1-back working memory test

Fail

Audited by Snyk on Mar 18, 2026

Risk Level: HIGH
Full Analysis

HIGH W007: Insecure credential handling detected in skill instructions.

  • Insecure credential handling detected (high risk: 0.80). The skill requires the agent to store and explicitly output the prior input item verbatim (the "prior letter" and a match indicator), so if a user supplies an API key/password/cookie as an item it will be echoed and thus can exfiltrate secrets even though the prompt does not explicitly request them.

Issues (1)

W007
HIGH

Insecure credential handling detected in skill instructions.

Audit Metadata
Risk Level
HIGH
Analyzed
Mar 18, 2026, 04:48 AM
Issues
1
Security Audit — snyk — 1-back working memory test