doppler-secret-validation

Fail

Audited by Snyk on Jun 16, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The skill shows and encourages placing secret values directly into commands and scripts (e.g., python token='TOKEN_VALUE', doppler secrets set PYPI_TOKEN="pypi-AgEI...") which requires embedding or echoing secrets verbatim and thus is high-risk secret handling.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Jun 16, 2026, 01:05 AM
Issues
1
Security Audit — snyk — doppler-secret-validation