security-check
Fail
Audited by Snyk on Aug 19, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 0.90). The skill instructs the agent to read local config files and run grep patterns that detect API keys/private keys and environment variables (e.g., sk-..., ghp_..., "BEGIN.*PRIVATE KEY"), which exposes secret values to the LLM and creates a high risk that secrets will be seen and potentially echoed verbatim in the report or command outputs.
Issues (1)
W007
HIGHInsecure credential handling detected in skill instructions.
Audit Metadata