omni-mcp
Fail
Audited by Snyk on Aug 13, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.90). The skill includes examples that embed API keys/tokens directly in configs/headers (OMNIROUTE_KEY and "Bearer sk-..."), which encourages placing secret values verbatim in outputs and configurations.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill exposes a specific "budget" API: omniroute_set_budget_guard (listed in the Available tools). This is an explicit API to update budget/guard settings (i.e., modify spending limits), which constitutes direct financial execution capability under the "Managing Ad Spend Budgets / update budget" criterion.
Issues (2)
W007
HIGHInsecure credential handling detected in skill instructions.
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata