Generated source
This hub is built from the same local package data as individual package pages: Nucleus package metadata, Homebrew enrichment, Geiger classifier output, radioisotope manifests, and approval-gate seeds where available.
credential exposure
Secret-risk package pages group tools with radioisotope coverage, approval gates, or Geiger classifier findings that matter when an AI agent can invoke local executables.
GEO summary
Secret-risk packages currently includes 2429 generated package pages. 104 have radioisotope coverage, 20 have approval-gate metadata, and 2364 have non-low Geiger classifier findings. The grouping is generated, not curated prose, so it can stay current as package metadata changes.
This hub is built from the same local package data as individual package pages: Nucleus package metadata, Homebrew enrichment, Geiger classifier output, radioisotope manifests, and approval-gate seeds where available.
Use the hub to find command families that should receive tighter runtime secret injection, approval gates, or manual review before AI agents execute them.
packages
| Package | Manager | Signals | Why it appears here |
|---|---|---|---|
| node | Homebrew | radioisotope, approval gate, yellow risk, v26.0.0 | Plain Text Publishing Token |
| openssl@3 | Homebrew | radioisotope, approval gate, green risk, v3.6.2 | Plain Text Private Keys |
| uv | Homebrew | radioisotope, approval gate, green risk, v0.11.16 | Plain Text Package Credentials |
| mkcert | Homebrew | radioisotope, approval gate, green risk, v1.4.4 | Plain Text Root CA Private Key |
| gh | Homebrew | radioisotope, approval gate, blue risk, v2.92.0 | Trivially Accessible Secrets |
| awscli | Homebrew | radioisotope, approval gate, orange risk, v2.34.53 | Plain Text Secrets |
| git | Homebrew | radioisotope, approval gate, blue risk, v2.54.0 | Plain Text Git Credentials |
| docker | Homebrew | radioisotope, approval gate, orange risk, v29.5.2 | Ambient Docker Registry Credentials |
| ruby | Homebrew | radioisotope, yellow risk, v4.0.5 | Plain Text RubyGems Credentials |
| maven | Homebrew | radioisotope, yellow risk, v3.9.16 | Plain Text Repository Passwords |
| perl | Homebrew | radioisotope, yellow risk, v5.42.2 | Plain Text CPAN Credentials |
| sbt | Homebrew | radioisotope, yellow risk, v1.12.11 | Plain Text sbt Repository Credentials |
| node@18 | Homebrew | radioisotope, yellow risk | Plain Text Publishing Token |
| dropbox-uploader | Homebrew | radioisotope, yellow risk, v1.0 | Plain Text Dropbox OAuth Token |
| fauna-shell | Homebrew | radioisotope, yellow risk, v4.0.0 | Plain Text Fauna CLI Credentials |
| rust | Homebrew | radioisotope, green risk, v1.95.0 | Plain Text Crates.io Token |
| glab | Homebrew | radioisotope, green risk, v1.99.0 | Plain Text GitLab Tokens |
| flyctl | Homebrew | radioisotope, green risk, v0.4.54 | Plain Text Fly.io Access Token |
| mysql-client | Homebrew | radioisotope, green risk, v9.6.0 | Plain Text MySQL Client Passwords |
| k6 | Homebrew | radioisotope, green risk, v2.0.0 | Plain Text k6 Cloud Token |
| jfrog-cli | Homebrew | radioisotope, green risk, v2.104.1 | Plain Text JFrog CLI Credentials |
| buf | Homebrew | radioisotope, green risk, v1.69.0 | Plain Text Buf Registry Token |
| firebase-cli | Homebrew | radioisotope, green risk, v15.18.0 | Plain Text Firebase CLI Tokens |
| qwen-code | Homebrew | radioisotope, green risk, v0.16.0 | Plain Text Qwen Code API Keys |
| doctl | Homebrew | radioisotope, green risk, v1.159.0 | Plain Text DigitalOcean Tokens |
| bitwarden-cli | Homebrew | radioisotope, green risk, v2026.4.2 | Plain Text Bitwarden CLI Tokens |
| railway | Homebrew | radioisotope, green risk, v4.61.1 | Plain Text Railway CLI Tokens |
| supabase | Homebrew | radioisotope, green risk, v2.100.1 | Trivially Accessible Supabase Tokens |
| midnight-commander | Homebrew | radioisotope, green risk, v4.8.33 | Plain Text Midnight Commander VFS Credentials |
