CSP-S300: Suspicious Hardcoded Secret Assignment¶
Category: Secrets
Severity: MEDIUM
Description¶
This rule reports suspicious assignments where variable names suggest credentials (for example password, token, secret) and the value appears hardcoded.
Trigger Example¶
Recommended Refactor¶
Notes¶
- This rule complements
CSP-S200by catching non-patterned secrets. - Entropy and suspicious-name scoring affect confidence.