aws-ssm-document-content

SSM Command, Automation, Session, Package, and Policy documents contain scripts, defaults, and plugin inputs that can hard-code secrets.

awscritical service: aws:ssm emits ContainsCredential

Where it sits

locationGetDocument.Content
location kindtemplate_document
data kindscredential password api_key access_key secret_key private_key connection_string source_code_secret
emits edgeContainsCredential
serviceSystems Manager (aws:ssm)

Collection recipe

access moderead_api
operationGetDocument
response pathContent
encodingyaml
params{"DocumentFormat": "YAML", "DocumentVersion": "\u003cversion\u003e", "Name": "\u003cdocument-name\u003e"}

Required permissions

ssm:GetDocument

References

move · open · esc close