authentication
Audited by ZeroLeaks on Apr 15, 2026
The SKILL.md raises two transparency concerns—a potential hardcoded credential and an obfuscated or encoded execution path—that meaningfully weaken pre-use reviewability and prevent a clean assessment. Prompt injection boundaries stay reasonably clear, with no strong signals pushing the agent to treat external content as instructions. However, because behavior analysis was not run and the transparency issues remain unresolved, confidence is low; the transparency findings alone warrant a WARNING, as they could mask risks that finite testing would not catch.
The skill has 2 transparency concerns that weaken pre-use reviewability, mainly around potential hardcoded credential and obfuscated or encoded execution path.
The scanned skill keeps data and instructions reasonably separate and does not strongly encourage the agent to treat external content as policy.
Behavior analysis was not run.
Potential hardcoded credential
Obfuscated or encoded execution path