Zennoxa Shield / Documentation

Zennoxa Shield Documentation

Learn how to use every part of Shield — from your first scan to the CLI — plus the full reference for all 315 detection rules.เรียนรู้วิธีใช้ทุกส่วนของ Shield — ตั้งแต่สแกนครั้งแรกจนถึง CLI — พร้อมเอกสารอ้างอิงครบทั้ง 315 rule

Quickstart (CLI)

curl -sSL zennoxa.com/install | sh
shield login
shield scan . --submit --project YOUR-PROJECT-ID --org YOUR-ORG-ID

Conceptsแนวคิด

Scan layersชั้นการสแกน

SAST, Secrets, DAST (dynamic + live), Containers, Infrastructure-as-Code, and Dependencies — in one scan.SAST, Secrets, DAST (สแกน + ยิงจริง), Containers, IaC และ Dependencies — ในการสแกนครั้งเดียว

Severityระดับความรุนแรง

Every rule carries a severity: critical, high, medium, low, or info.ทุก rule มีระดับ: critical, high, medium, low หรือ info

Reachabilityการเข้าถึงได้

Flags whether vulnerable code is actually reachable in your app, not just present.บอกว่าโค้ดช่องโหว่ถูกเรียกใช้จริงในแอปมั้ย ไม่ใช่แค่มีอยู่

Priority scoreคะแนน Priority

Ranks findings by real-world risk (severity weighted by reachability).จัดอันดับตามความเสี่ยงจริง (ความรุนแรงถ่วงด้วยการเข้าถึงได้)

Using Shieldวิธีใช้งาน Shield

Step-by-step how-to for each function.วิธีใช้แต่ละฟังก์ชันทีละขั้นตอน

Loginเข้าสู่ระบบ

First step: log in at zennoxa.comขั้นตอนแรก: เข้าสู่ระบบที่ zennoxa.com

  1. 1Open your browser and go to https://zennoxa.comเปิด browser แล้วไปที่ https://zennoxa.com
  2. 2Enter your email address and passwordกรอก Email และ Password ของคุณ
  3. 3Click "Sign In" — the Dashboard loads automaticallyคลิก "Sign In" — ระบบจะพาไปที่ Dashboard อัตโนมัติ
  4. 4If 2FA is enabled, enter the 6-digit code from your authenticator appถ้าเปิด 2FA ไว้ ให้กรอกรหัส 6 หลักจากแอป Authenticator ด้วย
Tipเคล็ดลับ Forgot password? Click the "Forgot?" link on the sign-in page — you'll get a password-reset link by email (valid for 1 hour).ลืมรหัสผ่าน? คลิกลิงก์ "Forgot?" ที่หน้า Sign In — ระบบจะส่งลิงก์รีเซ็ตรหัสผ่านไปทางอีเมล (ใช้ได้ภายใน 1 ชั่วโมง)

1. Create a Project1. สร้างโปรเจกต์

Before scanning, create a project — one per repository.โปรเจกต์คือกลุ่มของ repository ที่คุณต้องการสแกน ก่อนสแกนโค้ด คุณต้องสร้างโปรเจกต์ก่อน (1 โปรเจกต์ต่อ 1 repository)

  1. 1Click Projects in the left sidebarคลิก Projects ที่เมนูด้านซ้าย
  2. 2Click the "+ New Project" button in the top-right corner — an inline "Create New Project" form opensคลิกปุ่ม "+ New Project" มุมขวาบน — จะมีฟอร์ม "Create New Project" เปิดขึ้นมา
  3. 3Enter a Project Name (e.g. "my-website") — the Slug auto-fills from the name and can be edited; both are requiredกรอกชื่อโปรเจกต์ (เช่น "my-website") — ระบบเติม Slug ให้อัตโนมัติจากชื่อ (แก้ไขได้) ทั้งชื่อและ slug ต้องกรอก
  4. 4Choose how to connect the repo: the "From GitHub" tab lets you pick a repository from your connected GitHub App, or the "Enter URL manually" tab accepts a GitHub, GitLab, Azure DevOps, Bitbucket, or self-hosted git URL over HTTPS (add an access token for private repos)(ไม่บังคับ) กรอก Repository URL ถ้าต้องการเชื่อมต่อกับ GitHub/GitLab
  5. 5Click "Create Project" — you're taken straight to the new project's pageคลิก Create — โปรเจกต์จะปรากฏในรายการทันที
  6. 6Note down the Project ID — you'll need it when scanning with the CLIจด Project ID ไว้ (ใช้ตอนสแกนด้วย CLI)
Tipแนะนำ Best practice: Create one project per repository, e.g. "frontend-app" and "backend-api".แนะนำ: สร้าง 1 โปรเจกต์ต่อ 1 repository เช่น "frontend-app" และ "backend-api"
Projects pageหน้าโปรเจกต์

2. Trigger a Scanสั่งสแกนโค้ด — สแกนหาช่องโหว่ในซอร์สโค้ดของคุณ

You can scan in two ways: via the Web UI or the CLI. CLI is covered in section 7.คุณสแกนได้ 2 วิธี: ผ่าน Web UI หรือ CLI

  1. 1Click Projects in the sidebar, then click the project you want to scanคลิก Projects ที่เมนูซ้าย แล้วคลิกโปรเจกต์ที่ต้องการสแกน
  2. 2Click the "Trigger Scan" buttonคลิกปุ่ม "Trigger Scan"
  3. 3Pick the branch to scan from the dropdown (it defaults to the repo's default branch) — or click "Type branch name" to enter one manually if the list isn't availableกรอก Branch ที่ต้องการสแกน (เช่น main หรือ develop)
  4. 4Click Start Scan — status changes to RUNNINGคลิก Start Scan — สถานะจะเปลี่ยนเป็น RUNNING
  5. 5Wait — a live progress panel updates automatically and the page refreshes when the scan is done. (Tip: no repo connected yet? Use the "Try Demo Scan" button to scan a built-in vulnerable sample end-to-end.)รอสักครู่ หน้าจอจะอัปเดตอัตโนมัติเมื่อสแกนเสร็จ DONE
  6. 6When done, click Findings in the sidebar to review resultsเมื่อสแกนเสร็จ คลิก Findings ที่เมนูซ้ายเพื่อดูผลลัพธ์
Noteหมายเหตุ Note: For automatic scanning on every code push, use the CLI in GitHub Actions (see section 7).หมายเหตุ: ถ้าต้องการให้สแกนอัตโนมัติทุกครั้งที่ push โค้ด ใช้ CLI ใน GitHub Actions (ดูหัวข้อที่ 7)

3. View Findingsตรวจสอบช่องโหว่ที่พบและดูวิธีแก้ไข

The Findings page lists every vulnerability found in your code, with severity levels and fix suggestions.หน้า Findings แสดงช่องโหว่ทั้งหมดที่พบในโค้ด พร้อมระดับความรุนแรงและคำแนะนำวิธีแก้ไข

  1. 1Click Findings in the sidebar — all vulnerabilities are listed.คลิก Findings ที่เมนูซ้าย — จะเห็นรายการช่องโหว่ทั้งหมด
  2. 2Click a severity filter like Critical to see only that level.กดปุ่มกรองระดับความรุนแรง เช่น Critical เพื่อดูเฉพาะช่องโหว่วิกฤต
  3. 3Click "By Priority" to sort by real-world risk score, not just severity label.คลิก "By Priority" เพื่อเรียงตามความเสี่ยงจริง (ไม่ใช่แค่ระดับ)
  4. 4Sort by "By Priority" to see the findings with the highest computed risk score first, then work down the list.ช่องโหว่ที่มีป้าย KEV คือช่องโหว่ที่มีคนใช้โจมตีจริงแล้ว — แก้ก่อนเลย
  5. 5Click the › chevron on any row to expand the code snippet.คลิก › ที่แถวใดแถวหนึ่งเพื่อดูโค้ดที่มีปัญหา
  6. 6Click a finding's message to open its detail page. If an AI analysis has been generated for that finding, an "AI Analysis" card shows a plain-language explanation and a suggested fix.คลิกที่ข้อความ (message) ของช่องโหว่เพื่อเปิดหน้ารายละเอียด ถ้ามีการสร้างคำอธิบาย AI ไว้แล้ว จะเห็นการ์ด "AI Analysis" ที่อธิบายเป็นภาษาง่าย ๆ พร้อมแนวทางแก้ไข
Importantสำคัญ How does priority work? "By Priority" ranks findings by a computed risk score (severity weighted by code reachability), not just the severity label — so you fix what matters most first.Priority ทำงานอย่างไร? "By Priority" จัดอันดับช่องโหว่ตามคะแนนความเสี่ยงที่คำนวณได้ (ความรุนแรงถ่วงน้ำหนักด้วยการเข้าถึงได้ของโค้ด) ไม่ใช่แค่ป้ายระดับความรุนแรง จึงช่วยให้แก้สิ่งที่สำคัญที่สุดก่อน
Findings pageหน้า Findings

4. Manage Usersจัดการผู้ใช้

Add, remove, and manage user permissions within your organization (Admin only).เพิ่ม ลบ และจัดการสิทธิ์ผู้ใช้ในองค์กร (เฉพาะ Admin)

  1. 1How to invite a new team member: In the sidebar's Admin section, click Usersวิธีเพิ่มสมาชิกใหม่เข้าทีม: คลิก Admin ที่เมนูซ้าย แล้วเลือก Users
  2. 2Click "Invite user"คลิก "Invite user"
  3. 3Enter the email address of the person you want to inviteกรอก Email ของผู้ที่ต้องการเชิญ
  4. 4Choose a Role: Admin (full access, manage users), Member (create projects & trigger scans), or Viewer (read-only)เลือก Role: Admin (จัดการทุกอย่าง รวมถึงผู้ใช้), Member (สร้างโปรเจกต์และสั่งสแกนได้), หรือ Viewer (ดูอย่างเดียว)
  5. 5Click Send invite — a temporary password is generated; copy it and share it securely with the user, who changes it after first loginคลิก Send invite — ระบบจะสร้างรหัสผ่านชั่วคราวให้ คัดลอกแล้วส่งให้ผู้ใช้อย่างปลอดภัย ผู้ใช้จะเปลี่ยนรหัสผ่านหลัง login ครั้งแรก
  6. 6The invited user appears in the Users list immediately and can log in with the temporary password you sharedผู้ใช้ที่ถูกเชิญจะปรากฏในรายการ Users ทันที และเข้าสู่ระบบได้ด้วยรหัสผ่านชั่วคราวที่คุณส่งให้
  7. 7How to remove a user: Go to Admin → Usersวิธีลบผู้ใช้ออกจากองค์กร: ไปที่ Admin → Users
  8. 8Find the user you want to remove and click the red trash (Delete) icon on their rowหาชื่อผู้ใช้ที่ต้องการลบ แล้วคลิก Remove
  9. 9Confirm the removal — that user can no longer log inยืนยันการลบ — ผู้ใช้คนนั้นจะไม่สามารถ login ได้อีกต่อไป
Noteหมายเหตุ Admin only: The Admin Panel is only visible to users with the admin role.เฉพาะ Admin: เมนู Admin Panel จะมองเห็นได้เฉพาะผู้ใช้ที่มีสิทธิ์ admin เท่านั้น ถ้าไม่เห็นเมนูนี้ ให้ติดต่อ admin ขององค์กร

5. Set Up an API Keyสร้าง key สำหรับใช้งาน CLI หรือ GitHub Actions

API Keys are used for: CLI scanning, GitHub Actions, or direct API calls.API Key ใช้สำหรับ: สแกนด้วย CLI, รัน GitHub Actions, หรือเรียก API โดยตรง

  1. 1Click Settings in the left sidebarคลิก Settings ที่เมนูซ้าย
  2. 2Select API Keysเลือก API Keys
  3. 3Click "Create key"คลิก "Create key"
  4. 4Enter a Key name so you remember what this key is for, e.g. "GitHub Actions CI", and pick an expiration (30 days by default, or No expiry)กรอก Key name เพื่อจำว่า key นี้ใช้ทำอะไร เช่น "GitHub Actions CI" และเลือกวันหมดอายุ (ค่าเริ่มต้น 30 วัน หรือ No expiry)
  5. 5Copy the key immediately — it is shown only once. If you close the page, it cannot be retrievedคัดลอก key ทันที — key จะแสดงแค่ครั้งเดียว ถ้าปิดหน้าจอไปแล้วจะเรียกคืนไม่ได้
  6. 6Use a CLI token in the CLI: export SHIELD_CLI_TOKEN=shield_cli_... (or run `shield login` and paste the token). Dashboard API keys are branded znx_ and are for direct API calls / CI.ใช้ CLI token กับ CLI: export SHIELD_CLI_TOKEN=shield_cli_... (หรือรัน `shield login` แล้ววาง token)
Use the key in CLIใช้งาน key ใน CLI
export SHIELD_CLI_TOKEN=shield_cli_...
Importantสำคัญ Warning: Never commit API Keys to source code. Always store them in environment variables or a secrets manager.ระวัง: ห้าม commit API Key ลง source code เด็ดขาด ให้เก็บไว้ใน environment variable หรือ secrets manager เสมอ

6. Install the CLI6. ติดตั้ง CLI

The Shield CLI lets you scan code directly from your terminal — ideal for GitHub Actions or other CI/CD pipelines.Shield CLI ให้คุณสแกนโค้ดจาก terminal ได้โดยตรง เหมาะสำหรับใช้ใน GitHub Actions หรือ pipeline อื่น ๆ

  1. 1No prerequisites — the installer downloads a self-contained binary and verifies its SHA256 checksumไม่ต้องติดตั้งอะไรก่อน — ตัวติดตั้งจะดาวน์โหลด binary พร้อมใช้และตรวจ SHA256 checksum ให้อัตโนมัติ
  2. 2Run this command in your terminal:รันคำสั่งนี้ใน terminal:
  3. 3Verify the installation:ตรวจสอบว่าติดตั้งสำเร็จ:
  4. 4Log in with your API Key (created in section 5):Login ด้วย API Key (สร้างจากหัวข้อที่ 5):
Install the Shield CLIติดตั้ง Shield CLI
curl -sSL zennoxa.com/install | sh
# or: brew install zennoxa/tap/shield
# or download a binary + SHA256SUMS: github.com/Zennoxa/shield/releases
Verify the installationตรวจสอบว่าติดตั้งสำเร็จ
shield version
Log in with your API KeyLogin ด้วย API Key
# ตั้งค่า CLI token (สำหรับ headless/CI)
export SHIELD_CLI_TOKEN=shield_cli_your_token_here

# หรือ Login แบบ interactive / Or login interactively (เปิด browser ไปที่ /settings/cli-tokens)
shield login

7. Scan a Repository with the CLIสแกน repo ด้วย CLI

รันการสแกนจาก terminal ใน 1 คำสั่ง

  1. 1Open a terminal and navigate to your project's root directoryเปิด terminal แล้วไปที่ root ของ project ที่ต้องการสแกน
  2. 2Run this command (replace YOUR-PROJECT-ID with your Project ID from section 1, and YOUR-ORG-ID with your organization ID):รันคำสั่งนี้ (แทนที่ YOUR-PROJECT-ID ด้วย Project ID จากหัวข้อที่ 1 และ YOUR-ORG-ID ด้วย organization ID):
  3. 3To apply a zone policy (dev, staging, production):ถ้าต้องการระบุ branch ด้วย:
  4. 4Wait for the CLI to report scan completion (it prints the Scan ID)รอจนกว่า CLI จะพิมพ์ว่า scan เสร็จแล้ว (จะแสดง Scan ID)
Scan the current directory for a projectสแกนไดเรกทอรีปัจจุบันสำหรับโปรเจกต์
shield scan . --submit \
  --project YOUR-PROJECT-ID --org YOUR-ORG-ID \
  --api-url https://zennoxa.com
Scan while specifying a branchสแกนพร้อมระบุ branch
shield scan . --submit --project YOUR-PROJECT-ID --org YOUR-ORG-ID --zone production
GitHub Actions workflow line to scan on every pushบรรทัดใน GitHub Actions workflow เพื่อสแกนทุก push
shield scan . --submit --project ${{ vars.SHIELD_PROJECT }} --org ${{ vars.SHIELD_ORG }} --api-url https://zennoxa.com
Tipเคล็ดลับ GitHub Actions: Add this line to your workflow YAML to scan automatically on every push. Set SHIELD_CLI_TOKEN as a GitHub Actions secret.GitHub Actions: เพิ่มบรรทัดนี้ใน workflow YAML เพื่อสแกนอัตโนมัติทุก push ตั้งค่า SHIELD_CLI_TOKEN เป็น GitHub Actions secret

8. View Resultsดูผลลัพธ์

See scan results both on the Dashboard and in the terminal.ดูผลการสแกนได้ทั้งบน Dashboard และใน terminal

  1. 1On the web: Go to https://zennoxa.com and click Findings — results appear automaticallyบน Web: ไปที่ https://zennoxa.com แล้วคลิก Findings — ผลจะปรากฏอัตโนมัติ
  2. 2In terminal: shield scan prints a per-severity summary (critical/high/medium/low/info) after each scan. To browse or filter findings, use the web dashboard.ใน terminal: ดูรายการ findings ล่าสุดด้วยคำสั่งด้านล่าง
  3. 3On the Dashboard, click Findings and filter by project or severity levelคลิก Findings บน Dashboard แล้วกรองตามโปรเจกต์หรือระดับ severity ที่สนใจ
  4. 4Click a finding's message for details. If an AI analysis has been generated, an "AI Analysis" card shows a plain-language description and a suggested fix.คลิก rule name ใด ๆ เพื่อเปิดหน้า detail — ถ้ามีคำอธิบาย AI แล้ว จะเห็นการ์ด "AI Analysis" อธิบายภาษาง่าย ๆ พร้อมแนวทางแก้ไข
List recent findings and check scan status in the terminalดูรายการ findings ล่าสุดและตรวจสอบสถานะ scan ใน terminal
# ดูผลลัพธ์บน dashboard — CLI ไม่มีคำสั่ง list findings/scans
# เปิด https://zennoxa.com/findings (กรองตาม severity ในหน้าเว็บ)
Log in to ShieldLogin เข้าระบบ
shield login
Scan current directoryสแกน directory ปัจจุบัน
shield scan . --submit --project PROJECT-ID --org ORG-ID
List all projectsดูรายการโปรเจกต์
# The CLI has no `projects list` command — view projects at https://zennoxa.com/projects
List recent scansดูประวัติการสแกน
# The CLI has no `scans list` command — view scan history at https://zennoxa.com/scans
List critical findingsดูช่องโหว่ critical
# The CLI has no `findings list` command — filter at https://zennoxa.com/findings?severity=critical
Tipเคล็ดลับ Open a finding's detail page from its message. When an AI analysis exists for that finding, an "AI Analysis" card provides a plain-language description together with a suggested fix.เปิดหน้า detail ของช่องโหว่จากข้อความของมัน เมื่อมีคำอธิบาย AI สำหรับช่องโหว่นั้น จะมีการ์ด "AI Analysis" อธิบายง่าย ๆ พร้อมแนวทางแก้ไข
Open Shield Dashboardเปิด Shield Dashboard

Rules Referenceรายการ Rules

Every rule Shield can raise — id, severity, CWE, what it detects, where it appears, and how to fix. Use search to filter. (Rule text is in English.)ทุก rule ที่ Shield ตรวจได้ — id, severity, CWE, เจออะไร, ดูตรงไหน, แก้ยังไง (พิมพ์ค้นหาเพื่อกรอง; ข้อความ rule เป็นภาษาอังกฤษ)

No rules match your search.

