developer-growth-analysis

Fail

Audited by Snyk on Aug 11, 2026

Risk Level: CRITICAL
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.80). The skill instructs the agent to read and quote evidence from a local chat history file (pastedContents) and to include "evidence from chat history" in the report, which can force the LLM to output any secrets or API keys that users may have pasted into that history; it also mentions initiating Slack auth via tools (but does not explicitly request tokens).

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The skill explicitly reads a local Claude chat history file (~/.claude/history.jsonl) and instructs sending analyzed reports to Slack via external connection tools, creating a clear risk of deliberate data exfiltration and potential misuse of Slack auth credentials.

Issues (2)

W007
HIGH

Insecure credential handling detected in skill instructions.

E006
CRITICAL

Malicious code pattern detected in skill scripts.

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 11, 2026, 05:08 PM
Issues
2
Security Audit — snyk — developer-growth-analysis