GPR-014 · critical risk
Review Git credential access
Require review before supported file-read surfaces access a Git credential store.
Decision
review
Matcher
path = .git-credentials
Reviewed
2026-08-09
Safe test cases
matching synthetic case
path = .git-credentials → review
different benign synthetic case
path = benign-.git-credentials → unmatched
Limitations
- Credential helpers and platform keychains are separate surfaces.
Review before applying
This recipe is a starting point, not a universal security policy. Open it in Policy Studio, replace example identifiers where necessary, review scope and blast radius, simulate where supported, and use the normal approval flow before enforcement.
Recipe SHA-256: fe5faa4e9dd1665b0101d7f55099b896d71acb5eaf49a35a1c020608c39d4815
When a policy is saved and delivered through Guard Cloud, it uses the existing Guard policy-bundle compiler. If the policy-bundle signing key is configured, that compiler produces an RSA-PSS-SHA256 signed bundle that local Guard verifies before applying.