SAST — Source Code 223 rules

SHIELD-CPP-004criticalCWE-242Use of gets is inherently unsafe
What it detects

Detects gets() which performs an unbounded read from stdin and always risks buffer overflow.

Where it appears

C/C++ files via gets() pattern matching

How to fix

Replace gets with fgets and a fixed buffer size.

SHIELD-CPP-008criticalCWE-78Command injection via system
What it detects

Detects system() called with a variable or concatenated string enabling command injection.

Where it appears

C/C++ files via system + variable/concatenation pattern matching

How to fix

Avoid the shell; use execve with a fixed argument vector and validated inputs.

SHIELD-CPP-009criticalCWE-78Command injection via popen
What it detects

Detects popen() with a variable or concatenated command string enabling command injection.

Where it appears

C/C++ files via popen + variable/concatenation pattern matching

How to fix

Replace popen with a direct exec of a fixed program and sanitized arguments.

SHIELD-CSHARP-001criticalCWE-89SQL injection via string concatenation in SqlCommand
What it detects

Detects SqlCommand constructed by concatenating untrusted strings directly into the query text.

Where it appears

C# files via SqlCommand + concatenation pattern matching

How to fix

Use parameterized queries with SqlParameter instead of concatenating values into the SQL string.

SHIELD-CSHARP-002criticalCWE-89SQL injection via string.Format or interpolation into query
What it detects

Detects SQL query assembled with string.Format or interpolated string containing SELECT/INSERT/UPDATE/DELETE.

Where it appears

C# files via SQL + string.Format/interpolation pattern matching

How to fix

Replace string.Format and interpolation with parameterized queries binding user input as SqlParameter values.

SHIELD-CSHARP-003criticalCWE-89SQL injection via ExecuteReader on interpolated string
What it detects

Detects ExecuteReader/ExecuteScalar/ExecuteNonQuery running a command with interpolated string text.

Where it appears

C# files via Execute method + interpolated string pattern matching

How to fix

Use parameterized commands rather than passing an interpolated SQL string to Execute methods.

SHIELD-CSHARP-004criticalCWE-78Command injection via Process.Start with concatenation
What it detects

Detects Process.Start with command or argument string built from concatenated untrusted input.

Where it appears

C# files via Process.Start + concatenation pattern matching

How to fix

Pass a fixed executable path and supply arguments as a validated ProcessStartInfo.ArgumentList collection.

SHIELD-CSHARP-006criticalCWE-502Insecure deserialization via BinaryFormatter and similar formatters
What it detects

Detects BinaryFormatter, LosFormatter, NetDataContractSerializer, or ObjectStateFormatter Deserialize calls.

Where it appears

C# files via insecure formatter pattern matching

How to fix

Replace BinaryFormatter and similar formatters with a safe serializer such as System.Text.Json without type name handling.

SHIELD-CSHARP-007criticalCWE-502Insecure deserialization via Json.NET TypeNameHandling
What it detects

Detects Json.NET configured with TypeNameHandling.All, Auto, Objects, or Arrays enabling type-confusion attacks.

Where it appears

C# files via TypeNameHandling pattern matching

How to fix

Set TypeNameHandling to None or use a strict SerializationBinder that allowlists safe types.

SHIELD-DART-001criticalCWE-89SQL injection via raw query interpolation
What it detects

Detects raw SQL executed with string-interpolated or concatenated user input.

Where it appears

Dart files via rawQuery/rawInsert/execute + interpolation/concatenation pattern matching

How to fix

Use parameterized queries with whereArgs or positional argument lists instead of interpolation.

SHIELD-DART-002criticalCWE-78Command injection via shell process execution
What it detects

Detects Process.run/Process.start invoked through a shell enabling command injection.

Where it appears

Dart files via Process + shell pattern matching

How to fix

Pass a fixed executable with an argument list and avoid runInShell with untrusted input.

SHIELD-DART-005criticalCWE-295Insecure certificate validation bypass
What it detects

Detects badCertificateCallback returning true disabling TLS validation enabling man-in-the-middle attacks.

Where it appears

Dart files via badCertificateCallback => true pattern matching

How to fix

Never unconditionally trust certificates; validate the chain and host properly.

SHIELD-GEN-003criticalCWE-798AWS access key exposed
What it detects

Matches AWS access key ID pattern (AKIA followed by 16 alphanumeric characters) which grants AWS resource access.

Where it appears

All languages via regex pattern AKIA[0-9A-Z]{16}

How to fix

Revoke the exposed key immediately and use IAM roles or environment variables for authentication.

SHIELD-GEN-004criticalCWE-321Private RSA/EC key material in source
What it detects

Detects PEM-formatted private key headers (RSA, EC, OpenSSH, DSA PRIVATE KEY) embedded in source code.

Where it appears

All languages via PEM header pattern matching

How to fix

Remove the private key from the codebase immediately. Rotate the key. Use a secrets manager.

SHIELD-GEN-006criticalCWE-798GitHub personal access token exposed
What it detects

Detects GitHub PAT prefix ghp_ followed by 36 alphanumeric characters which grant repository access.

Where it appears

All languages via GitHub PAT pattern matching

How to fix

Revoke the token immediately at github.com/settings/tokens and rotate secrets.

SHIELD-GEN-008criticalCWE-798JWT secret hardcoded
What it detects

Detects jwt_secret, jwt_key, or signing_key assigned to a quoted string of 8+ characters, allowing token forgery.

Where it appears

All languages via JWT secret assignment pattern

How to fix

Generate a cryptographically random secret and load it from the environment.

SHIELD-GEN-012criticalCWE-798Stripe secret key exposed
What it detects

Detects Stripe secret key pattern (sk_live_ or sk_test_ followed by 24+ alphanumeric characters) which grants full API access.

Where it appears

All languages via Stripe secret key pattern matching

How to fix

Revoke the key in the Stripe dashboard immediately and rotate secrets.

SHIELD-GO-001criticalCWE-89SQL Injection via string formatting
What it detects

Detects SQL database query methods called with fmt.Sprintf for string interpolation.

Where it appears

Go files via db.Query + fmt.Sprintf pattern matching

How to fix

Use parameterized queries with ? or $N placeholders instead of fmt.Sprintf.

SHIELD-GO-002criticalCWE-89SQL Injection via string concatenation
What it detects

Detects SQL query methods called with + string concatenation operator.

Where it appears

Go files via database query + concatenation pattern matching

How to fix

Use parameterized queries. Never concatenate user input into SQL strings.

SHIELD-GO-007criticalCWE-78Command injection via exec.Command with user input
What it detects

Detects exec.Command calls with user input from HTTP request URL, Form, PostForm, Header, or Body.

Where it appears

Go files via exec.Command + request pattern matching

How to fix

Never pass user input directly to exec.Command. Validate and allowlist commands and arguments.

SHIELD-JAVA-001criticalCWE-89SQL Injection via String Concatenation
What it detects

Detects SQL statement execution methods (executeQuery, executeUpdate, execute) called with string concatenation.

Where it appears

Java files via SQL method + concatenation pattern matching

How to fix

Use PreparedStatement with parameterized queries instead of concatenating input into SQL strings.

SHIELD-JAVA-002criticalCWE-78OS Command Injection via Runtime.exec
What it detects

Detects Runtime.getRuntime().exec() called with concatenated string.

Where it appears

Java files via Runtime.exec + concatenation pattern matching

How to fix

Avoid shell invocation; pass a fixed command with an argument array and validate all inputs.

SHIELD-JAVA-003criticalCWE-78OS Command Injection via ProcessBuilder
What it detects

Detects ProcessBuilder constructed with concatenated arguments.

Where it appears

Java files via ProcessBuilder + concatenation pattern matching

How to fix

Use a fixed argument list and validate or allowlist any user-controlled arguments.

SHIELD-JAVA-004criticalCWE-502Insecure Java Deserialization
What it detects

Detects ObjectInputStream.readObject() or readUnshared() on untrusted data enabling remote code execution.

Where it appears

Java files via ObjectInputStream pattern matching

How to fix

Avoid native serialization for untrusted data; use a safe format like JSON with strict type validation.

SHIELD-JAVA-005criticalCWE-502Insecure Deserialization via XMLDecoder
What it detects

Detects XMLDecoder instantiation which deserializes arbitrary objects and can execute attacker code.

Where it appears

Java files via XMLDecoder pattern matching

How to fix

Do not use XMLDecoder on untrusted input; use a safe data-binding library with restricted types.

SHIELD-JAVA-014criticalCWE-295Trust-All TLS HostnameVerifier
What it detects

Detects HostnameVerifier.verify() method that returns true unconditionally, disabling host validation.

Where it appears

Java files via HostnameVerifier pattern matching

How to fix

Remove the custom verifier and rely on the default hostname verification.

SHIELD-JAVA-017criticalCWE-917SpEL or OGNL Expression Injection
What it detects

Detects parseExpression, getValue, or setValue methods called with concatenated input.

Where it appears

Java files via expression + concatenation pattern matching

How to fix

Never evaluate expressions built from user input; use a fixed expression with bound variables.

SHIELD-JAVA-018criticalCWE-917Log4Shell JNDI Lookup Injection
What it detects

Detects jndi lookup patterns ${jndi:...} in logged data which can trigger remote code execution via Log4j.

Where it appears

Java files via JNDI pattern matching

How to fix

Upgrade Log4j and disable message lookups; never log unsanitized user input.

SHIELD-JS-001criticalCWE-89SQL Injection via string concatenation
What it detects

Detects SQL query methods (query, execute, db.run, pool.query) called with string concatenation using + operator.

Where it appears

JavaScript/TypeScript files via pattern matching on query method calls with + operator

How to fix

Use parameterized queries or prepared statements instead of string concatenation.

SHIELD-JS-002criticalCWE-89SQL Injection via template literal
What it detects

Detects SQL query methods called with template literal interpolation using backticks and ${}.

Where it appears

JavaScript/TypeScript files via template literal pattern matching

How to fix

Use parameterized queries with placeholders instead of template literals.

SHIELD-JS-005criticalCWE-95Dangerous eval() usage
What it detects

Detects calls to eval() function which executes arbitrary JavaScript code.

Where it appears

JavaScript/TypeScript files via eval() pattern matching

How to fix

Remove eval(). Use JSON.parse() for data or refactor to avoid dynamic code execution.

SHIELD-JS-009criticalCWE-78Command injection via exec/spawn
What it detects

Detects shell execution functions (exec, execSync, spawn) called with request.params/query/body.

Where it appears

JavaScript/TypeScript files via exec/spawn + request pattern matching

How to fix

Avoid passing user input to shell commands. Use execFile with an argument array instead of exec.

SHIELD-KOTLIN-001criticalCWE-89SQL injection via string interpolation in rawQuery/execSQL
What it detects

Detects SQLiteDatabase rawQuery/execSQL called with Kotlin string template interpolating a variable.

Where it appears

Kotlin files via rawQuery/execSQL + string interpolation pattern matching

How to fix

Use parameterized queries with selectionArgs placeholders instead of interpolating user input into SQL strings.

SHIELD-KOTLIN-002criticalCWE-89SQL injection via string concatenation in query APIs
What it detects

Detects SQL query methods called with + operator concatenation.

Where it appears

Kotlin files via SQL query + concatenation pattern matching

How to fix

Use PreparedStatement with bound parameters or selectionArgs rather than concatenating strings.

SHIELD-KOTLIN-003criticalCWE-78Command injection via Runtime.exec with variable
What it detects

Detects Runtime.getRuntime().exec invoked with an interpolated or concatenated variable.

Where it appears

Kotlin files via Runtime.exec + variable pattern matching

How to fix

Avoid shell execution with untrusted input; use a fixed argument array and validate inputs against an allowlist.

SHIELD-KOTLIN-004criticalCWE-78Command injection via ProcessBuilder with variable
What it detects

Detects ProcessBuilder constructed with an interpolated or concatenated variable.

Where it appears

Kotlin files via ProcessBuilder + variable pattern matching

How to fix

Pass a static list of arguments and never build the command line from untrusted data.

SHIELD-KOTLIN-007criticalCWE-502Insecure deserialization via ObjectInputStream.readObject
What it detects

Detects ObjectInputStream.readObject on untrusted data triggering remote code execution via gadget chains.

Where it appears

Kotlin files via ObjectInputStream.readObject pattern matching

How to fix

Avoid Java native deserialization of untrusted input; use a safe format like JSON with strict schemas.

SHIELD-KOTLIN-014criticalCWE-295Trust-all TrustManager or HostnameVerifier disables TLS validation
What it detects

Detects empty checkServerTrusted or HostnameVerifier that always returns true disabling certificate validation.

Where it appears

Kotlin files via trust-all pattern matching

How to fix

Perform full certificate and hostname validation; use certificate pinning for sensitive connections.

SHIELD-PHP-001criticalCWE-89SQL injection via string concatenation or interpolation
What it detects

Detects mysqli/PDO query calls built by concatenating or interpolating variables into the query.

Where it appears

PHP files via database query + concatenation/interpolation pattern matching

How to fix

Use parameterized queries with bound placeholders instead of building SQL from variables.

SHIELD-PHP-002criticalCWE-89SQL injection via mysql_query with user input
What it detects

Detects legacy mysql_query call including request superglobals or concatenated variables in the SQL.

Where it appears

PHP files via mysql_query + request pattern matching

How to fix

Migrate to PDO or mysqli with prepared statements and bound parameters.

SHIELD-PHP-003criticalCWE-78OS command injection via shell execution functions
What it detects

Detects shell execution functions (system, exec, shell_exec, passthru, popen, proc_open, pcntl_exec) with variables.

Where it appears

PHP files via shell execution function + variable pattern matching

How to fix

Avoid shell calls with user data; use escapeshellarg/escapeshellcmd or safe library APIs.

SHIELD-PHP-004criticalCWE-78Command injection via backtick shell operator
What it detects

Detects backtick execution operator running a shell command containing a variable.

Where it appears

PHP files via backtick shell operator + variable pattern matching

How to fix

Do not use backtick execution with variables; validate input and use escapeshellarg.

SHIELD-PHP-005criticalCWE-95Code injection via eval or assert on variables
What it detects

Detects eval, assert, or create_function receiving a variable allowing arbitrary PHP code execution.

Where it appears

PHP files via code execution function + variable pattern matching

How to fix

Never pass dynamic input to eval/assert; refactor to avoid dynamic code evaluation.

SHIELD-PHP-006criticalCWE-95Code injection via preg_replace /e modifier
What it detects

Detects preg_replace with the deprecated /e modifier which evaluates the replacement as PHP code.

Where it appears

PHP files via preg_replace + /e modifier pattern matching

How to fix

Replace the /e modifier with preg_replace_callback.

SHIELD-PHP-007criticalCWE-98File inclusion (LFI/RFI) via dynamic path
What it detects

Detects include/require with a variable path enabling local or remote file inclusion.

Where it appears

PHP files via include/require + variable pattern matching

How to fix

Include only from a fixed whitelist of allowed files; never use raw user input in paths.

SHIELD-PHP-009criticalCWE-502Unsafe deserialization of user input
What it detects

Detects unserialize called on request data allowing object injection and remote code execution.

Where it appears

PHP files via unserialize + request superglobal pattern matching

How to fix

Use json_decode for untrusted data or pass allowed_classes=>false to unserialize.

SHIELD-PY-001criticalCWE-89SQL Injection via string formatting
What it detects

Detects SQL execute methods called with % formatting, .format(), or f-string interpolation.

Where it appears

Python files via execute + string formatting pattern matching

How to fix

Use parameterized queries with ? or %s placeholders instead of string formatting.

