nuke-audit
Fail
Audited by Snyk on Aug 15, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.80). The candidate schema requires including "at least one verbatim quoted line per cited site," which forces agents to output exact source-file lines (potentially containing API keys, passwords, tokens, or other secrets) into generated reports, creating an exfiltration risk.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). In
nuke-audit, the runtime workflow can ingest outsider-authored free text via the “ai” lens path: Phase 1 does web-search/quality-bar research and Phase 2 agents may incorporate that retrieved text into their charter/challenges and prompts without any explicit restriction to trusted (vendor-authored) sources.
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata