Skip to content

Default Protections

agento-patronum ships with a curated set of protection patterns covering common sensitive files and commands.

Environment Files

PatternReason
**/.envEnvironment files may contain credentials
**/.env.*Environment variable overrides may contain secrets

Private Keys & Certificates

PatternReason
**/*.pemPEM files contain private keys or certificates
**/*.keyKey files contain private keys

SSH

PatternReason
~/.ssh/*SSH directory contains private keys and config

Cloud Credentials

PatternReason
~/.aws/credentialsAWS credentials file contains access keys
~/.aws/configAWS config may contain sensitive account data
~/.docker/config.jsonDocker config may contain registry auth tokens
~/.kube/configKubernetes config contains cluster credentials

Package Manager Tokens

PatternReason
~/.npmrcNPM config may contain auth tokens
~/.pypircPyPI config may contain auth tokens

Bash Commands

PatternReason
Bash(printenv)Exposes all environment variables including secrets

Need more?

Use /patronum-suggest to get stack-specific recommendations, or add your own patterns with /patronum-add.

Think a pattern should be included by default? Open a feature request on GitHub.