SEC-1: OAuth Token Refresh
Highlight OAuth connections that may stop working because token maintenance is not in place.
Highlight OAuth connections that may stop working because token maintenance is not in place.
Check whether automations validate and sanitize untrusted input before acting on it.
Encourage regular credential rotation to reduce long-lived exposure.
Check whether public inbound automation endpoints require authentication.
Detect signs that secrets may be stored directly in automation configuration.
Identify additional signs that sensitive values may be exposed or stored unsafely.
Highlight automations with recurring failure activity that may not be well contained.
Check whether automation network traffic uses encrypted transport.