SHIELD-PY-002criticalCWE-89SQL Injection via f-string interpolation
What it detects

Detects SQL execute/query methods called with f-string literals containing variable interpolation.

Where it appears

Python files via execute + f-string pattern matching

How to fix

Use parameterized queries. Never interpolate values directly into SQL strings.

SHIELD-PY-003criticalCWE-502Dangerous pickle deserialization
What it detects

Detects pickle.loads(), pickle.load(), or Unpickler calls which can deserialize arbitrary Python objects.

Where it appears

Python files via pickle deserialization pattern matching

How to fix

Use JSON or another safe serialization format instead of pickle for untrusted data.

SHIELD-PY-004criticalCWE-95Dangerous exec() usage
What it detects

Detects exec() function calls which execute arbitrary Python code.

Where it appears

Python files via exec() pattern matching

How to fix

Remove exec(). Refactor to use static code paths instead of dynamic code execution.

SHIELD-PY-005criticalCWE-78Shell injection via os.system
What it detects

Detects os.system() calls which execute shell commands with user input.

Where it appears

Python files via os.system() pattern matching

How to fix

Use subprocess.run() with a list of arguments and shell=False instead of os.system().

SHIELD-PY-008criticalCWE-95Insecure use of eval()
What it detects

Detects eval() calls which execute arbitrary Python code from strings.

Where it appears

Python files via eval() pattern matching

How to fix

Remove eval(). Use ast.literal_eval() for safe expression parsing of known data structures.

SHIELD-RUBY-001criticalCWE-89SQL injection via string interpolation in where
What it detects

Detects user input interpolated directly into an ActiveRecord where clause via #{} syntax.

Where it appears

Ruby files via where + string interpolation pattern matching

How to fix

Use parameterized queries with placeholders such as where("col = ?", value).

SHIELD-RUBY-002criticalCWE-89SQL injection via find_by_sql interpolation
What it detects

Detects variables interpolated into find_by_sql building a query vulnerable to SQL injection.

Where it appears

Ruby files via find_by_sql + interpolation pattern matching

How to fix

Pass an array with bind parameters to find_by_sql instead of interpolating.

SHIELD-RUBY-003criticalCWE-89SQL injection via execute interpolation
What it detects

Detects input interpolated into connection.execute allowing arbitrary SQL execution.

Where it appears

Ruby files via execute + interpolation pattern matching

How to fix

Use exec_query with bind parameters or sanitize input before executing raw SQL.

SHIELD-RUBY-004criticalCWE-78Command injection via system or exec with interpolation
What it detects

Detects interpolated string passed to system or exec which runs it through a shell.

Where it appears

Ruby files via system/exec + interpolation pattern matching

How to fix

Pass command and arguments as separate array elements to avoid shell interpretation.

SHIELD-RUBY-005criticalCWE-78Command injection via backticks or %x with interpolation
What it detects

Detects interpolated variables inside backticks or %x() executing attacker-controlled shell commands.

Where it appears

Ruby files via backticks/%x + interpolation pattern matching

How to fix

Use Open3.capture2 with an argument array instead of backticks or %x with interpolation.

SHIELD-RUBY-007criticalCWE-95Code injection via eval
What it detects

Detects variable or interpolated string passed to eval executing arbitrary Ruby code.

Where it appears

Ruby files via eval + variable/interpolation pattern matching

How to fix

Avoid eval on dynamic input; use a safe dispatch table or whitelist of allowed operations.

SHIELD-RUBY-012criticalCWE-502Unsafe deserialization via Marshal.load
What it detects

Detects Marshal.load on untrusted data which can instantiate arbitrary objects and execute code.

Where it appears

Ruby files via Marshal.load pattern matching

How to fix

Never deserialize untrusted data with Marshal; use JSON with a strict schema instead.

SHIELD-RUBY-013criticalCWE-502Unsafe deserialization via YAML.load or Oj object mode
What it detects

Detects YAML.load or Oj.load in object mode on untrusted input instantiating arbitrary Ruby objects.

Where it appears

Ruby files via YAML.load/Oj pattern matching

How to fix

Use YAML.safe_load or Oj with :strict mode to reject arbitrary object instantiation.

SHIELD-RUST-001criticalCWE-89SQL injection via format! in query
What it detects

Detects SQL query/execute methods called with format! string interpolation.

Where it appears

Rust files via query/execute + format! pattern matching

How to fix

Use parameterized queries with bind parameters instead of building SQL via format!.

SHIELD-RUST-002criticalCWE-89SQL injection via diesel sql_query with format!
What it detects

Detects diesel::sql_query built from format! interpolating untrusted values into raw SQL.

Where it appears

Rust files via sql_query + format! pattern matching

How to fix

Bind parameters with .bind() rather than interpolating into the SQL string.

SHIELD-RUST-004criticalCWE-78Command injection via interpolated argument
What it detects

Detects process argument passed via .arg() with format! allowing command injection.

Where it appears

Rust files via .arg + format! pattern matching

How to fix

Pass fixed arguments as separate .arg() values; never build args from untrusted input.

SHIELD-RUST-005criticalCWE-78Command execution via shell interpreter
What it detects

Detects Command::new spawning a shell (sh/bash/cmd/powershell/zsh) enabling command injection.

Where it appears

Rust files via Command::new + shell pattern matching

How to fix

Invoke the target binary directly with argument vectors instead of a shell.

SHIELD-RUST-013criticalCWE-295TLS certificate verification disabled
What it detects

Detects danger_accept_invalid_certs/hostnames enabled disabling TLS validation.

Where it appears

Rust files via danger_accept_invalid pattern matching

How to fix

Never disable certificate or hostname verification in production TLS clients.

SHIELD-SWIFT-001criticalCWE-89SQL injection via string interpolation
What it detects

Detects SQLite query built with Swift string interpolation via \() syntax.

Where it appears

Swift files via sqlite3_exec + string interpolation pattern matching

How to fix

Use sqlite3_prepare_v2 with bound parameters via sqlite3_bind_* instead of interpolating values.

SHIELD-SWIFT-002criticalCWE-89SQL injection via string concatenation
What it detects

Detects raw SQL query assembled with the concatenation operator + on variable input.

Where it appears

Swift files via SQL + concatenation pattern matching

How to fix

Use parameterized queries with bound placeholders rather than concatenating strings.

SHIELD-SWIFT-003criticalCWE-78Command injection via Process arguments
What it detects

Detects Process/NSTask launched with arguments derived from variable interpolation.

Where it appears

Swift files via Process.arguments + interpolation pattern matching

How to fix

Avoid shell interpolation and pass fixed argument arrays with validated inputs.

SHIELD-SWIFT-004criticalCWE-78Command injection via system call
What it detects

Detects shell command executed through system() or popen with interpolated data.

Where it appears

Swift files via system/popen + interpolation pattern matching

How to fix

Do not pass user data to a shell; use Process with an explicit argument array.

SHIELD-SWIFT-010criticalCWE-295Insecure TLS trust bypass
What it detects

Detects URLSession delegate returning a credential from serverTrust without validation.

Where it appears

Swift files via URLCredential(trust:) pattern matching

How to fix

Validate the server trust with SecTrustEvaluateWithError or pinning before accepting.

SHIELD-CPP-001highCWE-120Unbounded strcpy buffer overflow
What it detects

Detects strcpy() which copies without a length limit and can overflow the destination buffer.

Where it appears

C/C++ files via strcpy() pattern matching

How to fix

Use strncpy or strlcpy with an explicit bounded size and ensure null termination.

SHIELD-CPP-002highCWE-120Unbounded strcat buffer overflow
What it detects

Detects strcat() which appends without checking remaining destination capacity.

Where it appears

C/C++ files via strcat() pattern matching

How to fix

Use strncat or strlcat with the remaining buffer size accounted for.

SHIELD-CPP-003highCWE-120Unbounded sprintf buffer overflow
What it detects

Detects sprintf() or vsprintf() which write formatted output without a size limit.

Where it appears

C/C++ files via sprintf/vsprintf pattern matching

How to fix

Use snprintf or vsnprintf with an explicit buffer size.

SHIELD-CPP-005highCWE-120Unbounded scanf %s read
What it detects

Detects scanf() with %s format specifier which reads into a buffer without a width limit.

Where it appears

C/C++ files via scanf + %s pattern matching

How to fix

Specify a maximum field width such as %31s matching the buffer size.

SHIELD-CPP-006highCWE-134Non-constant format string
What it detects

Detects printf/vprintf called with a variable format string enabling format string attacks.

Where it appears

C/C++ files via printf + variable format pattern matching

How to fix

Always pass a constant format string such as printf("%s", var).

SHIELD-CPP-007highCWE-134Non-constant format string with stream target
What it detects

Detects fprintf/sprintf using a variable as the format argument enabling format string attacks.

Where it appears

C/C++ files via fprintf/sprintf + variable format pattern matching

How to fix

Pass an explicit constant format string instead of a variable.

SHIELD-CPP-010highCWE-78Exec with untrusted path
What it detects

Detects execl/execlp invoked with a variable program path allowing execution of attacker binaries.

Where it appears

C/C++ files via exec + variable path pattern matching

How to fix

Use absolute trusted paths and validate arguments before calling exec.

SHIELD-CPP-013highCWE-327Weak cryptographic primitive
What it detects

Detects use of DES, MD5, or SHA1 which provides broken or deprecated cryptographic strength.

Where it appears

C/C++ files via weak crypto pattern matching

How to fix

Use AES-GCM for encryption and SHA-256 or stronger for hashing.

SHIELD-CPP-014highCWE-327Insecure ECB cipher mode
What it detects

Detects EVP_*_ecb cipher mode usage which leaks plaintext structure and is not semantically secure.

Where it appears

C/C++ files via ECB cipher pattern matching

How to fix

Use an authenticated mode such as GCM with a unique nonce per message.

SHIELD-CPP-015highCWE-798Hardcoded credential literal
What it detects

Detects PASS, PASSWORD, SECRET, or APIKEY constants assigned string literals.

Where it appears

C/C++ files via hardcoded credential pattern matching

How to fix

Load secrets from environment variables or a secrets manager at runtime.

SHIELD-CPP-019highCWE-120memcpy with unchecked length
What it detects

Detects memcpy/memmove with a variable length from input which can overflow the destination buffer.

Where it appears

C/C++ files via memcpy/memmove + variable length pattern matching

How to fix

Validate the length against the destination capacity before copying.

SHIELD-CPP-021highCWE-338Insecure random for security tokens
What it detects

Detects rand/random/srand usage for security-sensitive values which is not cryptographically secure.

Where it appears

C/C++ files via insecure random pattern matching

How to fix

Use a CSPRNG such as getrandom or RAND_bytes for security-sensitive values.

SHIELD-CSHARP-005highCWE-78Command injection via ProcessStartInfo.Arguments from variable
What it detects

Detects ProcessStartInfo.Arguments assigned a value derived from concatenation or a raw variable.

Where it appears

C# files via ProcessStartInfo.Arguments + variable pattern matching

How to fix

Use ArgumentList with individually validated arguments instead of building a single Arguments string.

SHIELD-CSHARP-008highCWE-502Insecure deserialization via JavaScriptSerializer SimpleTypeResolver
What it detects

Detects JavaScriptSerializer constructed with a SimpleTypeResolver permitting arbitrary type deserialization.

Where it appears

C# files via JavaScriptSerializer + SimpleTypeResolver pattern matching

How to fix

Construct JavaScriptSerializer without a type resolver or migrate to System.Text.Json.

SHIELD-CSHARP-009highCWE-611XXE via unsafe DtdProcessing or XmlResolver
What it detects

Detects XML reader with DtdProcessing.Parse or XmlResolver assignment exposing parser to XXE attacks.

Where it appears

C# files via unsafe XML configuration pattern matching

How to fix

Set DtdProcessing to Prohibit and XmlResolver to null when parsing untrusted XML.

SHIELD-CSHARP-010highCWE-611XXE via XmlTextReader without resolver hardening
What it detects

Detects XmlTextReader created from a variable source without disabling DTD processing.

Where it appears

C# files via XmlTextReader + variable pattern matching

How to fix

Use XmlReader.Create with XmlReaderSettings that set DtdProcessing to Prohibit and XmlResolver to null.

SHIELD-CSHARP-011highCWE-327Weak or broken cryptographic algorithm
What it detects

Detects instantiation of weak ciphers (DES, TripleDES, RC2) or hashes (MD5, SHA1) for security use.

Where it appears

C# files via weak crypto algorithm pattern matching

How to fix

Use AES with an authenticated mode for encryption and SHA-256 or stronger for hashing.

SHIELD-CSHARP-012highCWE-327Insecure ECB cipher mode
What it detects

Detects symmetric cipher configured to use ECB mode which leaks plaintext patterns.

Where it appears

C# files via CipherMode.ECB pattern matching

How to fix

Use an authenticated mode such as GCM, or CBC with a random IV instead of ECB.

SHIELD-CSHARP-013highCWE-22Path traversal from request input into file API
What it detects

Detects file read or stream opened using a path derived directly from HTTP request input.

Where it appears

C# files via file operation + Request pattern matching

How to fix

Canonicalize and validate the path against an allowlisted base directory before opening the file.

SHIELD-CSHARP-014highCWE-918SSRF via request from variable-controlled URL
What it detects

Detects HTTP request target built from a variable allowing server-side request forgery.

Where it appears

C# files via WebRequest.Create/HttpClient + variable pattern matching

How to fix

Validate the URL host against an allowlist and reject internal or link-local addresses before making the request.

SHIELD-CSHARP-015highCWE-798Hardcoded credential in source
What it detects

Detects password, pwd, or ConnectionString variables assigned literal quoted strings of 3+ characters.

Where it appears

C# files via hardcoded credential pattern matching

How to fix

Load secrets from a secrets manager, environment variable, or protected configuration store.

SHIELD-CSHARP-017highCWE-90LDAP injection via DirectorySearcher filter
What it detects

Detects DirectorySearcher filter built by concatenating untrusted input into the LDAP query.

Where it appears

C# files via DirectorySearcher.Filter + concatenation pattern matching

How to fix

Escape LDAP special characters in user input before building the search filter.

SHIELD-CSHARP-018highCWE-79Reflected XSS via Response.Write or Html.Raw
What it detects

Detects Response.Write with HTTP request input or Html.Raw usage on user-controlled content.

Where it appears

C# files via Response.Write/Html.Raw + request pattern matching

How to fix

HTML-encode untrusted output and avoid Html.Raw for user-controlled content.

SHIELD-CSHARP-019highCWE-295Trust-all TLS certificate validation
What it detects

Detects certificate validation callback overridden to always return true, disabling TLS trust checks.

Where it appears

C# files via certificate validation callback pattern matching

How to fix

Perform proper certificate chain and hostname validation instead of returning true unconditionally.

SHIELD-CSHARP-021highCWE-470Unsafe reflection from user-controlled type name
What it detects

Detects Type.GetType or Activator.CreateInstance invoked with a variable type name from untrusted input.

Where it appears

C# files via reflection + variable type pattern matching

How to fix

Map user input to an allowlisted set of known types rather than resolving arbitrary type names.

SHIELD-DART-003highCWE-78Command injection via interpolated process arguments
What it detects

Detects Process call with interpolated variable arguments manipulated to run arbitrary commands.

Where it appears

Dart files via Process + variable pattern matching

How to fix

Validate and whitelist arguments and never pass raw user input to a process invocation.

SHIELD-DART-004highCWE-79WebView JavaScript injection
What it detects

Detects evaluateJavascript/runJavascript with JavaScript built from variables enabling script injection.

Where it appears

Dart files via WebView JavaScript + variable pattern matching

How to fix

JSON-encode values passed into WebView JavaScript and avoid injecting raw user input.

SHIELD-DART-007highCWE-327Weak cryptographic hash
What it detects

Detects MD5 or SHA-1 from the crypto package which are broken and unsuitable for passwords.

Where it appears

Dart files via weak hash pattern matching

How to fix

Use SHA-256 or stronger, and bcrypt, scrypt, or Argon2 for password hashing.

SHIELD-DART-008highCWE-798Hardcoded secret credential
What it detects

Detects password, apiKey, secret, or token variables assigned literal strings.

Where it appears

Dart files via hardcoded secret pattern matching

How to fix

Load secrets from secure storage or environment configuration, never from source literals.

SHIELD-DART-009highCWE-312Sensitive data in insecure storage
What it detects

Detects passwords/tokens stored in SharedPreferences which saves them in plaintext.

Where it appears

Dart files via SharedPreferences + sensitive keyword pattern matching

How to fix

Use flutter_secure_storage or the platform keystore for sensitive values.

SHIELD-DART-010highCWE-22Path traversal via unsanitized file path
What it detects

Detects File constructed from request-derived input allowing path traversal.

Where it appears

Dart files via File + request pattern matching

How to fix

Canonicalize the path and verify it stays within an allowed base directory.

SHIELD-DART-011highCWE-918SSRF via user-controlled request URL
What it detects

Detects http HTTP methods with variable URLs letting attackers force requests to internal services.

Where it appears

Dart files via http + Uri.parse + variable pattern matching

How to fix

Validate the URL against an allowlist of trusted hosts before making the request.

SHIELD-DART-014highCWE-749WebView with unrestricted JavaScript mode
What it detects

Detects WebView using unrestricted JavaScript mode exposing loaded content to full script execution.

Where it appears

Dart files via JavascriptMode.unrestricted pattern matching

How to fix

Disable JavaScript unless required, restrict file access, and load only trusted content.

SHIELD-GEN-005highCWE-798Generic API key or secret pattern
What it detects

Matches patterns where api_key, api_secret, client_secret, or access_token are assigned values of 20+ alphanumeric characters.

