What happens
insforge branch reset <name> --json returns the branch object with a plaintext database_password:
{
"branch": {
"id": "021b880b-...",
"organization_id": "ddecefbb-...",
"name": "e2e-...",
"database_password": "T+rIl1ksws0bSMilsSoVOln/o3r/JVY9yKz1Pj/yCEH4lyO7uPXyh92I+YX3KQNL...",
...
}
}
Why it matters
Command output is the least controlled surface there is. It lands in terminal scrollback, CI logs, and any tooling that captures stdout — none of which treat it as secret-bearing. A credential that arrives this way is copied into places nobody chose.
We hit it because the E2E harness records CLI stdout into its run logs and artifacts. Our redactor masks secrets it is told about, and it had no way to know about this one: the value is generated server-side and first seen in this response. It was written to the artifacts of a public workflow run before we noticed.
Suggestion
Omit database_password from the command's output, or mask it the way ai setup masks the OpenRouter key — that command already returns a maskedKey and deliberately keeps the raw value out of stdout, so the pattern exists in the codebase.
Worth a sweep for the same shape: any command that echoes a project or branch object straight from the API may carry credentials the API includes for other reasons. branch create and branch switch return adjacent objects.
Found while adding branch coverage to the deterministic fixture E2E.
What happens
insforge branch reset <name> --jsonreturns the branch object with a plaintextdatabase_password:{ "branch": { "id": "021b880b-...", "organization_id": "ddecefbb-...", "name": "e2e-...", "database_password": "T+rIl1ksws0bSMilsSoVOln/o3r/JVY9yKz1Pj/yCEH4lyO7uPXyh92I+YX3KQNL...", ... } }Why it matters
Command output is the least controlled surface there is. It lands in terminal scrollback, CI logs, and any tooling that captures stdout — none of which treat it as secret-bearing. A credential that arrives this way is copied into places nobody chose.
We hit it because the E2E harness records CLI stdout into its run logs and artifacts. Our redactor masks secrets it is told about, and it had no way to know about this one: the value is generated server-side and first seen in this response. It was written to the artifacts of a public workflow run before we noticed.
Suggestion
Omit
database_passwordfrom the command's output, or mask it the wayai setupmasks the OpenRouter key — that command already returns amaskedKeyand deliberately keeps the raw value out of stdout, so the pattern exists in the codebase.Worth a sweep for the same shape: any command that echoes a project or branch object straight from the API may carry credentials the API includes for other reasons.
branch createandbranch switchreturn adjacent objects.Found while adding branch coverage to the deterministic fixture E2E.