app-navigator
Fail
Audited by Snyk on Jul 20, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill asks the user for an email and password, writes them into a project memory file, and instructs using those exact credentials in MCP tool calls (form-fill), which requires the LLM/agent to read and emit secret values verbatim.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.65). SKILL.md’s setup workflow includes “Login via Browser” and “Navigate & Map” using Playwright MCP tools to snapshot/capture page structure and visible text from the target app at runtime; that page content is outsider-authored (the app’s UI/SSO pages) and can include free text that may be ingested into the LLM context via snapshots/waits.
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata