Play / The map / The capabilities / Read credentials stored where it runs
Read credentials stored where it runs
read.credential.host — read × credential at host reach (the machine, container or account it runs as). Family: identity. Effect: cannot be undone.
Granted by 4 of 9
| Profile | Control on the path | Evidence | Via |
|---|---|---|---|
| Claude Code — web container | ● none | observed | shell (Bash) |
| Claude Code — local · confirm off | ● none | documented | shell (Bash) |
| Claude Code — local · confirm on | ● none | documented | shell (Bash) |
| Claude Desktop — local tools | ● none | documented | local files and commands (when enabled) |
What narrows it
The setting: keep credentials out of the account the agent runs as: a credential helper, a separate account, or a container without your home mounted
What it costs: an afternoon, and re-authenticating where the agent needs a credential of its own
Tier after: boundary
Questions that ask about it
- Are your cloud, SSH or registry credentials in the home directory of the account it runs as? — eliciting, reliability 0.3
In the mandates
- not wanted by A coding assistant on my machine
- not wanted by The desktop app, with local tools switched on
- not wanted by Chat in the browser, nothing connected
- not wanted by A CI job on a hosted runner