Where it appears

All languages via assignment pattern matching

How to fix

Move secrets to environment variables or a secrets manager.

SHIELD-GEN-007highCWE-798Slack webhook URL exposed
What it detects

Matches Slack webhook URL pattern (hooks.slack.com/services/...) which allows posting messages to channels without authentication.

Where it appears

All languages via Slack webhook pattern matching

How to fix

Revoke and rotate the Slack webhook URL. Store it in an environment variable.

SHIELD-GEN-009highCWE-798Database password hardcoded in connection string
What it detects

Matches database connection string patterns (postgres://, mysql://, mongodb://, redis://) with embedded username:password credentials.

Where it appears

All languages via connection string pattern matching

How to fix

Use environment variables for database connection strings. Never commit credentials.

SHIELD-GO-003highCWE-327Weak cryptographic hash (MD5)
What it detects

Detects md5.New() or md5.Sum() calls which are cryptographically broken.

Where it appears

Go files via md5 pattern matching

How to fix

Use crypto/sha256 or crypto/sha512 instead of crypto/md5.

SHIELD-GO-004highCWE-327Weak cryptographic hash (SHA1)
What it detects

Detects sha1.New() or sha1.Sum() calls which are cryptographically weak.

Where it appears

Go files via sha1 pattern matching

How to fix

Use crypto/sha256 or crypto/sha512 instead of crypto/sha1.

SHIELD-GO-006highCWE-22Path traversal via user-controlled filepath
What it detects

Detects file operations (os.Open, Create, ReadFile, WriteFile) with user input from HTTP request.

Where it appears

Go files via file operation + request pattern matching

How to fix

Use filepath.Clean() and verify the path is within the allowed base directory.

SHIELD-GO-008highCWE-295TLS InsecureSkipVerify enabled
What it detects

Detects InsecureSkipVerify: true in TLS configuration which disables certificate validation.

Where it appears

Go files via InsecureSkipVerify: true pattern matching

How to fix

Never set InsecureSkipVerify to true in production. Fix the TLS certificate instead.

SHIELD-GO-009highCWE-798Hardcoded password or secret
What it detects

Detects password, secret, apiKey, token, or passwd variables assigned quoted strings of 8+ characters.

Where it appears

Go files via hardcoded credential pattern matching

How to fix

Use environment variables or a secrets manager instead of hardcoded credentials.

SHIELD-GO-010highCWE-918Server-Side Request Forgery via http.Get with user input
What it detects

Detects http.Get, http.Post, or http.Do with user-controlled URLs from request.

Where it appears

Go files via http method + request pattern matching

How to fix

Validate URLs against an allowlist before making outbound HTTP requests.

SHIELD-JAVA-006highCWE-611XXE via DocumentBuilderFactory
What it detects

Detects DocumentBuilderFactory.newInstance() without disabling external entities.

Where it appears

Java files via DocumentBuilderFactory pattern matching

How to fix

Call setFeature to disable doctype declarations and external general and parameter entities.

SHIELD-JAVA-007highCWE-611XXE via SAXParserFactory
What it detects

Detects SAXParserFactory.newInstance() without disabling external entities.

Where it appears

Java files via SAXParserFactory pattern matching

How to fix

Disable external entities and DTDs via setFeature before parsing untrusted XML.

SHIELD-JAVA-008highCWE-327Weak Cipher Algorithm
What it detects

Detects Cipher.getInstance() using DES, RC4, or ECB mode which provides inadequate confidentiality.

Where it appears

Java files via Cipher weak algorithm pattern matching

How to fix

Use AES in GCM or another authenticated mode with a securely managed key.

SHIELD-JAVA-010highCWE-798Hardcoded Credentials
What it detects

Detects password, secret, apikey, or token variables assigned string literals.

Where it appears

Java files via hardcoded credential pattern matching

How to fix

Load secrets from environment variables or a secrets manager, never from source code.

SHIELD-JAVA-011highCWE-22Path Traversal via File Construction
What it detects

Detects File constructor with request-derived input (request, getParameter, params, userInput) without validation.

Where it appears

Java files via File + request pattern matching

How to fix

Canonicalize the path and verify it stays within an allowed base directory.

SHIELD-JAVA-012highCWE-918SSRF via URL openConnection
What it detects

Detects new URL(variable).openConnection() which allows SSRF attacks.

Where it appears

Java files via URL.openConnection + variable pattern matching

How to fix

Validate the target against an allowlist of permitted hosts and protocols before connecting.

SHIELD-JAVA-013highCWE-90LDAP Injection via Concatenated Filter
What it detects

Detects LDAP search filter built with string concatenation which permits LDAP injection.

Where it appears

Java files via LDAP search + concatenation pattern matching

How to fix

Escape LDAP special characters or use parameterized search with encoded filter values.

SHIELD-JAVA-016highCWE-470Unsafe Reflection via Class.forName with Variable
What it detects

Detects Class.forName() loading a class from a variable enabling attacker-controlled class loading.

Where it appears

Java files via Class.forName + variable pattern matching

How to fix

Restrict loadable classes to an allowlist rather than instantiating from raw input.

SHIELD-JS-003highCWE-79Cross-Site Scripting (XSS) via innerHTML
What it detects

Detects .innerHTML assignment which can inject unescaped HTML when used with user-controlled data.

Where it appears

JavaScript/TypeScript files via .innerHTML pattern matching

How to fix

Use textContent or sanitize input with a library like DOMPurify before setting innerHTML.

SHIELD-JS-004highCWE-79Cross-Site Scripting (XSS) via document.write
What it detects

Detects document.write() calls which can inject user input directly into the DOM.

Where it appears

JavaScript/TypeScript files via document.write pattern matching

How to fix

Avoid document.write; use DOM manipulation methods instead.

SHIELD-JS-006highCWE-95Dangerous Function() constructor
What it detects

Detects new Function() which dynamically compiles code and is equivalent to eval().

Where it appears

JavaScript/TypeScript files via Function constructor pattern matching

How to fix

Avoid the Function constructor. Refactor to static functions.

SHIELD-JS-007highCWE-1321Prototype pollution via merge/assign
What it detects

Detects patterns accessing __proto__, constructor.prototype, or prototype.__proto__ in merge operations.

Where it appears

JavaScript/TypeScript files via prototype pollution pattern matching

How to fix

Sanitize object keys before merging. Use Object.create(null) for dictionaries.

SHIELD-JS-008highCWE-22Path traversal via user input
What it detects

Detects file read/write methods (readFile, createReadStream, writeFile) called with request.params/query/body.

Where it appears

JavaScript/TypeScript files via file method + request pattern matching

How to fix

Validate and sanitize file paths. Use path.resolve() and check against an allowed base directory.

SHIELD-JS-011highCWE-798Hardcoded password or secret
What it detects

Detects password, secret, apikey, token, or passwd variables assigned quoted strings of 8+ characters.

Where it appears

JavaScript/TypeScript files via hardcoded credential pattern matching

How to fix

Store secrets in environment variables or a secrets manager. Never hardcode credentials.

SHIELD-JS-014highCWE-295Disabled TLS/SSL certificate verification
What it detects

Detects rejectUnauthorized: false configuration which disables certificate verification.

Where it appears

JavaScript/TypeScript files via rejectUnauthorized: false pattern

How to fix

Never disable certificate verification in production. Fix the certificate instead.

SHIELD-JS-016highCWE-918Server-Side Request Forgery (SSRF) via user-controlled URL
What it detects

Detects fetch, axios, or http methods called with request.params/query/body allowing SSRF attacks.

Where it appears

JavaScript/TypeScript files via fetch/axios + request pattern matching

How to fix

Validate and allowlist URLs before making server-side HTTP requests.

SHIELD-KOTLIN-005highCWE-749WebView addJavascriptInterface exposes native code to JS
What it detects

Detects WebView.addJavascriptInterface bridging JavaScript to native objects enabling remote code execution.

Where it appears

Kotlin files via addJavascriptInterface pattern matching

How to fix

Avoid addJavascriptInterface for untrusted content; if required, target API 17+ and annotate exposed methods with @JavascriptInterface.

SHIELD-KOTLIN-006highCWE-79JavaScript injection via WebView loadUrl/evaluateJavascript
What it detects

Detects concatenating or interpolating a variable into WebView loadUrl('javascript:') or evaluateJavascript.

Where it appears

Kotlin files via WebView JavaScript + variable pattern matching

How to fix

Never inject untrusted data into JavaScript; encode values or pass them via safe message channels.

SHIELD-KOTLIN-008highCWE-327Weak or ECB-mode cipher via Cipher.getInstance
What it detects

Detects Cipher requesting DES, RC4, or AES in ECB mode providing inadequate confidentiality.

Where it appears

Kotlin files via Cipher weak algorithm/mode pattern matching

How to fix

Use AES in GCM mode (AES/GCM/NoPadding) with a securely generated random IV.

SHIELD-KOTLIN-010highCWE-798Hardcoded secret in source
What it detects

Detects password, api_key, secret, token, or access_key variable assigned a literal string constant.

Where it appears

Kotlin files via hardcoded secret pattern matching

How to fix

Load secrets from the Android Keystore, encrypted storage, or a secure server-side configuration.

SHIELD-KOTLIN-011highCWE-22Path traversal via File/FileInputStream with request input
What it detects

Detects File/FileInputStream constructed from request-derived input allowing path traversal.

Where it appears

Kotlin files via File + request pattern matching

How to fix

Canonicalize the path and verify it stays within an allowed base directory before opening.

SHIELD-KOTLIN-012highCWE-918SSRF via URL(variable).openConnection
What it detects

Detects URL constructor with variable enabling SSRF attacks to internal services.

Where it appears

Kotlin files via URL + variable pattern matching

How to fix

Validate the target host against an allowlist and reject internal or link-local addresses.

SHIELD-KOTLIN-015highCWE-732World-readable or world-writable file mode
What it detects

Detects MODE_WORLD_READABLE or MODE_WORLD_WRITEABLE exposing app files to other applications.

Where it appears

Kotlin files via MODE_WORLD pattern matching

How to fix

Use MODE_PRIVATE and store sensitive data with EncryptedSharedPreferences or the Keystore.

SHIELD-KOTLIN-017highCWE-312Password stored in plaintext SharedPreferences
What it detects

Detects password/token/secret written into standard SharedPreferences stored unencrypted.

Where it appears

Kotlin files via SharedPreferences + sensitive keyword pattern matching

How to fix

Use EncryptedSharedPreferences (Jetpack Security) or the Android Keystore for sensitive values.

SHIELD-KOTLIN-018highCWE-749WebView JavaScript enabled with file access
What it detects

Detects WebView with JavaScript and file access enabled allowing local file exfiltration.

Where it appears

Kotlin files via WebView JavaScript + file access pattern matching

How to fix

Disable file access for WebViews that render remote content and only enable JavaScript when strictly required.

SHIELD-PHP-008highCWE-79Reflected XSS via echo of request data
What it detects

Detects request superglobal echoed or printed without output encoding enabling cross-site scripting.

Where it appears

PHP files via echo/print + request superglobal pattern matching

How to fix

Encode output with htmlspecialchars() using ENT_QUOTES before echoing user input.

SHIELD-PHP-010highCWE-22Path traversal via file read with request data
What it detects

Detects file read functions receiving request data directly allowing path traversal.

Where it appears

PHP files via file read + request superglobal pattern matching

How to fix

Canonicalize with realpath() and confirm the path stays within an allowed base directory.

SHIELD-PHP-011highCWE-918Server-side request forgery via dynamic URL
What it detects

Detects curl target or file_get_contents URL built from a variable enabling SSRF.

Where it appears

PHP files via curl/file_get_contents + variable pattern matching

How to fix

Validate and allowlist destination hosts; reject internal/link-local addresses.

SHIELD-PHP-012highCWE-916Weak hashing algorithm for passwords
What it detects

Detects md5 or sha1 used to hash sensitive password values which are cryptographically weak.

Where it appears

PHP files via weak hash + password pattern matching

How to fix

Use password_hash() with PASSWORD_DEFAULT and verify with password_verify().

SHIELD-PHP-013highCWE-327Insecure legacy encryption (mcrypt DES/ECB)
What it detects

Detects deprecated mcrypt with DES or ECB mode which provides weak, insecure encryption.

Where it appears

PHP files via mcrypt pattern matching

How to fix

Use openssl or sodium with AES-GCM or a modern authenticated cipher.

SHIELD-PHP-014highCWE-798Hardcoded credentials in source
What it detects

Detects password, pwd, db_pass, secret, or api_key constants assigned literal strings.

Where it appears

PHP files via hardcoded credential pattern matching

How to fix

Load credentials from environment variables or a secrets manager, not from source.

SHIELD-PHP-016highCWE-697Type juggling in loose comparison of hashes
What it detects

Detects loose == comparison against hash function result enabling type juggling authentication bypass.

Where it appears

PHP files via hash comparison pattern matching

How to fix

Use strict === comparison or hash_equals() for constant-time hash comparison.

SHIELD-PHP-018highCWE-621Variable overwrite via extract on request data
What it detects

Detects extract() applied to request superglobals allowing attackers to overwrite arbitrary local variables.

Where it appears

PHP files via extract + request superglobal pattern matching

How to fix

Avoid extract() on user input; access specific request keys explicitly.

SHIELD-PY-006highCWE-78Shell injection via subprocess with shell=True
What it detects

Detects subprocess calls (run, Popen, call, check_output) with shell=True parameter.

Where it appears

Python files via subprocess + shell=True pattern matching

How to fix

Use shell=False (default) and pass arguments as a list to avoid shell injection.

SHIELD-PY-007highCWE-918Server-Side Request Forgery (SSRF) via requests with user input
What it detects

Detects requests HTTP methods called with request.args/form/json/data/values.

Where it appears

Python files via requests + request pattern matching

How to fix

Validate and allowlist URLs before making outbound HTTP requests.

SHIELD-PY-009highCWE-22Path traversal via open()
What it detects

Detects open() calls with user-controlled paths from request.args/form/json/values.

Where it appears

Python files via open + request pattern matching

How to fix

Validate file paths using os.path.realpath() and check against an allowed base directory.

SHIELD-PY-011highCWE-798Hardcoded password or secret
What it detects

Detects PASSWORD, SECRET, API_KEY, TOKEN, or PASSWD constants assigned quoted strings of 8+ characters.

Where it appears

Python files via hardcoded credential pattern matching

How to fix

Store secrets in environment variables or a secrets manager. Never hardcode credentials.

SHIELD-PY-012highCWE-94Flask debug mode enabled
What it detects

Detects app.run() with debug=True parameter which enables interactive debugger in production.

Where it appears

Python files via Flask debug=True pattern matching

How to fix

Disable debug mode in production. Use environment variables to control debug settings.

SHIELD-PY-013highCWE-502YAML deserialization with yaml.load (unsafe)
What it detects

Detects yaml.load() without Loader parameter which can deserialize arbitrary Python objects.

Where it appears

Python files via yaml.load pattern matching

How to fix

Use yaml.safe_load() instead of yaml.load() to prevent arbitrary object deserialization.

SHIELD-PY-015highCWE-611XML External Entity (XXE) injection
What it detects

Detects XML parsing via xml.etree.ElementTree or lxml.etree without disabling external entities.

Where it appears

Python files via XML parsing pattern matching

How to fix

Disable external entity processing. Use defusedxml library for safe XML parsing.

SHIELD-PY-016highCWE-502Insecure deserialization with marshal
What it detects

Detects marshal.loads() or marshal.load() which can cause crashes or arbitrary code execution.

Where it appears

Python files via marshal deserialization pattern matching

How to fix

Do not deserialize untrusted data with marshal. Use JSON for data interchange.

SHIELD-RUBY-006highCWE-78Command injection via Open3 or spawn with variable
What it detects

Detects single interpolated string passed to Open3/spawn which invokes a shell and permits injection.

Where it appears

Ruby files via Open3/spawn + interpolation pattern matching

How to fix

Provide the command and each argument as distinct array elements to Open3 or spawn.

SHIELD-RUBY-008highCWE-95Code injection via instance_eval or class_eval
What it detects

Detects instance_eval/class_eval on dynamic input executing arbitrary code in an object or class context.

Where it appears

Ruby files via instance_eval/class_eval + dynamic input pattern matching

How to fix

Do not evaluate user-supplied strings; refactor to call known methods directly.

SHIELD-RUBY-009highCWE-94Unsafe method dispatch via send with user input
What it detects

Detects send/public_send called with a params-derived method name allowing arbitrary method invocation.

Where it appears

Ruby files via send + params pattern matching

How to fix

Whitelist allowed method names before dispatching with send.

SHIELD-RUBY-010highCWE-915Mass assignment via permit bang
What it detects

Detects permit! call which bypasses strong parameter filtering allowing assignment of any attribute.

Where it appears

Ruby files via permit! pattern matching

How to fix

Explicitly permit only the required attributes with permit(:a, :b).

SHIELD-RUBY-011highCWE-915Mass assignment via update with raw params
What it detects

Detects unfiltered params passed directly to update/assign_attributes allowing mass assignment.

Where it appears

Ruby files via update + params pattern matching

How to fix

Filter params through strong parameters before passing them to update.

SHIELD-RUBY-014highCWE-918SSRF via open-uri or Net::HTTP with variable URL
What it detects

Detects URI.open/Net::HTTP.get with user input or interpolated URL allowing server-side request forgery.

Where it appears

Ruby files via open-uri/Net::HTTP + variable URL pattern matching

How to fix

Validate the URL against an allowlist of hosts and schemes before fetching.

