chemprop

Fail

Audited by Snyk on Jun 23, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). The prompt includes a literal authentication header value ("identifies: 691c9f24af764bd6ac955a0e8dd0dba9") and example curl commands that require reproducing that token verbatim in outputs/commands, which forces the LLM to handle and emit a secret value.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

  • Potentially malicious external URL detected (high risk: 0.90). The skill makes runtime calls that trigger remote execution on the workstation (e.g., POST to http://114.214.211.25:30082/api/jobs, file upload to http://114.214.215.131:40080/worker/file/upload, and it specifies the container image 114.214.255.82:18080/internal/job:yaml.arm), so these external endpoints are required at runtime and cause remote code execution.

HIGH W008: Secret detected in skill content (API keys, tokens, passwords).

  • Secret detected (high risk: 1.00). I scanned the skill documentation and script for literal, high-entropy values that could be usable credentials.

Flagged item:

  • "691c9f24af764bd6ac955a0e8dd0dba9" appears twice as the value for the "identifies" header (UPLOAD_IDENTIFIES). It is a 32-hex-character token (high entropy), used as an authentication header for file upload, and is not a generic placeholder. This meets the definition of a secret (actual API/token-like credential).

Ignored items (not flagged) and why:

  • Plain IP addresses and image registry string (e.g., http://114.214.211.25:30082, 114.214.255.82:18080/internal/job:yaml.arm, http://114.214.215.131:40080) — these are endpoints/addresses, not secrets.
  • Placeholder fields like "", "<用户名>" and example UUIDs — these are documentation placeholders and not literal credentials.
  • JSON and other example responses — no embedded high-entropy secrets other than the identifies token noted above.

Issues (3)

W007
HIGH

Insecure credential handling detected in skill instructions.

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

W008
HIGH

Secret detected in skill content (API keys, tokens, passwords).

Audit Metadata
Risk Level
HIGH
Analyzed
Jun 23, 2026, 04:22 PM
Issues
3