Auditor
Session tokens are not kept in localStorage unless a documented reason exists.
1.0.2: never analyses temporary files (*.tmp.*; spec.excludes follows AUDITOR_ANALYSIS_EXCLUDES). (1.0.1: never analyses test, spec, fixture and mock paths nor the auditor's own scripts (spec.excludes = AUDITOR_ANALYSIS_EXCLUDES); a fixture-looking secret (sk_test_, example, dummy) in real code is LOW, informative; every model call stays under the engine prompt cap (spec.promptMaxChars = AUDITOR_AI_PROMPT_MAX_CHARS): assess mode sends the candidate set in parts and aggregates the verdicts (a HIGH in any part is a FAIL, an unsatisfied part is a FAIL).)
| const CREDENTIAL_KEY = /\b(?:access_?token|refresh_?token|id_?token|auth_?token|jwt|token|session_?id|session|auth|api_?key|bearer|credentials?|secret)\b/i; |
| const STORAGE_WRITE = /\b(localStorage|sessionStorage)\s*(?:\.\s*setItem\s*\(\s*([^,\n]+)\s*,|\[\s*([^\]\n]+)\s*\]\s*=|\.\s*(\w+)\s*=)/g; |
| // localStorage + credential key and no comment with reason|justification|accepted risk within 3 lines -> FAIL; sessionStorage -> MEDIUM |
The full script is disclosed on request in a read-only viewer (never published on GitHub); the attestation binds to this exact hash.