| gallery-dl | Homebrew | radioisotope, green risk, v1.32.1 | Plain Text gallery-dl Credentials |
| mycli | Homebrew | radioisotope, green risk, v1.72.1 | Plain Text mycli DSNs and Passwords |
| mercurial | Homebrew | radioisotope, green risk, v7.2.2 | Plain Text Mercurial Auth Passwords |
| hf | Homebrew | radioisotope, green risk, v1.16.1 | Plain Text Hugging Face Token |
| circleci | Homebrew | radioisotope, green risk, v0.1.36202 | Plain Text CircleCI API Token |
| akamai | Homebrew | radioisotope, green risk, v2.0.3 | Plain Text Akamai EdgeGrid Credentials |
| netlify-cli | Homebrew | radioisotope, green risk, v26.0.2 | Plain Text Netlify CLI Credentials |
| snowflake-cli | Homebrew | radioisotope, green risk, v3.18.0 | Plain Text Snowflake Passwords |
| s3cmd | Homebrew | radioisotope, green risk, v2.4.0 | Plain Text S3 Access Keys |
| openstackclient | Homebrew | radioisotope, green risk, v10.0.0 | Plain Text OpenStack Cloud Credentials |
| wakatime-cli | Homebrew | radioisotope, green risk, v2.14.7 | Plain Text WakaTime API Keys |
| twine | Homebrew | radioisotope, green risk, v6.2.0 | Plain Text Python Package Index Credentials |
| shodan | Homebrew | radioisotope, green risk, v1.31.0 | Plain Text Shodan API Key |
| virustotal-cli | Homebrew | radioisotope, green risk, v1.3.1 | Plain Text VirusTotal API Key |
| todoist-cli | Homebrew | radioisotope, green risk, v1.67.1 | Plain Text Todoist API Token |
| fastly | Homebrew | radioisotope, green risk, v15.1.0 | Plain Text Fastly CLI Tokens |
| vultr | Homebrew | radioisotope, green risk, v3.10.0 | Plain Text Vultr API Keys |
| censys | Homebrew | radioisotope, green risk, v2.2.19 | Plain Text Censys CLI Credentials |
| gcli | Homebrew | radioisotope, green risk, v2.11.0 | Plain Text gcli API Tokens |
| goat | Homebrew | radioisotope, green risk, v0.2.3 | Plain Text AT Protocol Sessions |
| algolia | Homebrew | radioisotope, green risk, v1.10.5 | Plain Text Algolia API Keys |
| grafanactl | Homebrew | radioisotope, green risk, v0.1.10 | Plain Text Grafana Credentials |
| astra | Homebrew | radioisotope, green risk, v1.0.4 | Plain Text Astra Application Tokens |
| sslmate | Homebrew | radioisotope, green risk, v1.10.0 | Plain Text SSLMate API Key |
| wsk | Homebrew | radioisotope, green risk, v1.2.0 | Plain Text OpenWhisk Auth Key |
| phylum-cli | Homebrew | radioisotope, green risk, v7.5.0 | Plain Text Phylum API Token |
| curl | Homebrew | radioisotope, blue risk, v8.20.0 | Plain Text HTTP Credentials |
| kubernetes-cli | Homebrew | radioisotope, orange risk, v1.36.1 | Plain Text Kubeconfig Secrets |
| helm | Homebrew | radioisotope, orange risk, v4.2.0 | Plain Text Chart Repository Credentials |
| pnpm | Homebrew | radioisotope, orange risk, v11.2.2 | Plain Text npm Auth Token |
| mysql | Homebrew | radioisotope, orange risk, v9.6.0 | Plain Text MySQL Client Passwords |
| podman | Homebrew | radioisotope, orange risk, v5.8.2 | Plain Text Registry Credentials |
| composer | Homebrew | radioisotope, orange risk, v2.9.8 | Plain Text Composer Auth |
| argocd | Homebrew | radioisotope, orange risk, v3.4.2 | Plain Text Argo CD Tokens |
| rclone | Homebrew | radioisotope, orange risk, v1.74.2 | Plain Text rclone Remote Credentials |
| mysql@8.0 | Homebrew | radioisotope, orange risk, v8.0.46 | Plain Text MySQL Client Passwords |
| rsync | Homebrew | radioisotope, blue risk, v3.4.3 | Plain Text rsync Password Files |
| opentofu | Homebrew | radioisotope, orange risk, v1.12.0 | Plain Text OpenTofu Cloud Tokens |
| openssh | Homebrew | radioisotope, blue risk, v10.3p1 | Plain Text SSH Private Keys |
| mariadb | Homebrew | radioisotope, orange risk, v12.2.2 | Plain Text MariaDB Client Passwords |
| mysql@8.4 | Homebrew | radioisotope, orange risk, v8.4.9 | Plain Text MySQL Client Passwords |
| luarocks | Homebrew | radioisotope, orange risk, v3.13.0 | Plain Text LuaRocks Upload Key |
| pulumi | Homebrew | radioisotope, orange risk, v3.243.0 | Plain Text Pulumi Access Tokens |