SHIELD-RUBY-015highCWE-22Path traversal via File or send_file with params
What it detects

Detects file path built from params in File.read/File.open/send_file enabling path traversal.

Where it appears

Ruby files via file operation + params pattern matching

How to fix

Resolve the path and confirm it stays within an allowed base directory before access.

SHIELD-RUBY-016highCWE-79XSS via raw or html_safe on dynamic data
What it detects

Detects raw() or .html_safe on interpolated/variable content outputting unescaped HTML.

Where it appears

Ruby files via raw/html_safe + dynamic data pattern matching

How to fix

Let Rails auto-escape output or sanitize with the sanitize helper instead of raw or html_safe.

SHIELD-RUBY-017highCWE-79XSS via unescaped ERB output tag
What it detects

Detects <%== unescaped ERB output tag which renders content without HTML escaping.

Where it appears

Ruby files via <%== pattern matching

How to fix

Use the escaping ERB tag and only bypass escaping for content you fully control.

SHIELD-RUBY-019highCWE-798Hardcoded secret or password
What it detects

Detects password, secret_key, api_key, secret_token, or access_key assigned literal values.

Where it appears

Ruby files via hardcoded secret pattern matching

How to fix

Load secrets from environment variables or Rails encrypted credentials.

SHIELD-RUBY-022highCWE-470Remote code execution via constantize with user input
What it detects

Detects constantize/qualified_const_get on params instantiating unintended classes.

Where it appears

Ruby files via constantize + params pattern matching

How to fix

Map user input to allowed classes through an explicit whitelist rather than constantize.

SHIELD-RUST-003highCWE-89SQL injection via string concatenation
What it detects

Detects SQL query methods called with + operator concatenating variables.

Where it appears

Rust files via query/execute + concatenation pattern matching

How to fix

Use bound parameters instead of concatenating query fragments.

SHIELD-RUST-008highCWE-327Weak cryptographic hash
What it detects

Detects MD5/SHA-1/DES usage which are cryptographically broken and unsuitable for security.

Where it appears

Rust files via weak hash pattern matching

How to fix

Use SHA-256+ for hashing and Argon2/bcrypt/scrypt for passwords.

SHIELD-RUST-009highCWE-798Hardcoded credential
What it detects

Detects password, secret, api_key, or token variable assigned a quoted string literal.

Where it appears

Rust files via hardcoded credential pattern matching

How to fix

Load secrets from environment variables or a secrets manager, never from source.

SHIELD-RUST-011highCWE-918SSRF via user-controlled request URL
What it detects

Detects reqwest/http methods called with format! URL allowing SSRF to internal hosts.

Where it appears

Rust files via HTTP method + format! URL pattern matching

How to fix

Validate the URL against an allowlist of hosts and block private/link-local ranges.

SHIELD-RUST-012highCWE-22Path traversal via user-controlled file path
What it detects

Detects File operations called with format! path enabling directory traversal.

Where it appears

Rust files via file operation + format! path pattern matching

How to fix

Canonicalize the path and verify it stays within an allowed base directory.

SHIELD-RUST-015highCWE-89SQL statement built with format!
What it detects

Detects SQL query assembled with format! which interpolates values into the statement.

Where it appears

Rust files via format! SQL pattern matching

How to fix

Build queries with bound parameters instead of format!; never interpolate values into SQL text.

SHIELD-SWIFT-005highCWE-79WebView JavaScript injection
What it detects

Detects evaluateJavaScript called with a string containing interpolated variable data.

Where it appears

Swift files via evaluateJavaScript + interpolation pattern matching

How to fix

Pass data via WKScriptMessageHandler or JSON-encode and escape values before injection.

SHIELD-SWIFT-006highCWE-79WebView HTML injection via loadHTMLString
What it detects

Detects loadHTMLString rendering HTML built from interpolated variable data.

Where it appears

Swift files via loadHTMLString + interpolation pattern matching

How to fix

Sanitize and HTML-encode user data before embedding it into loaded markup.

SHIELD-SWIFT-007highCWE-327Weak hash for password
What it detects

Detects MD5 or SHA1 used to hash passwords which is cryptographically broken.

Where it appears

Swift files via weak hash pattern matching

How to fix

Use a memory-hard KDF such as Argon2, scrypt, or PBKDF2 with a salt for passwords.

SHIELD-SWIFT-008highCWE-327Insecure DES or ECB cipher
What it detects

Detects DES algorithm or ECB mode usage which are both insecure.

Where it appears

Swift files via weak cipher algorithm/mode pattern matching

How to fix

Use AES-GCM or another authenticated cipher with a secure mode instead of DES or ECB.

SHIELD-SWIFT-009highCWE-798Hardcoded secret in source
What it detects

Detects password, api_key, secret, token, or access_key variable assigned a hardcoded string literal.

Where it appears

Swift files via hardcoded secret pattern matching

How to fix

Load secrets from the Keychain or a secure configuration service, never from source.

SHIELD-SWIFT-011highCWE-319Arbitrary insecure HTTP loads allowed
What it detects

Detects App Transport Security disabled via NSAllowsArbitraryLoads or insecure HTTP exceptions.

Where it appears

Swift files via ATS exception pattern matching

How to fix

Remove the ATS exception and require HTTPS with valid certificates for all endpoints.

SHIELD-SWIFT-012highCWE-922Sensitive data stored in UserDefaults
What it detects

Detects password or token persisted in UserDefaults which is unencrypted.

Where it appears

Swift files via UserDefaults + sensitive keyword pattern matching

How to fix

Store credentials in the Keychain with an appropriate accessibility class instead of UserDefaults.

SHIELD-SWIFT-013highCWE-22Path traversal via file read
What it detects

Detects file read from a path built with interpolated variable data.

Where it appears

Swift files via Data(contentsOf:URL) + interpolation pattern matching

How to fix

Canonicalize the path and confine it to an allowed base directory before reading.

SHIELD-SWIFT-014highCWE-918SSRF via dynamic URL request
What it detects

Detects URLSession request targeting a URL constructed from variable input.

Where it appears

Swift files via URL + variable pattern matching

How to fix

Validate the host against an allowlist before issuing outbound requests.

SHIELD-SWIFT-015highCWE-338Insecure random for security token
What it detects

Detects arc4random or non-cryptographic random source used to generate a token.

Where it appears

Swift files via insecure random + token pattern matching

How to fix

Generate security tokens with SecRandomCopyBytes for cryptographic strength.

SHIELD-CPP-011mediumCWE-190Integer overflow in malloc size
What it detects

Detects malloc/calloc/realloc with a multiplied size which can overflow and allocate too little.

Where it appears

C/C++ files via allocation + multiplication pattern matching

How to fix

Use calloc or check for multiplication overflow before allocating.

SHIELD-CPP-012mediumCWE-770Dangerous alloca or VLA with variable size
What it detects

Detects alloca() with a variable size which can exhaust the stack and cause overflow.

Where it appears

C/C++ files via alloca + variable size pattern matching

How to fix

Use heap allocation with a validated bounded size instead of alloca.

SHIELD-CPP-016mediumCWE-377Insecure temporary file creation
What it detects

Detects mktemp/tmpnam/tempnam calls which generate predictable names vulnerable to symlink attacks.

Where it appears

C/C++ files via insecure temp pattern matching

How to fix

Use mkstemp which atomically creates and opens a unique file.

SHIELD-CPP-017mediumCWE-22File open with untrusted path
What it detects

Detects fopen/open with a variable path allowing path traversal to unintended files.

Where it appears

C/C++ files via file open + variable path pattern matching

How to fix

Canonicalize the path with realpath and confirm it stays inside an allowed directory.

SHIELD-CPP-018mediumCWE-367TOCTOU race with access then open
What it detects

Detects access() call which creates a time-of-check to time-of-use race condition.

Where it appears

C/C++ files via access() pattern matching

How to fix

Open the file first and check permissions on the resulting descriptor with fstat.

SHIELD-CPP-020mediumCWE-170strncpy without null termination
What it detects

Detects strncpy() calls which may leave the destination without a null terminator.

Where it appears

C/C++ files via strncpy pattern matching

How to fix

Explicitly set the final byte to zero or use strlcpy.

SHIELD-CSHARP-016mediumCWE-338Insecure random used for security tokens
What it detects

Detects System.Random usage with Next/NextBytes/NextDouble for security tokens.

Where it appears

C# files via Random pattern matching

How to fix

Use RandomNumberGenerator or RNGCryptoServiceProvider for security-sensitive random values.

SHIELD-CSHARP-020mediumCWE-601Open redirect from request input
What it detects

Detects Response.Redirect targeting a URL taken directly from HTTP request input.

Where it appears

C# files via Response.Redirect + request pattern matching

How to fix

Validate redirect targets against an allowlist of trusted local paths or hosts.

SHIELD-DART-006mediumCWE-319Insecure cleartext HTTP endpoint
What it detects

Detects cleartext http:// URLs which transmit data without encryption.

Where it appears

Dart files via http:// pattern matching

How to fix

Use HTTPS endpoints and enforce TLS for all network requests.

SHIELD-DART-012mediumCWE-338Insecure random for security tokens
What it detects

Detects Random() usage which is not cryptographically secure for tokens or secrets.

Where it appears

Dart files via Random pattern matching

How to fix

Use Random.secure() for any security-sensitive random value.

SHIELD-DART-013mediumCWE-532Sensitive data logged to console
What it detects

Detects print/debugPrint/log statements leaking passwords or tokens into device logs.

Where it appears

Dart files via logging + sensitive keyword pattern matching

How to fix

Remove secrets from log output or redact them before logging.

SHIELD-GEN-001mediumCWE-284Hardcoded IP address
What it detects

Detects hardcoded IP addresses in source code which can expose internal network topology and reduce flexibility.

Where it appears

All languages via regex pattern matching for IPv4 addresses

How to fix

Use configuration files or environment variables instead of hardcoded IP addresses.

SHIELD-GEN-010mediumCWE-295Disabled SSL/TLS verify in curl command
What it detects

Detects curl usage with -k or --insecure flags which disable certificate validation, enabling MITM attacks.

Where it appears

All languages via curl flag pattern matching

How to fix

Remove -k/--insecure from curl commands. Fix the TLS certificate instead.

SHIELD-GO-005mediumCWE-338Insecure random number generation via math/rand
What it detects

Detects math/rand functions (Intn, Int63, Float64, New, Seed) which are not cryptographically secure.

Where it appears

Go files via math/rand pattern matching

How to fix

Use crypto/rand for security-sensitive randomness.

SHIELD-GO-011mediumCWE-601Open redirect via http.Redirect with user input
What it detects

Detects http.Redirect called with user input from request URL, Form, PostForm, or Header.

Where it appears

Go files via http.Redirect + request pattern matching

How to fix

Validate redirect targets against an allowlist of permitted URLs.

SHIELD-JAVA-009mediumCWE-327Weak Hash Algorithm
What it detects

Detects MessageDigest.getInstance() using MD5 or SHA-1 which are cryptographically broken.

Where it appears

Java files via MessageDigest weak algorithm pattern matching

How to fix

Use SHA-256 or stronger; for passwords use bcrypt, scrypt, or Argon2.

SHIELD-JAVA-015mediumCWE-330Insecure Randomness for Security Tokens
What it detects

Detects new Random() usage for security tokens yielding predictable values.

Where it appears

Java files via Random constructor pattern matching

How to fix

Use java.security.SecureRandom for tokens, session IDs, and any security-sensitive values.

SHIELD-JS-010mediumCWE-338Insecure random number generation
What it detects

Detects Math.random() usage which is not cryptographically secure for security-sensitive operations.

Where it appears

JavaScript/TypeScript files via Math.random() pattern matching

How to fix

Use crypto.getRandomValues() or crypto.randomBytes() for security-sensitive randomness.

SHIELD-JS-012mediumCWE-319Insecure HTTP usage (non-HTTPS)
What it detects

Detects http:// URLs in code which expose data to interception.

Where it appears

JavaScript/TypeScript files via http:// pattern matching

How to fix

Use HTTPS for all external connections.

SHIELD-JS-013mediumCWE-601Open redirect via res.redirect
What it detects

Detects res.redirect() called with request.params/query/body which can redirect to attacker-controlled URLs.

Where it appears

JavaScript/TypeScript files via res.redirect + request pattern matching

How to fix

Validate redirect URLs against an allowlist of trusted destinations.

SHIELD-JS-015mediumCWE-532Sensitive data in console.log
What it detects

Detects console logging statements (log, info, debug, warn) containing password, token, secret, or apikey keywords.

Where it appears

JavaScript/TypeScript files via console logging + sensitive keyword pattern matching

How to fix

Remove sensitive data from log statements. Use structured logging with redaction.

SHIELD-JS-017mediumCWE-1333Regex Denial of Service (ReDoS) — catastrophic backtracking
What it detects

Detects new RegExp() constructed from request.params/query/body which can cause exponential backtracking.

Where it appears

JavaScript/TypeScript files via RegExp + request pattern matching

How to fix

Never construct regexes from user input. Use a safe regex library or validate input first.

SHIELD-KOTLIN-009mediumCWE-327Weak hash algorithm via MessageDigest.getInstance
What it detects

Detects MessageDigest with MD5 or SHA-1 which are cryptographically broken.

Where it appears

Kotlin files via MessageDigest weak algorithm pattern matching

How to fix

Use SHA-256 or stronger, and for passwords use a KDF such as bcrypt, scrypt, or PBKDF2.

SHIELD-KOTLIN-013mediumCWE-338Insecure random used for security tokens
What it detects

Detects java.util.Random or kotlin.random.Random usage which is predictable for tokens.

Where it appears

Kotlin files via insecure random pattern matching

How to fix

Use java.security.SecureRandom for any security-sensitive random values.

SHIELD-KOTLIN-016mediumCWE-532Sensitive data logged via Log statements
What it detects

Detects Log.d/Log.e/Log.i statements leaking passwords/tokens/secrets into device logs.

Where it appears

Kotlin files via Log + sensitive keyword pattern matching

How to fix

Never log secrets; redact sensitive fields and disable verbose logging in release builds.

SHIELD-PHP-015mediumCWE-338Insecure randomness for security tokens
What it detects

Detects rand/mt_rand/uniqid/lcg_value used to generate token, secret, nonce, or key.

Where it appears

PHP files via insecure random pattern matching

How to fix

Use random_bytes() or random_int() for cryptographically secure token generation.

SHIELD-PHP-017mediumCWE-113HTTP header injection via dynamic header value
What it detects

Detects header() function called with a variable value allowing response splitting or header injection.

Where it appears

PHP files via header + variable pattern matching

How to fix

Validate header values and strip CR/LF characters before calling header().

SHIELD-PY-010mediumCWE-327Weak MD5 or SHA1 hash usage
What it detects

Detects hashlib.md5() or hashlib.sha1() usage which are cryptographically broken.

Where it appears

Python files via weak hash pattern matching

How to fix

Use hashlib.sha256() or hashlib.sha3_256() instead.

SHIELD-PY-014mediumCWE-338Insecure random number for security purposes
What it detects

Detects random module functions (random, randint, choice, shuffle, sample) which are not cryptographically secure.

Where it appears

Python files via random module pattern matching

How to fix

Use secrets module (secrets.token_bytes, secrets.choice) for security-sensitive randomness.

SHIELD-PY-017mediumCWE-208Timing attack in string comparison
What it detects

Detects password, token, secret, key, or signature variables compared with == operator which is vulnerable to timing attacks.

Where it appears

Python files via timing attack pattern matching

How to fix

Use hmac.compare_digest() for constant-time string comparison of secrets.

SHIELD-RUBY-018mediumCWE-327Weak hashing with MD5 or SHA1
What it detects

Detects Digest::MD5 or Digest::SHA1 usage for passwords or integrity which is cryptographically broken.

Where it appears

Ruby files via Digest weak hash pattern matching

How to fix

Use bcrypt or Argon2 for passwords and SHA-256 or stronger for integrity.

SHIELD-RUBY-020mediumCWE-330Insecure randomness for tokens
What it detects

Detects token/secret/nonce/salt/otp assigned rand() or Random.rand/new producing predictable values.

Where it appears

Ruby files via insecure random pattern matching

How to fix

Generate tokens with SecureRandom.hex or SecureRandom.uuid.

SHIELD-RUBY-021mediumCWE-601Open redirect via redirect_to with params
What it detects

Detects redirect_to called with params allowing attackers to send users to arbitrary sites.

Where it appears

Ruby files via redirect_to + params pattern matching

How to fix

Redirect only to validated internal paths or set allow_other_host to false.

SHIELD-RUBY-023mediumCWE-1333Regex denial of service via interpolated pattern
What it detects

Detects Regexp.new built from unsanitized user input creating catastrophic backtracking patterns.

Where it appears

Ruby files via Regexp.new + user input pattern matching

How to fix

Escape user input with Regexp.escape or match against a fixed anchored pattern.

SHIELD-RUST-006mediumCWE-119Unsafe block requires review
What it detects

Detects unsafe blocks which bypass Rust memory-safety guarantees and must be manually audited.

Where it appears

Rust files via unsafe block pattern matching

How to fix

Confirm the unsafe block upholds all invariants; prefer safe abstractions where possible.

SHIELD-RUST-007mediumCWE-502Insecure deserialization of untrusted bytes
What it detects

Detects bincode/rmp deserialization of attacker-controlled bytes without validation.

Where it appears

Rust files via bincode/rmp deserialization pattern matching

How to fix

Validate and bound input, and prefer self-describing formats with strict schemas.

SHIELD-RUST-010mediumCWE-338Insecure randomness for security value
What it detects

Detects rand::random or thread_rng usage which is not a CSPRNG guarantee for tokens.

