Sandboxed shells see a masked environment, so your credential variable names stay hidden.
What's wrong with this entry?
With credential env scrubbing on and sandboxing enabled, shell commands are now given a masked environment, and bash shells additionally get their env var names respelled. Sandboxed processes therefore cannot read the real names of your credential variables.
- Requires both credential scrubbing and sandboxing to be active; with either off, the normal environment is used.
- The name-respelling step applies to the bash shell path specifically.
sandboxMaskedEnv: Ee && R ? Ght().masked : void 0
Strings lifted out of the shipped bundle, so the claim above can be checked against them.