aws-stepfunctions-state-machine-definition

Amazon States Language definitions can hard-code task parameters, HTTP headers, credentials, and sensitive constants.

awscritical service: aws:stepfunctions emits ContainsCredential

Where it sits

locationDescribeStateMachine.definition
location kindtemplate_document
data kindscredential password api_key access_key secret_key connection_string source_code_secret
emits edgeContainsCredential
serviceStep Functions (aws:stepfunctions)

Collection recipe

access moderead_api
operationDescribeStateMachine
response pathdefinition
encodingjson
params{"stateMachineArn": "\u003cstate-machine-arn\u003e"}

Required permissions

states:DescribeStateMachine

References

move · open · esc close