Where it appears

Rust files via insecure random pattern matching

How to fix

Use a CSPRNG (rand::rngs::OsRng / getrandom) for security-sensitive values.

SHIELD-SWIFT-016mediumCWE-200Sensitive data copied to pasteboard
What it detects

Detects password or secret written to the general UIPasteboard exposing it to other apps.

Where it appears

Swift files via UIPasteboard + sensitive keyword pattern matching

How to fix

Avoid placing secrets on the shared pasteboard, or mark items as expiring and local-only.

SHIELD-SWIFT-017mediumCWE-311Keychain item without access control
What it detects

Detects Keychain item added with an insecure always-accessible protection class.

Where it appears

Swift files via kSecAttrAccessibleAlways pattern matching

How to fix

Use kSecAttrAccessibleWhenUnlockedThisDeviceOnly or add SecAccessControl with biometrics.

SHIELD-GEN-002lowCWE-1068Security-sensitive TODO/FIXME comment
What it detects

Finds TODO, FIXME, HACK, or XXX comments that mention security-related keywords like auth, injection, or password, indicating unresolved security debt.

Where it appears

All languages via comment pattern matching

How to fix

Resolve the identified security issue before shipping to production.

SHIELD-GEN-011lowCWE-798Base64 encoded potential secret
What it detects

Detects SECRET, PASSWORD, TOKEN, or KEY variables assigned base64-encoded strings of 40+ characters, which may contain embedded secrets.

Where it appears

All languages via base64 pattern matching

How to fix

Verify that this value does not contain a secret. Move secrets to a secrets manager.

SHIELD-GO-012lowCWE-477Use of deprecated ioutil package
What it detects

Detects ioutil function usage (ReadAll, ReadFile, WriteFile, TempFile, TempDir, NopCloser, Discard) which are deprecated since Go 1.16.

Where it appears

Go files via ioutil pattern matching

How to fix

Replace ioutil functions with their io or os equivalents (e.g., io.ReadAll, os.ReadFile).

SHIELD-RUST-014lowCWE-190Potential integer overflow in allocation size
What it detects

Detects with_capacity/Vec sizing from multiplication of untrusted values which can overflow.

Where it appears

Rust files via with_capacity + multiplication pattern matching

How to fix

Use checked_mul and validate sizes before allocating from untrusted input.

Secrets 27 rules

SECRET-001criticalCWE-798AWS Access Key ID
What it detects

Detects AWS Access Key IDs matching the pattern (AKIA|ABIA|ACCA|ASIA) followed by 16 alphanumeric characters. These are the public identifiers for AWS IAM users and roles.

Where it appears

/opt/shield/packages/secret-detector/detector.go:29-33

How to fix

Immediately rotate the exposed AWS Access Key ID. Go to AWS IAM console, delete the compromised key, create a new key pair, and update all applications and scripts using the old key. Monitor CloudTrail for unauthorized activity.

SECRET-002criticalCWE-798AWS Secret Access Key
What it detects

Detects AWS Secret Access Keys through pattern matching for 'aws_secret_access_key' assignments followed by 40-character base64-like values. The secret is the private key paired with an Access Key ID.

Where it appears

/opt/shield/packages/secret-detector/detector.go:34-39

How to fix

Immediately rotate the AWS Secret Access Key. Delete the compromised key from IAM console, create a new key pair, update all configurations and applications, and review CloudTrail logs for unauthorized access.

SECRET-003criticalCWE-798Azure Connection String
What it detects

Detects Azure Storage connection strings containing DefaultEndpointsProtocol, AccountName, and AccountKey with 88-character base64-encoded key. These grant full access to Azure Storage resources.

Where it appears

/opt/shield/packages/secret-detector/detector.go:40-45

How to fix

Revoke the compromised storage account key in Azure Portal immediately. Regenerate a new key, update all applications and services using the old key, and audit storage access logs.

SECRET-004criticalCWE-798GCP Service Account Private Key
What it detects

Detects GCP Service Account JSON files containing 'private_key' field with RSA or EC private key PEM header. Service account keys grant programmatic access to GCP resources.

Where it appears

/opt/shield/packages/secret-detector/detector.go:46-51

How to fix

Delete the compromised service account key immediately in GCP Console. Audit the service account's activity logs. Create a new key if needed and rotate it in all applications. Consider disabling the entire service account if compromise is severe.

SECRET-005criticalCWE-798GitHub Personal Access Token (classic)
What it detects

Detects GitHub personal access tokens (classic format) matching 'ghp_' prefix followed by 36 alphanumeric characters. These tokens grant access to GitHub repositories and user data.

Where it appears

/opt/shield/packages/secret-detector/detector.go:52-57

How to fix

Revoke the token immediately in GitHub Settings > Developer settings > Personal access tokens. Create a new token if needed. Check GitHub audit log for any unauthorized access and rotate credentials for any secrets accessed with this token.

SECRET-006criticalCWE-798GitHub Fine-Grained Personal Access Token
What it detects

Detects GitHub fine-grained personal access tokens matching 'github_pat_' prefix followed by 82 alphanumeric and underscore characters. These newer tokens offer granular permission control.

Where it appears

/opt/shield/packages/secret-detector/detector.go:58-63

How to fix

Revoke the compromised token in GitHub Settings > Developer settings > Personal access tokens > Fine-grained tokens. Create a new token with minimal required permissions. Review GitHub audit logs for unauthorized activity.

SECRET-007criticalCWE-798GitHub OAuth App Token
What it detects

Detects GitHub OAuth application tokens matching 'gho_' prefix followed by 36 alphanumeric characters. These are authorization tokens used by OAuth apps to access GitHub on behalf of users.

Where it appears

/opt/shield/packages/secret-detector/detector.go:64-69

How to fix

Revoke the OAuth token in GitHub Settings. If the app was compromised, also revoke the entire OAuth app in GitHub Settings > Developer settings > OAuth apps. Check audit logs for unauthorized activity.

SECRET-008criticalCWE-798GitLab Personal Access Token
What it detects

Detects GitLab personal access tokens matching 'glpat-' prefix followed by 20 characters of alphanumerics, hyphens, and underscores. These tokens authenticate against GitLab API and git operations.

Where it appears

/opt/shield/packages/secret-detector/detector.go:70-75

How to fix

Revoke the token immediately in GitLab User Settings > Access Tokens. Create a new token if needed. Review GitLab audit logs to check if the token was used unauthorized. Update any CI/CD pipelines using the old token.

SECRET-010criticalCWE-798Database Connection String with Credentials
What it detects

Detects database connection strings for PostgreSQL, MySQL, MongoDB, Redis, and MSSQL with embedded username and password in the connection URL (format: protocol://username:password@host).

Where it appears

/opt/shield/packages/secret-detector/detector.go:82-87

How to fix

Change database credentials immediately. Update all applications with new credentials. Move connection strings to environment variables or secrets management systems. Audit database access logs for unauthorized queries.

SECRET-013criticalCWE-798RSA Private Key
What it detects

Detects RSA private key files by matching the '-----BEGIN RSA PRIVATE KEY-----' PEM header. RSA private keys are used for authentication and encryption.

Where it appears

/opt/shield/packages/secret-detector/detector.go:94-99

How to fix

Immediately rotate the RSA private key. Generate a new key pair and update all services using this key. Revoke the old key/certificate. If used for SSH, update authorized_keys on affected servers and audit access logs.

SECRET-014criticalCWE-798Generic Private Key (PKCS#8)
What it detects

Detects PKCS#8 format private keys by matching the '-----BEGIN PRIVATE KEY-----' PEM header. This format is used for various cryptographic keys including RSA, EC, and DSA.

Where it appears

/opt/shield/packages/secret-detector/detector.go:100-105

How to fix

Immediately revoke and rotate the compromised private key. Generate a new key pair and update all systems using this key. If used for TLS/SSL, reissue certificates. If used for SSH, update authorized_keys and audit access logs.

SECRET-015criticalCWE-798OpenSSH Private Key
What it detects

Detects OpenSSH format private keys by matching the '-----BEGIN OPENSSH PRIVATE KEY-----' PEM header. These are SSH keys used for authentication to servers.

Where it appears

/opt/shield/packages/secret-detector/detector.go:106-111

How to fix

Immediately revoke the SSH key. Remove the corresponding public key from authorized_keys on all affected servers. Generate a new key pair. Audit server access logs for unauthorized logins.

SECRET-016criticalCWE-798PGP Private Key
What it detects

Detects PGP private key blocks by matching the '-----BEGIN PGP PRIVATE KEY BLOCK-----' header. PGP private keys are used for encryption and digital signatures.

Where it appears

/opt/shield/packages/secret-detector/detector.go:112-117

How to fix

Immediately revoke the PGP private key using a key revocation certificate. Upload the revocation certificate to key servers. Generate a new key pair. Notify anyone who has encrypted data to this key about the compromise.

SECRET-018criticalCWE-798Stripe Secret Key
What it detects

Detects Stripe secret keys matching 'sk_live_' prefix followed by 24+ alphanumeric characters. Secret keys have full access to Stripe account and can make payments or access sensitive data.

Where it appears

/opt/shield/packages/secret-detector/detector.go:124-129

How to fix

Revoke the compromised Stripe secret key immediately in Stripe Dashboard > API keys. Create a new secret key. Update all applications with the new key. Review Stripe API logs for unauthorized charges or access.

SECRET-019criticalCWE-798Twilio Auth Token
What it detects

Detects Twilio Auth Tokens through pattern matching for 'twilio_auth_token' assignments with 32 hexadecimal characters. These tokens authenticate to Twilio API for SMS, voice, and messaging.

Where it appears

/opt/shield/packages/secret-detector/detector.go:130-135

How to fix

Revoke the Twilio Auth Token immediately in Twilio Console > Account > Settings. Create a new auth token. Update all applications using the old token. Review Twilio usage logs for unauthorized activity.

SECRET-023criticalCWE-798OpenAI API Key
What it detects

Detects OpenAI API keys matching pattern 'sk-(proj-|svcacct-|admin-)?[A-Za-z0-9_-]{20,}T3BlbkFJ[A-Za-z0-9_-]{20,}' which includes legacy and new OpenAI key formats.

Where it appears

/opt/shield/packages/secret-detector/detector.go:148-153

How to fix

Revoke the OpenAI API key immediately in OpenAI platform account. Create a new API key with necessary scopes. Update all applications using the old key. Monitor OpenAI API usage logs for unauthorized requests.

SECRET-025criticalCWE-798Anthropic API Key
What it detects

Detects Anthropic API keys matching pattern 'sk-ant-[A-Za-z0-9_-]{20,}' which is the standard format for Anthropic API authentication.

Where it appears

/opt/shield/packages/secret-detector/detector.go:160-165

How to fix

Revoke the Anthropic API key immediately in Anthropic console. Create a new API key. Update all applications and scripts using the old key. Monitor API usage logs for unauthorized requests.

SECRET-009highCWE-798npm Access Token
What it detects

Detects npm access tokens matching 'npm_' prefix followed by 36 alphanumeric characters. These tokens authenticate for npm registry operations and package publishing.

Where it appears

/opt/shield/packages/secret-detector/detector.go:76-81

How to fix

Revoke the token immediately via 'npm token revoke' or in npmjs.com account settings. Create a new token if needed. Check npm audit logs for any unauthorized package operations. Re-authenticate for any active npm operations.

SECRET-011highCWE-798JWT Secret / Signing Key
What it detects

Detects JWT signing secrets and keys assigned via patterns like 'jwt_secret' or 'jwt_signing_key' with values of 16+ characters. Compromised JWT secrets allow forging authentication tokens.

Where it appears

/opt/shield/packages/secret-detector/detector.go:88-93

How to fix

Rotate the JWT signing secret immediately. Revoke all existing JWT tokens by invalidating them or rotating the secret on all services. Update all applications with the new secret. Force users to re-authenticate.

SECRET-012highCWE-798Generic API Key Assignment
What it detects

Detects generic API key assignments through pattern matching for 'api_key' or 'apikey' with values of 20+ alphanumeric, hyphen, or underscore characters. This is a catch-all for provider-specific patterns.

Where it appears

/opt/shield/packages/secret-detector/detector.go:176-181

How to fix

Revoke the exposed API key in the service provider's dashboard. Create a new API key with limited scopes if possible. Update applications to use the new key. Monitor for unauthorized API usage.

SECRET-017highCWE-798Slack Webhook URL
What it detects

Detects Slack incoming webhook URLs matching the pattern 'https://hooks.slack.com/services/T[A-Z0-9]+/B[A-Z0-9]+/[A-Za-z0-9]+'. These URLs allow posting messages to Slack channels.

Where it appears

/opt/shield/packages/secret-detector/detector.go:118-123

How to fix

Revoke the webhook URL immediately in Slack workspace settings. Create a new webhook URL if needed. Update all applications using the old webhook. Monitor Slack for unauthorized message posting.

SECRET-020highCWE-798SendGrid API Key
What it detects

Detects SendGrid API keys matching the pattern 'SG.[A-Za-z0-9\-_]{22}.[A-Za-z0-9\-_]{43}' (consists of SG. prefix, 22 chars, dot, then 43 chars). These keys authenticate to SendGrid email service.

Where it appears

/opt/shield/packages/secret-detector/detector.go:136-141

How to fix

Revoke the SendGrid API key immediately in SendGrid Settings > API Keys. Create a new API key if needed. Update all applications and scripts using the old key. Monitor SendGrid activity logs.

SECRET-022highCWE-798Discord Bot Token
What it detects

Detects Discord bot tokens matching pattern [MN][A-Za-z0-9]{23}.[\w-]{6}.[\w-]{27}. These tokens authenticate bot applications to Discord API.

Where it appears

/opt/shield/packages/secret-detector/detector.go:142-147

How to fix

Regenerate the bot token immediately in Discord Developer Portal. Update all bot applications with the new token. Review bot audit logs for unauthorized server actions or access.

SECRET-024highCWE-798Slack Token
What it detects

Detects Slack authentication tokens matching pattern 'xox[baprs]-[A-Za-z0-9-]{10,}' which covers bot (xoxb), app (xoxa), personal (xoxp), and refresh (xoxr) tokens.

Where it appears

/opt/shield/packages/secret-detector/detector.go:154-159

How to fix

Revoke the Slack token immediately in the workspace settings. Create a new token if needed. Update all applications using the old token. Review workspace audit logs for unauthorized actions.

SECRET-026highCWE-798Linear API Key
What it detects

Detects Linear API keys matching pattern 'lin_api_[A-Za-z0-9]{40}' which is the standard format for Linear API authentication.

Where it appears

/opt/shield/packages/secret-detector/detector.go:166-171

How to fix

Revoke the Linear API key immediately in Linear workspace settings. Create a new API key if needed. Update all integrations using the old key. Review Linear audit logs for unauthorized changes.

SECRET-021mediumCWE-798Generic Password in Config
What it detects

Detects generic password assignments through pattern matching for 'password', 'passwd', or 'pwd' with quoted values of 8+ characters. This is a catch-all for hardcoded passwords.

Where it appears

/opt/shield/packages/secret-detector/detector.go:182-187

How to fix

Change the password immediately in the associated system or service. Remove the hardcoded password from configuration files. Use environment variables or secrets management systems instead. Audit logs for unauthorized access.

SECRET-ENTmediumCWE-798High-Entropy Secret (potential unknown format)
What it detects

Detects high-entropy tokens in assignment expressions (key=value or key:value) when the key name suggests it might hold a secret (contains words like 'secret', 'token', 'password', 'key', 'auth', 'credential', 'bearer', etc.) and the value has Shannon entropy >= 4.5. Skips known benign patterns (hex digests, UUIDs, integrity hashes) and generated files.

Where it appears

/opt/shield/packages/secret-detector/detector.go:374-390

How to fix

Verify if the detected value is actually a secret. If it is, rotate it immediately using the provider's management interface. If it is a legitimate non-secret high-entropy value (hash, checksum, etc.), add it to .shieldignore or rename the assignment key to avoid pattern matching.

DAST — Dynamic 37 rules

DAST-001criticalCWE-319TLS/SSL appears disabled or using weak protocol
What it detects

Configuration files or source code patterns indicating TLS/SSL is disabled or using deprecated weak protocols (SSLv2, SSLv3, TLSv1.0). Detects patterns like ssl_protocols SSLv2, ssl=false, or tls=false in web configs and source files.

Where it appears

Web configuration files (nginx.conf, apache.conf, httpd.conf, .htaccess, *.conf), environment files (.env, .env.production, .env.staging), and application source code (*.go, *.py, *.js, *.ts, *.rb, *.java, *.php, *.jsx, *.tsx)

How to fix

Enable TLS 1.2 or higher in all web server configurations. Remove SSLv2/v3 and TLSv1.0 from ssl_protocols directive. Set all ssl/tls flags to true or enabled. Update web server configuration files to enforce modern TLS versions only.

DAST-LIVE-001criticalCWE-319Application served over HTTP without TLS
What it detects

Live HTTP probe detects the application is served over HTTP (unencrypted) instead of HTTPS. This represents a critical confidentiality and integrity risk as all traffic can be intercepted.

Where it appears

Live endpoint/URL probing during runtime against HTTP targets

How to fix

Enforce HTTPS for all application endpoints. Obtain and install a valid TLS certificate. Configure the web server to redirect HTTP to HTTPS. Set Strict-Transport-Security (HSTS) header to enforce HTTPS for future requests.

DAST-LIVE-012criticalCWE-295TLS connection failed
What it detects

Live probe fails to establish a TLS connection to the target HTTPS endpoint. This indicates a certificate issue, misconfigured TLS, or unreachable target.

