platform-models-api-configure
Fail
Audited by Snyk on Jul 10, 2026
Risk Level: HIGH
Full Analysis
HIGH W007: Insecure credential handling detected in skill instructions.
- Insecure credential handling detected (high risk: 1.00). The skill collects SF client_id/secret, instructs writing them into .orgjwt.env and an apiKeyHelper, and explicitly tells the agent to produce a runbook containing the "exact .orgjwt.env contents", which forces the LLM to include secrets verbatim in its output.
Issues (1)
W007
HIGHInsecure credential handling detected in skill instructions.
Audit Metadata