social-publisher

Fail

Audited by Snyk on Jun 12, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.90). The prompt shows and encourages embedding the workspace API key in commands (exporting and using SC_API_KEY, a curl Authorization header, and a socialclaw login --api-key <workspace-key> flag), which requires the agent or user to place the secret verbatim into commands/outputs — an exfiltration risk.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Jun 12, 2026, 09:12 PM
Issues
1
Security Audit — snyk — social-publisher