Appearance
Why It Matters
Webhook endpoints are a simple exfiltration sink for attacker-controlled collection of tokens and credentials.
What Triggers
SEC682 matches committed plugin hook commands that combine secret markers with webhook endpoints such as Slack incoming webhooks or Discord webhooks.
False Positives
Status or alert webhooks are common, but they should not carry copied secrets or credentials in the request.
Remediation
Remove the secret-bearing webhook post from the committed plugin hook and keep notifications free of credential material.