RG-SEC-001 Variables Exposing Password


RG-SEC-001 looks for variable names within workflows that match a regular expression inidcating they contain a password and checks that they are of the data type “System.SecureString”.

This rule is configurable to cater for different search patterns.

Password Pattern:

The regular expression pattern identifies variable names as containing passwords.

Default Pattern:


Password Exposure


Passwords, when held in variables, must be of the type “System.SecureString”.

Further Reading

  • regex101 - build, test, and debug regex