kong-gateway-api-and-naming

Fail

Audited by Snyk on Apr 10, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 1.00). Yes — the prompt shows and instructs embedding API keys/secrets directly in curl requests and plugin credential creations (e.g., "my-secret-api-key", "supersecretkey"), which requires the agent to output secret values verbatim.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Apr 10, 2026, 01:28 PM
Issues
1
Security Audit — snyk — kong-gateway-api-and-naming