source-code-review

Fail

Audited by Snyk on Jul 6, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The prompt explicitly instructs the agent to search for and report hardcoded credentials and to report each match with file path, line number, and surrounding context (and to notify state manager of confirmed credentials), which requires outputting secret values verbatim and thus creates an exfiltration risk.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Jul 6, 2026, 09:16 AM
Issues
1
Security Audit — snyk — source-code-review