Relationships
⊘ blocks #2820#2952 extension push: Credentials & Secrets review flags token-count fields (inputTokens, outputTokens, totalTokens) as secrets
Opened by skunk-ape · 10/2/2026· Shipped 10/2/2026
What happens
swamp extension push --dry-run (CLI 20261001.095719.0-sha.f20ce9f1) warns three times on @swamp/stagecraft's work_item.ts:
[medium] Credentials & Secrets — Field on line "inputTokens: z.coerce.number().int().nonnegative().optional()," looks like a secret but is not marked .meta({ sensitive: true }). Sensitive values must be vaulted.(and the same for outputTokens and totalTokens). These are LLM token counts recorded with record_usage: non-negative integers, never credentials.
Expected
The heuristic should not flag a field whose schema is numeric (z.number(), z.coerce.number(), .int()), or should treat *Tokens counts differently from token strings (apiToken, accessToken). Marking a count sensitive would vault it and hide usage metrics, which is wrong.
Impact
Non-blocking, but every push of @swamp/stagecraft (swamp-club #2947, #2820) carries three medium warnings that reviewers must learn to ignore, which dulls the warning for real secrets.
Shipped
Click a lifecycle step above to view its details.