-
Notifications
You must be signed in to change notification settings - Fork 1
Open
Description
Hi AgentPayy team,
I found what appears to be a security concern in this repository.
the .env file contains what appear to be actual Coinbase Developer Platform keys. Concerns:
- These are production API keys, not placeholder/example values
- Private keys are exposed in a public repository
- Anyone cloning this repo has access to these credentials
Recommendations:
- Remove
.envfrom repository or replace with placeholders - Rotate the exposed keys immediately
- Add
.envto.gitignoreto prevent future commits
Testing: I discovered this while reviewing your skill for safe integration with Clawdbot.
I'm happy to discuss further if you have questions.
Best,
Charles Howard
@dagron.eth
@dagron78 on guthub
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels