docent

Fail

Audited by Snyk on Jul 2, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.80). The skill requires embedding verbatim code excerpts and file contents into the generated HTML report (including "带锚点的代码片段——关键代码原文"), and it gives no guidance to detect or redact secrets, so if the repository contains API keys/passwords/cookies those values may be read and output unchanged.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Jul 2, 2026, 03:02 AM
Issues
1
Security Audit — snyk — docent