performance-db-setup

Fail

Audited by Snyk on Aug 23, 2026

Risk Level: HIGH
Full Analysis

HIGH W008: Secret detected in skill content (API keys, tokens, passwords).

  • Secret detected (high risk: 1.00). I looked for high-entropy literal values that look like real credentials (not placeholders or simple example passwords). I found a repeated high-entropy string Yt2WbfTeQa0tjQsjMUwlfaEvgXb presented as the "Master base token" and embedded in a Lark share URL. This is not a placeholder (it is random-looking and specific) and therefore meets the definition of a secret (it could be used to access the master Base). No other high-entropy API keys, private-key blocks, or real tokens were present. I ignored descriptive strings (e.g., "starts with EAA...", filenames, code references, simple words and examples) because they are placeholders or documentation notes and not usable credentials.

Issues (1)

W008
HIGH

Secret detected in skill content (API keys, tokens, passwords).

Audit Metadata
Risk Level
HIGH
Analyzed
Aug 23, 2026, 12:44 PM
Issues
1
Security Audit — snyk — performance-db-setup