetry distinguishes a configuration template from a credential shaped location. A captured read of .env raises a credential access warning, with an environment file category you can inspect.
The difference that changes the finding
Triggering example
cat .env
Warning finding
Quiet comparison
cat .env.example
No finding for this detector.
The checked template read stays quiet. The environment file read warns. If an external destination appears in captured tool arguments after that read, the finding becomes critical. A destination before the read does not create that escalation.
Inspect the detector result
{
"kind": "credential_access",
"severity": "warning",
"evidence": {
"categories": [
"environment file"
],
"strong_categories": [
"environment file"
],
"accesses": 1,
"egress_after": [],
"dump_secret_names": 0,
"observed": "tool_arguments",
"redacted": "paths, commands and secret values are deliberately not recorded"
}
}Download inputs and complete results (JSON)How the example was checked
These examples evaluate the published detector with authored event data or disposable configuration files. The videos illustrate those behaviors. They are not recordings of live agents or the product interface. No command in the examples was executed.
The result establishes behavior for these inputs. It does not establish runtime ingestion, prevention or a real compromise. Inspect the pinned source contract.
What to check next
Review the tool call, compare it with the task and inspect what followed. Was the sensitive file needed, and did an external destination appear next?
- Review the tool call
- Check the task
- Inspect what followed
What this signal establishes
Access is not proof of disclosure. The detector sees recorded tool arguments and output; it is not a syscall or network monitor.