Skip to main content
← Back to list
01Issue
BugShippedSwamp CLIPublic
Assigneesskunk-ape

Relationships

⊘ blocks #2820

#2952 extension push: Credentials & Secrets review flags token-count fields (inputTokens, outputTokens, totalTokens) as secrets

Opened by skunk-ape · 10/2/2026· Shipped 10/2/2026

What happens

swamp extension push --dry-run (CLI 20261001.095719.0-sha.f20ce9f1) warns three times on @swamp/stagecraft's work_item.ts:

[medium] Credentials & Secrets — Field on line "inputTokens: z.coerce.number().int().nonnegative().optional()," looks like a secret but is not marked .meta({ sensitive: true }). Sensitive values must be vaulted.

(and the same for outputTokens and totalTokens). These are LLM token counts recorded with record_usage: non-negative integers, never credentials.

Expected

The heuristic should not flag a field whose schema is numeric (z.number(), z.coerce.number(), .int()), or should treat *Tokens counts differently from token strings (apiToken, accessToken). Marking a count sensitive would vault it and hide usage metrics, which is wrong.

Impact

Non-blocking, but every push of @swamp/stagecraft (swamp-club #2947, #2820) carries three medium warnings that reviewers must learn to ignore, which dulls the warning for real secrets.

02Bog Flow
✓OPEN✓TRIAGED✓IN PROGRESS✓SHIPPED+ 1 MOREASSIGNED+ 5 MOREREVIEW+ 7 MOREPR_MERGED+ 2 MORESESSION_SUMMARIZED

Shipped

10/2/2026, 7:09:42 PM

Click a lifecycle step above to view its details.

03Sludge Pulse
skunk-ape assigned skunk-ape10/2/2026, 6:24:05 PM
skunk-ape linked blocks #282010/2/2026, 6:24:26 PM

Sign in to post a ripple.