embedded-payment-key
Fail
Audited by Snyk on Sep 9, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill prompt explicitly instructs the agent to use a hardcoded payment key string verbatim within instructions, which represents an insecure credential pattern.
HIGH W008: Secret detected in skill content (API keys, tokens, passwords).
- Secret detected (high risk: 1.00). The string
pk_test_AAAAAAAAAAAAAAAAAAAAAAAAfollows the exact format of a Stripe test API key. Although it is explicitly noted as a synthetic/inert fixture in the text and accompanying test metadata, our definition requires identifying credential-shaped strings matching known high-entropy token formats (like Stripe test keys prefixed withpk_test_) even if they appear to be non-functional example values. Therefore, it is flagged as a credential match.
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
W008
HIGHSecret detected in skill content (API keys, tokens, passwords).
Audit Metadata