Where it appears

TLS handshake during live HTTPS endpoint probes

How to fix

Verify the TLS certificate is valid, not expired, and properly installed. Check certificate CN/SAN matches the domain. Ensure port 443 is open and accessible. Verify certificate chain is complete. Test with openssl s_client for detailed diagnostics.

DAST-LIVE-014criticalCWE-295TLS certificate expired
What it detects

Live probe detects that the TLS certificate has already expired. This breaks HTTPS and will trigger browser warnings, disrupting service.

Where it appears

TLS certificate NotAfter timestamp during live HTTPS endpoint probes

How to fix

Immediately renew the TLS certificate. Use Let's Encrypt for free automated certificates. If using paid certificates, renew before expiration. Implement automated renewal processes to prevent future expirations. Add monitoring alerts 30 days before expiry.

DAST-LIVE-016criticalCWE-200Environment file (.env) publicly accessible
What it detects

Live probe detects that the .env file (commonly containing database passwords, API keys, secrets) is publicly accessible via HTTP GET on /.env endpoint, returning 200 OK.

Where it appears

HTTP GET /.env response during live sensitive path probes

How to fix

Remove .env files from web root entirely. Store secrets in environment variables, secret management systems (HashiCorp Vault, AWS Secrets Manager), or config files outside the web directory. Configure web server to deny access to dotfiles: deny all for /. files in nginx or <FilesMatch> in Apache.

DAST-LIVE-017criticalCWE-200Git repository metadata publicly accessible
What it detects

Live probe detects that the .git/config file (Git repository metadata) is publicly accessible via HTTP GET on /.git/config endpoint, returning 200 OK. Allows attackers to clone source code.

Where it appears

HTTP GET /.git/config response during live sensitive path probes

How to fix

Remove .git directories from production deployments. Use .gitignore to exclude from builds. Configure web server to deny access: deny all for /.git/ in nginx or <FilesMatch ~ /\.git/> in Apache. Use containerization to ensure .git doesn't ship in production images.

DAST-003highCWE-319Non-HTTPS endpoint configured
What it detects

HTTP endpoints (not HTTPS) configured for production use. Detects patterns like url: http://, endpoint: http://, base_url: http://, api_url: http://, or redirect: http:// pointing to non-localhost addresses. Excludes localhost and 127.0.0.1 which are development-only.

Where it appears

Configuration files (nginx.conf, apache.conf, *.conf, .env files) and application source code containing URL/endpoint definitions

How to fix

Replace HTTP with HTTPS for all production endpoints. Ensure all URLs, API endpoints, and redirects use https:// protocol. Keep HTTP only for localhost development or use localhost/127.0.0.1 addresses.

DAST-008highCWE-352CSRF protection explicitly disabled
What it detects

Cross-Site Request Forgery (CSRF) protection is explicitly disabled or set to false in source code or configuration. Detects patterns like csrf: false, xsrf: false, csrf_disabled, csrf_off, csrf_none, etc.

Where it appears

Application source code files (*.go, *.py, *.js, *.ts, *.rb, *.java, *.php, *.jsx, *.tsx) containing CSRF/XSRF configuration settings

How to fix

Enable CSRF protection by default. Ensure CSRF tokens are generated for all state-changing requests (POST, PUT, DELETE). Implement proper token validation on the server side. Use framework-provided CSRF middleware. Never disable CSRF protection in production.

DAST-011highCWE-215Debug mode enabled — may expose sensitive information
What it detects

Debug mode is enabled in production or staging configuration files. Detects patterns like DEBUG: true, DEBUG: 1, DEBUG: yes, DEBUG: on, debug_mode: true, or FLASK_DEBUG: true/1/yes/on.

Where it appears

Application source code files (*.go, *.py, *.js, *.ts, *.rb, *.java, *.php, *.jsx, *.tsx) and environment files (.env, .env.production, .env.staging) containing debug configuration

How to fix

Disable debug mode in production and staging environments. Set DEBUG=false in environment variables. Remove verbose error messages from production responses. Use separate DEBUG settings for development-only environments. Ensure stack traces and sensitive data are not exposed in error pages.

DAST-LIVE-002highCWE-319Missing Strict-Transport-Security (HSTS) header
What it detects

Live probe detects that the Strict-Transport-Security (HSTS) header is missing from HTTPS responses. Without HSTS, clients may still attempt HTTP connections on subsequent visits, enabling SSL stripping attacks.

Where it appears

HTTP response headers from live endpoint probes

How to fix

Add the Strict-Transport-Security header to HTTPS responses: Strict-Transport-Security: max-age=31536000; includeSubDomains; preload. Set max-age to at least 1 year (31536000 seconds). Include subdomains to protect all application endpoints. Consider HSTS preload list submission.

DAST-LIVE-013highCWE-326Weak TLS version
What it detects

Live probe detects that the TLS version negotiated is less than TLS 1.2 (e.g., TLS 1.0, TLS 1.1). These versions have known cryptographic weaknesses and are considered deprecated.

Where it appears

TLS handshake/ConnectionState during live HTTPS endpoint probes

How to fix

Configure the server to require TLS 1.2 or higher. Disable TLS 1.0 and 1.1. In nginx: ssl_protocols TLSv1.2 TLSv1.3;. In Apache: SSLProtocol -all +TLSv1.2 +TLSv1.3. Update client libraries to support modern TLS.

DAST-LIVE-018highCWE-200Debug endpoint publicly accessible
What it detects

Live probe detects that a /debug endpoint is publicly accessible, returning 200 OK. This endpoint typically exposes internal application state, configuration, or heap dumps.

Where it appears

HTTP GET /debug response during live sensitive path probes

How to fix

Remove or disable debug endpoints in production. Restrict debug endpoints to localhost or internal networks only. Require authentication for any diagnostic endpoints. Use framework-level configuration to disable debug mode: DEBUG=False in Django, Flask, etc.

DAST-LIVE-020highCWE-200phpinfo() page publicly accessible
What it detects

Live probe detects that /phpinfo.php endpoint is publicly accessible, returning 200 OK. Exposes detailed PHP configuration, loaded extensions, environment variables, and server info.

Where it appears

HTTP GET /phpinfo.php response during live sensitive path probes

How to fix

Remove phpinfo.php from production servers entirely. Never leave test/debug files in production. Disable PHP error reporting on screen. Set display_errors = Off in php.ini. Remove file if found during deployment/audit.

DAST-LIVE-022highCWE-200Spring Boot Actuator endpoints exposed
What it detects

Live probe detects that Spring Boot Actuator endpoints (/actuator) are publicly accessible, returning 200 OK. Exposes application metrics, environment variables, beans, and configuration.

Where it appears

HTTP GET /actuator response during live sensitive path probes

How to fix

Disable or restrict Spring Boot Actuator endpoints: set management.endpoints.web.exposure.exclude=* or expose only safe endpoints. Move actuator to internal/admin port. Require authentication: spring.security.user.name and spring.security.user.password. Use management.endpoints.web.base-path=/internal/actuator to hide from public.

DAST-LIVE-024highCWE-319HTTP does not redirect to HTTPS
What it detects

Live probe detects that HTTP requests to the application return 2xx (success) without redirecting to HTTPS. Allows unencrypted communication and enables man-in-the-middle attacks.

Where it appears

HTTP endpoint HTTP response status (200-299) during live HTTP-to-HTTPS redirect probes

How to fix

Configure HTTP to HTTPS redirect on port 80: server { listen 80; return 301 https://$host$request_uri; } in nginx or <VirtualHost *:80> with Redirect permanent / https://... in Apache. Ensure all traffic is redirected before serving content.

DAST-LIVE-025highCWE-319HTTP redirects but not to HTTPS
What it detects

Live probe detects that HTTP requests redirect (3xx response) but not to an HTTPS URL. Redirect may go to another HTTP URL or a different domain, still exposing traffic.

Where it appears

HTTP endpoint with 3xx response and Location header not starting with https:// during live HTTP-to-HTTPS redirect probes

How to fix

Ensure HTTP redirects to the HTTPS version of the same URL: return 301 https://$host$request_uri; in nginx. Verify Location header in 3xx responses starts with https://. Test HTTP-to-HTTPS redirect chain: http -> https, not http -> http.

DAST-002mediumCWE-942CORS allows all origins (*)
What it detects

Cross-Origin Resource Sharing (CORS) policy configured to allow all origins using the wildcard (*) pattern. Detects patterns like Access-Control-Allow-Origin: *, AllowOrigins: *, or allow_origin: * in configuration files.

Where it appears

Web configuration files (nginx.conf, apache.conf, httpd.conf, .htaccess, *.conf), environment files, and application source code detecting wildcard CORS patterns

How to fix

Replace the wildcard (*) with specific trusted origins. Explicitly list only the domains that need CORS access. Use a dynamic CORS policy that validates request origins against a whitelist. Never use wildcards for CORS in production.

DAST-004mediumCWE-1021X-Frame-Options set to permissive value
What it detects

X-Frame-Options header configured with permissive values (e.g., Allow) that permit the page to be framed by external sites, enabling clickjacking attacks. Detects patterns where X-Frame-Options contains 'ALLOW' keyword.

Where it appears

Web server configuration files (nginx.conf, apache.conf, httpd.conf, *.conf, .htaccess) containing X-Frame-Options directives

How to fix

Set X-Frame-Options to either DENY (prevents all framing) or SAMEORIGIN (allows framing only by the same origin). Avoid permissive values like ALLOW or ALLOWALL. Use Content-Security-Policy frame-ancestors directive as a complementary control.

DAST-006mediumCWE-548Directory listing enabled
What it detects

Directory listing/auto-indexing is enabled on the web server, allowing attackers to browse directory contents. Detects patterns like autoindex on, Options Indexes, or directory_listing: true.

Where it appears

Web server configuration files (nginx.conf, apache.conf, httpd.conf, *.conf, .htaccess) containing indexing directives

How to fix

Disable directory listing: set autoindex off in nginx, remove Indexes from Options in Apache (use Options -Indexes), or set directory_listing: false. Ensure only intentionally exposed files are accessible via web.

DAST-007mediumCWE-601Potential open redirect — user-controlled redirect target
What it detects

Code pattern for open redirect vulnerability where redirect/location targets are populated from user-controlled input parameters (req.*, request.*, params.*, query.*). Detects patterns like redirect(request.query), location(params.url), etc.

Where it appears

Application source code files (*.go, *.py, *.js, *.ts, *.rb, *.java, *.php, *.jsx, *.tsx) containing redirect or location statements

How to fix

Validate redirect targets against a whitelist of allowed destinations before redirecting. Use absolute URL validation and ensure redirects stay within the same domain. Never trust user input for redirect URLs without strict validation. Use framework helpers like Rails redirect_to with only: parameter.

DAST-009mediumCWE-614Cookie set without Secure or HttpOnly flags
What it detects

Cookies are set without the Secure flag (preventing transmission over HTTPS only) or HttpOnly flag (preventing access from JavaScript). Detects patterns like secure: false or httponly: false in Set-Cookie or cookie directives.

Where it appears

Application source code files (*.go, *.py, *.js, *.ts, *.rb, *.java, *.php, *.jsx, *.tsx) containing cookie configuration

How to fix

Set both Secure and HttpOnly flags on all cookies. Use Set-Cookie: name=value; Secure; HttpOnly; SameSite=Strict. The Secure flag prevents transmission over HTTP; HttpOnly prevents JavaScript access, mitigating XSS-based theft.

DAST-010mediumCWE-770Rate limiting disabled or not configured
What it detects

Rate limiting is explicitly disabled or not configured, leaving the application vulnerable to brute force and denial-of-service attacks. Detects patterns like rate_limit: false, rate_limit: disabled, rate_limit: off, rate_limit: 0, or rate_limit: none.

Where it appears

Application source code files (*.go, *.py, *.js, *.ts, *.rb, *.java, *.php, *.jsx, *.tsx) and configuration files containing rate limiting settings

How to fix

Enable rate limiting on sensitive endpoints (login, API, password reset). Implement per-IP or per-user rate limits. Configure reasonable thresholds based on legitimate usage patterns. Use reverse proxy (nginx, Cloudflare) or framework-level middleware for rate limiting.

DAST-LIVE-003mediumCWE-693Missing X-Content-Type-Options header
What it detects

Live probe detects that the X-Content-Type-Options header is missing from responses. Without this header, browsers may perform MIME sniffing, potentially leading to XSS or other content-type attacks.

Where it appears

HTTP response headers from live endpoint probes

How to fix

Add X-Content-Type-Options: nosniff to all responses. This prevents browsers from guessing the content type and forces them to respect the declared Content-Type header.

DAST-LIVE-004mediumCWE-1021Missing X-Frame-Options header — clickjacking risk
What it detects

Live probe detects that the X-Frame-Options header is missing from responses. Without this header, the application can be embedded in a frame on another site, enabling clickjacking attacks.

Where it appears

HTTP response headers from live endpoint probes

How to fix

Add X-Frame-Options header with a restrictive value: X-Frame-Options: DENY (prevent framing) or X-Frame-Options: SAMEORIGIN (allow framing only by same origin). Alternatively, use Content-Security-Policy: frame-ancestors 'none' or frame-ancestors 'self'.

DAST-LIVE-005mediumCWE-693Missing Content-Security-Policy header
What it detects

Live probe detects that the Content-Security-Policy (CSP) header is missing from responses. Without CSP, the application is vulnerable to XSS attacks as browsers will execute any inline scripts and load resources from any origin.

Where it appears

HTTP response headers from live endpoint probes

How to fix

Implement Content-Security-Policy header with a restrictive policy. Start with default-src 'self' and explicitly whitelist trusted sources for scripts, styles, images, etc. Avoid unsafe-inline and unsafe-eval. Use nonce or hash-based inline script policies for necessary inline content.

DAST-LIVE-009mediumCWE-942CORS allows all origins (*) — credentials could leak
What it detects

Live probe detects that Access-Control-Allow-Origin is set to * (wildcard), meaning the API accepts requests from any origin. If credentials (cookies, auth headers) are included, they may leak to malicious sites.

Where it appears

HTTP response header Access-Control-Allow-Origin from live endpoint probes

How to fix

Replace wildcard (*) with specific trusted origins. Use a whitelist approach: Access-Control-Allow-Origin: https://trusted-domain.com. If credentials are needed, list specific origins and set Access-Control-Allow-Credentials: true. Never combine ACAO=* with credentials.

DAST-LIVE-015mediumCWE-295TLS certificate expires in <N> days
What it detects

Live probe detects that the TLS certificate will expire soon (within 30 days). Proactive renewal is needed to prevent service disruption.

Where it appears

TLS certificate NotAfter timestamp during live HTTPS endpoint probes (expires within 30 days)

How to fix

Renew the TLS certificate before expiration. Set up automated certificate renewal (Let's Encrypt with certbot, Kubernetes cert-manager). Configure monitoring to alert 30+ days before expiry. Test certificate installation in staging before production deployment.

DAST-LIVE-019mediumCWE-200Server status page publicly accessible
What it detects

Live probe detects that the /server-status endpoint (typically Apache mod_status) is publicly accessible, returning 200 OK. Exposes server load, version, and request statistics.

Where it appears

HTTP GET /server-status response during live sensitive path probes

How to fix

Restrict access to /server-status endpoint: use Allow from 127.0.0.1 in Apache mod_status or move behind authentication. Remove if not needed. Use internal monitoring/observability tools (Prometheus, Grafana) instead of public endpoints.

DAST-LIVE-021mediumCWE-200WordPress admin panel exposed
What it detects

Live probe detects that the WordPress admin login panel (/wp-admin/) is publicly accessible, returning 200 OK. Enables brute force attacks on admin credentials.

Where it appears

HTTP GET /wp-admin/ response during live sensitive path probes

How to fix

Restrict access to /wp-admin/ to known IPs or via VPN. Use security plugins (Wordfence, iThemes Security) to require 2FA for admin login. Rename admin account (not 'admin'). Change default ports. Disable XML-RPC if not needed.

DAST-005lowCWE-200Server version information exposed
What it detects

Web server configuration leaks version information through headers. Detects patterns like server_tokens on, ServerSignature On, or expose_php = On in web server configurations.

Where it appears

Web server configuration files (nginx.conf, apache.conf, httpd.conf, *.conf, .htaccess) containing server token or signature directives

How to fix

Disable server token exposure: set server_tokens off in nginx, ServerSignature Off in Apache, or expose_php = Off in PHP configurations. Remove or minimize the Server header to avoid disclosing version information that could aid reconnaissance.

DAST-LIVE-006lowCWE-79Missing X-XSS-Protection header
What it detects

Live probe detects that the X-XSS-Protection header is missing from responses. This legacy header provided browser-level XSS protection in older browsers (less relevant with modern CSP but still a defense-in-depth measure).

Where it appears

HTTP response headers from live endpoint probes

How to fix

Add X-XSS-Protection header to responses: X-XSS-Protection: 1; mode=block. This enables the browser's XSS filter and blocks page rendering if XSS is detected. Note: This is a legacy header; rely on Content-Security-Policy as primary XSS defense.

DAST-LIVE-007lowCWE-200Missing Referrer-Policy header
What it detects

Live probe detects that the Referrer-Policy header is missing from responses. Without this header, browsers will leak referrer information across origins, potentially disclosing sensitive URLs.

Where it appears

HTTP response headers from live endpoint probes

How to fix

Add Referrer-Policy header to restrict referrer leakage: Referrer-Policy: no-referrer (never send referrer) or Referrer-Policy: strict-origin-when-cross-origin (send origin only for cross-origin requests). Choose based on application requirements.

DAST-LIVE-008lowCWE-693Missing Permissions-Policy header
What it detects

Live probe detects that the Permissions-Policy header (formerly Feature-Policy) is missing from responses. This header controls access to browser features (camera, microphone, geolocation, payment APIs, etc.).

Where it appears

HTTP response headers from live endpoint probes

How to fix

Add Permissions-Policy header to restrict feature access: Permissions-Policy: geolocation=(), microphone=(), camera=(). Explicitly disable features not needed by the application. Use () to disable globally or 'self' to allow same-origin only.

DAST-LIVE-010lowCWE-200Server header discloses version information
What it detects

Live probe detects that the Server header in HTTP responses contains version information (e.g., nginx/1.23.1, Apache/2.4.48). This aids attackers in reconnaissance and vulnerability scanning.

Where it appears

HTTP response header Server from live endpoint probes

How to fix

Remove or minimize the Server header. Configure web servers to not expose version: set server_tokens off in nginx, remove ServerTokens Prod in Apache, or use custom non-informative Server header values.

DAST-LIVE-011lowCWE-200X-Powered-By header exposes technology stack
What it detects

Live probe detects that the X-Powered-By header reveals the application technology stack (e.g., Express, ASP.NET, PHP 7.4). This information aids attackers in targeted vulnerability research.

Where it appears

HTTP response header X-Powered-By from live endpoint probes

How to fix

Remove the X-Powered-By header from all responses. Disable it in framework configuration (e.g., app.disable('x-powered-by') in Express). If needed for debugging, configure it only in development environments.

DAST-LIVE-023lowCWE-200GraphQL endpoint exposed (check introspection)
What it detects

Live probe detects that a GraphQL endpoint (/graphql) is publicly accessible, returning 200 OK. May allow schema introspection, revealing API structure and potential attack vectors.

Where it appears

HTTP GET /graphql response during live sensitive path probes

How to fix

Disable GraphQL introspection in production: set introspection: false in apollo-server or schema.introspection = false in graphql-core. Require authentication for GraphQL endpoint. Rate-limit queries. Use query complexity analysis to prevent DoS. Validate all inputs strictly.

DAST-LIVE-026infoCWE-200robots.txt found — check for sensitive path disclosure
What it detects

Live probe detects that robots.txt file exists at the root (HTTP 200 on /robots.txt). While informational, it may inadvertently disclose sensitive paths if not carefully maintained.

Where it appears

HTTP GET /robots.txt response during live sensitive path probes

How to fix

Review robots.txt contents to ensure it does not disclose sensitive paths or internal URLs. Use robots.txt only to guide public search engines. For truly sensitive paths, use authentication instead of relying on robots.txt. Keep robots.txt minimal and maintained.

Containers 11 rules

CONTAINER-005criticalCWE-829curl | bash — untrusted remote code execution in build
What it detects

Detects the dangerous pattern of piping curl output directly to bash, which executes untrusted remote code during container build with no verification or inspection.

Where it appears

Dockerfile:line (RUN instruction)

How to fix

Download scripts separately, verify checksums or signatures, and review contents before execution. Use package managers when possible, or break into discrete steps: RUN curl ... -o script.sh && chmod +x script.sh && ./script.sh

CONTAINER-008criticalCWE-250Privileged/capability escalation in container
What it detects

Detects RUN instructions that use --privileged flag or --cap-add options, which grant excessive Linux capabilities and can lead to container escape or host compromise.

Where it appears

Dockerfile:line (RUN instruction)

How to fix

Avoid --privileged mode. Use specific minimal capabilities with --cap-drop all and --cap-add ONLY_NEEDED_CAPS if absolutely required. Review if privileged access is truly necessary or if application logic can be refactored.

CONTAINER-009criticalCWE-250Docker Compose: privileged mode enabled
What it detects

Detects 'privileged: true' in docker-compose.yml files, which grants excessive capabilities to containers and significantly increases attack surface.

Where it appears

docker-compose.yml:line (service definition)

How to fix

Remove the 'privileged: true' setting. If specific capabilities are needed, use 'cap_add' with only the minimal required capabilities instead (e.g., cap_add: [NET_ADMIN]).

CONTAINER-001highCWE-250Container runs as root user
What it detects

Detects when a Dockerfile explicitly sets the user to root using the USER ROOT instruction, which violates the principle of least privilege and increases attack surface.

Where it appears

Dockerfile:line (identified by line number during scan)

How to fix

Replace 'USER root' with a non-root user. Create a dedicated application user in the Dockerfile before the USER instruction (e.g., 'RUN useradd -m appuser && USER appuser').

CONTAINER-007highCWE-798Potential secret in ENV instruction
What it detects

Detects ENV instructions that set sensitive variables (PASSWORD, SECRET, API_KEY, TOKEN, PRIVATE_KEY) with hardcoded values, which are baked into the image and visible in docker inspect.

Where it appears

Dockerfile:line (ENV instruction)

How to fix

Never hardcode secrets in Dockerfiles. Use build-time secrets via docker build --secret, environment variables injected at runtime, or container orchestration secret management systems (Kubernetes Secrets, Docker Secrets).

CONTAINER-010highCWE-668Docker Compose: host network mode
What it detects

Detects 'network_mode: host' in docker-compose.yml, which disables container network isolation and exposes all host network interfaces to the container.

Where it appears

docker-compose.yml:line (service definition)

How to fix

Remove 'network_mode: host'. Use the default bridge network or create a custom user-defined network. Only use host network if absolutely required and document the security justification.

CONTAINER-011highCWE-668Docker Compose: host PID namespace sharing
What it detects

Detects 'pid: host' in docker-compose.yml, which allows container to see and interact with all host processes, breaking process isolation.

Where it appears

docker-compose.yml:line (service definition)

How to fix

Remove 'pid: host'. Use the default isolated PID namespace. If inter-service communication is needed, use named volumes or network communication instead.

CONTAINER-002mediumCWE-1104Base image uses :latest tag (non-deterministic builds)
What it detects

Detects use of the ':latest' tag in FROM instructions, which makes builds non-deterministic and allows automatic pulling of new base image versions without explicit control.

Where it appears

Dockerfile:line (FROM instruction)

How to fix

Replace ':latest' with a specific version tag or digest. For example, use 'ubuntu:22.04' instead of 'ubuntu:latest' or specify a full digest hash for reproducible builds.

CONTAINER-004mediumCWE-200Exposing potentially sensitive port
What it detects

Detects EXPOSE instructions that publish sensitive ports (SSH:22, MySQL:3306, PostgreSQL:5432, Redis:6379, MongoDB:27017, Elasticsearch:9200), which may enable unauthorized access.

Where it appears

Dockerfile:line (EXPOSE instruction)

How to fix

Avoid exposing sensitive database and system ports publicly. Use EXPOSE only for application-facing ports needed by end users. Restrict network access via firewall rules and network policies.

CONTAINER-003lowCWE-829Use COPY instead of ADD for local files
What it detects

Detects use of ADD instruction for local files instead of COPY, which can unintentionally unpack tarballs or perform unexpected file transformations.

Where it appears

Dockerfile:line (ADD instruction)

How to fix

Replace ADD with COPY for copying local files. Use ADD only when you specifically need its special behaviors (automatic tarball unpacking or remote URL fetching).

CONTAINER-006lowCWE-693HEALTHCHECK explicitly disabled
What it detects

Detects explicit disabling of container healthchecks via 'HEALTHCHECK NONE', which removes the ability to automatically detect and recover from container failures.

Where it appears

Dockerfile:line (HEALTHCHECK instruction)

How to fix

Remove the HEALTHCHECK NONE instruction or replace it with a valid healthcheck. Define a proper HEALTHCHECK command that monitors application readiness (e.g., HEALTHCHECK CMD curl --fail http://localhost:8080/health || exit 1).

Infrastructure as Code 16 rules

IAC-CFN-001criticalCWE-284CloudFormation: S3 bucket with public access
What it detects

Detects CloudFormation templates configuring S3 buckets with public read or public read-write access (PublicRead or PublicReadWrite ACL).

Where it appears

CloudFormation template files (YAML/JSON containing 'cloudformation', 'cfn-', or 'template' in name), detected when line contains `PublicRead` or `PublicReadWrite`

How to fix

Set the bucket's `PublicAccessBlockConfiguration` to block all public access, and use CloudFront + OAI for public content distribution. Public S3 buckets are one of the most common breach vectors.

IAC-K8S-001criticalCWE-250Kubernetes: privileged container
What it detects

Detects Kubernetes containers configured with `privileged: true`, granting all capabilities and full host kernel access to the container.

Where it appears

Kubernetes YAML files (.yaml or .yml) in k8s/, kubernetes/, manifests/, deploy/, helm/, or charts/ directories, detected when line contains `privileged: true`

How to fix

Remove `privileged: true` from the container's securityContext. If a specific capability is required, add it explicitly via `capabilities.add: [NET_ADMIN]` rather than enabling all privileges.

IAC-K8S-005criticalCWE-250Kubernetes: ALL capabilities granted
What it detects

Detects Kubernetes containers with ALL Linux capabilities enabled via securityContext, granting excessive kernel privileges.

Where it appears

Kubernetes YAML files (.yaml or .yml) in k8s/, kubernetes/, manifests/, deploy/, helm/, or charts/ directories, line contains `ALL` and case-insensitive match for `capabilit`

How to fix

Drop `ALL` capabilities then add back only what's needed: `capabilities: { drop: [ALL], add: [NET_BIND_SERVICE] }`. Most workloads need zero capabilities.

IAC-TF-003criticalCWE-798Potential hardcoded secret in Terraform config
What it detects

Detects hardcoded credentials in Terraform files, including passwords, secret keys, and access keys assigned as string values.

Where it appears

Terraform files (.tf or .tf.json), detected via regex pattern `(password|secret_key|access_key)\s*=\s*"[^"]{8,}"` (case-insensitive)

How to fix

Move the secret out of Terraform code into a secret manager (AWS Secrets Manager, SSM Parameter Store with SecureString, or Hashicorp Vault) and reference it via a data source. Rotate the secret since it's now in state files and git history.

IAC-TF-004criticalCWE-284S3 bucket with public ACL
What it detects

Detects S3 bucket configurations with public read or public read-write ACLs, making bucket contents accessible to anyone on the internet.

Where it appears

Terraform files (.tf or .tf.json), line contains `acl` keyword and either `"public-read"` or `"public-read-write"`

How to fix

Remove the public ACL. Set `acl = "private"` and serve content via CloudFront with origin access identity, or via signed URLs. Block public access at the bucket level with `aws_s3_bucket_public_access_block`.

IAC-CFN-002highCWE-284CloudFormation: wildcard principal in IAM policy
What it detects

Detects CloudFormation IAM policies with wildcard principals (`"*"`), making the resource accessible to any AWS account.

Where it appears

CloudFormation template files (YAML/JSON containing 'cloudformation', 'cfn-', or 'template' in name), line contains `"*"` and case-insensitive `principal` keyword

How to fix

Replace the wildcard Principal with specific AWS account IDs, IAM ARNs, or service principals. Wildcard principals make the resource accessible to any AWS account.

IAC-CFN-003highCWE-311CloudFormation: RDS storage encryption disabled
What it detects

Detects CloudFormation RDS database configurations with `StorageEncrypted` set to false, leaving database data unencrypted at rest.

Where it appears

CloudFormation template files (YAML/JSON containing 'cloudformation', 'cfn-', or 'template' in name), line contains both `StorageEncrypted` and `false`

How to fix

Set `StorageEncrypted: true` on the RDS instance. AWS performs at-rest encryption transparently with KMS — there's no perf penalty and it's required for most compliance frameworks.

IAC-K8S-002highCWE-250Kubernetes: container runs as root (UID 0)
What it detects

Detects Kubernetes containers configured with `runAsUser: 0`, running with root privileges which increases blast radius if the container is compromised.

Where it appears

Kubernetes YAML files (.yaml or .yml) in k8s/, kubernetes/, manifests/, deploy/, helm/, or charts/ directories, detected when line contains `runAsUser: 0`

How to fix

Set `runAsUser` to a non-zero UID (e.g. `runAsUser: 1000`, `runAsNonRoot: true`). Build the image with a non-root user baked in so it works without privileged init.

IAC-K8S-003highCWE-668Kubernetes: host network enabled
What it detects

Detects Kubernetes pods configured with `hostNetwork: true`, allowing the pod to access the host's network namespace and bypass NetworkPolicy isolation.

Where it appears

Kubernetes YAML files (.yaml or .yml) in k8s/, kubernetes/, manifests/, deploy/, helm/, or charts/ directories, detected when line contains `hostNetwork: true`

How to fix

Remove `hostNetwork: true`. Host networking lets the pod see all host network interfaces and bypass NetworkPolicy. If specific host ports are needed, use `hostPort` on the container instead.

IAC-K8S-004highCWE-668Kubernetes: host PID namespace sharing
What it detects

Detects Kubernetes pods configured with `hostPID: true`, allowing the container to see and signal host processes, enabling container-escape attacks.

Where it appears

Kubernetes YAML files (.yaml or .yml) in k8s/, kubernetes/, manifests/, deploy/, helm/, or charts/ directories, detected when line contains `hostPID: true`

How to fix

Remove `hostPID: true`. Sharing the host PID namespace lets the container enumerate and signal host processes — a common container-escape primitive.

IAC-TF-001highCWE-284Security group allows ingress from 0.0.0.0/0
What it detects

Detects Terraform security group rules that allow unrestricted ingress from any IP address (0.0.0.0/0), exposing infrastructure to public network access.

Where it appears

Terraform files (.tf or .tf.json), detected when line contains `cidr_blocks = ["0.0.0.0/0"]`

How to fix

Replace `0.0.0.0/0` with the specific CIDR ranges that need access (e.g. office IPs, VPN range, peered VPC CIDR). For services that genuinely must be public, layer on additional controls like WAF or per-request auth.

IAC-TF-002highCWE-311Encryption explicitly disabled
What it detects

Detects Terraform configuration where encryption is explicitly set to false on storage resources (RDS, S3, EBS, etc.), leaving data unencrypted at rest.

Where it appears

Terraform files (.tf or .tf.json), detected via regex pattern matching `encrypt\w*\s*=\s*false` (case-insensitive)

How to fix

Set encryption to true (e.g. `storage_encrypted = true` for RDS, `server_side_encryption_configuration` for S3). At-rest encryption is free on AWS and required by most compliance frameworks.

IAC-TF-006highCWE-250Wildcard IAM action — overly permissive policy
What it detects

Detects IAM policies in Terraform with wildcard actions (`"*"`), granting all permissions on a resource and violating least-privilege principle.

Where it appears

Terraform files (.tf or .tf.json), line contains `"*"` and either `actions` or `Action` keyword

How to fix

Replace `"*"` actions with the specific actions actually needed (e.g. `["s3:GetObject", "s3:PutObject"]`). Wildcard policies violate least-privilege and dramatically expand blast radius if credentials leak.

IAC-K8S-006mediumCWE-770Kubernetes: no resource limits defined
What it detects

Detects Kubernetes containers with empty resource specifications (`resources: {}`), allowing unbounded CPU/memory consumption that can starve other pods.

Where it appears

Kubernetes YAML files (.yaml or .yml) in k8s/, kubernetes/, manifests/, deploy/, helm/, or charts/ directories, detected when line contains `resources: {}`

How to fix

Set explicit `resources.requests` and `resources.limits` for cpu and memory. Without limits, a runaway pod can starve neighbors on the same node and trigger OOM kills of unrelated workloads.

IAC-K8S-007mediumCWE-1104Kubernetes: image uses :latest tag
What it detects

Detects Kubernetes container images using the `:latest` tag, making deployments non-deterministic and preventing reliable rollback.

Where it appears

Kubernetes YAML files (.yaml or .yml) in k8s/, kubernetes/, manifests/, deploy/, helm/, or charts/ directories, detected via regex `image:\s*\S+:latest\b`

How to fix

Pin the image to a tag or digest (`image: nginx:1.27.3` or `image: nginx@sha256:...`). `:latest` makes rollouts non-deterministic and breaks rollback.

IAC-TF-005mediumCWE-778Logging disabled on infrastructure resource
What it detects

Detects Terraform resources where logging is explicitly disabled or set to false, reducing auditability and incident investigation capabilities.

Where it appears

Terraform files (.tf or .tf.json), line contains both `logging` and `false`

How to fix

Enable resource-level logging (CloudTrail data events for S3, VPC Flow Logs, ALB access logs, RDS audit logs). Without logs, you can't investigate incidents or prove compliance.

Dependencies 1 rules

DEP-CVEdynamicCWE-1395Known vulnerability in dependency (CVE/OSV record)
What it detects

Detects published vulnerabilities in direct and transitive dependencies by querying the OSV (Open Source Vulnerabilities) database. The scanner parses dependency manifests (package.json, go.mod, requirements.txt, Pipfile.lock, Gemfile.lock, package-lock.json) and checks each package version against OSV's vulnerability records for npm, Go, PyPI, and RubyGems ecosystems.

Where it appears

Dependency manifest files (package.json, package-lock.json, go.mod, requirements.txt, Pipfile.lock, Gemfile.lock) at the package name and resolved/locked version. Reported location is the manifest file path with line 0.

How to fix

Upgrade the vulnerable package to a version at or above the 'fixed' version reported by OSV in the vulnerability record. If no fixed version exists, evaluate whether to remove the dependency or accept the risk. The fix version is extracted from the OSV vulnerability's affected.ranges[].events[].fixed field.

CLI Reference

shield login                                  # authenticate (opens /settings/cli-tokens)
shield scan . --submit --project ID --org ID  # scan + upload results
shield version                                # print CLI version
Documentation — Zennoxa Shield